Actions, resources, and required conditions for vServer Access Decentralization
VNG Cloud Identity and access management (prefix: viIAM) provides the following service-specific resources, actions, and condition contexts for use in the IAM permissions policy.
STT | vServer Features | Feature Description | Permission to perform feature (Action) | Permission to perform feature (Action) | Permission to perform feature (Action) | vServer policies grant permissions |
Access level | Required resources | Required conditions |
STT | vServer Features | Feature Description | vServer Portal | vServer API | Terraform | vServer policies grant permissions | Access level | Required resources | Required conditions |
1 | List Volume Usage | Grant permission to access the Volume Usage list |
|
|
|
| List | backup-server |
|
2 | List Backup Server Volumes | Grant permission to access the list of Volumes attached to the Backup Server to create a Backup |
|
|
|
| List | backup-server |
|
3 | List Backup Location | Grant permission to access the list of backup locations (Backup) |
|
|
|
| List |
|
|
4 | List Backup Server For Restore | Grant permission to access the list of Backup Server copies that can be used for recovery (Restore) |
|
|
|
| List |
|
|
5 | List VPCs | Grant permission to access the list of VPCs |
|
|
|
| List | vpc |
|
6 | List Security Groups | Grant permission to access the list of Security Groups |
|
|
|
| List |
|
|
7 | List SSH Keys | Grant permission to access list of SSH Keys |
|
|
|
| List |
|
|
8 | List Virtual Ip Addresses | Grant permission to access the list of Virtual IP Address |
|
|
|
| List |
|
|
9 | List User Image | Grant permission to access the list of User Image |
|
|
|
| List |
|
|
10 | List Load Balancer Listeners | Grant permission to access the list of Load Balancer Listeners |
|
|
|
| List | load-balancer |
|
11 | List Load Balancer Members | Grant permission to access the list of Load Balancer Members |
|
|
|
| List | load-balancer load-balancer-listener |
|
12 | List Route Table | Grant permission to access the Route Table list |
|
|
|
| List |
|
|
13 | List Clusters | Grant permission to access the list of Clusters |
|
|
|
| List |
|
|
14 | List Cluster Volumes | Grant permission to access the list of Cluster Volumes |
|
|
|
| List | cluster |
|
15 | List Cluster Node Groups | Grant permission to access the Cluster Node Group list of the Cluster |
|
|
|
| List | cluster |
|
16 | List By Status And Resource Type | Grant user service permissions by state and resource type. |
|
|
|
| List |
|
|
17 | List Backup Server | Grant permission to access the Backup Server List |
|
|
|
| List |
|
|
18 | Update Backup Server Volumes | Grant the right to update more or less Volume associated with Backup Server |
|
|
|
| List | backup-server |
|
19 | List Backup Server Histories | Grant permission to access Backup Server history at History page |
|
|
|
| List |
|
|
20 | List Volumes | Grant permission to access the list of Volumes |
|
|
|
| List |
|
|
21 | List Subnets | Grant permission to access Networks' list of Subnets |
|
|
|
| List | vpc |
|
22 | List Security Group Rules | Grant permission to access security group rules by security group Id. |
|
|
|
| List | secgroup |
|
23 | List Floating Ips | Grant permission to access the list of Floating Ips |
|
|
|
| List |
|
|
24 | List Address Pairs | Grant permission to access the Virtual IP Address Address Pair list. |
|
|
|
| List | virtual-ip-address |
|
25 | List Volume History | Grant permission to access a list of Historical Activity of an episode by Volume Id |
|
|
|
| List | volume |
|
26 | List Load Balancer L7Policy | Grant permission to access load List Balancer L7Policy by Id List Balancer. |
|
|
|
| List | load-balancer load-balancer-listener |
|
27 | List Load Balancer By Subnet | Grant permission to access Load Balancer list by Subnet ID. |
|
|
|
| List | subnet |
|
28 | List Route From Route Table | Grant permission to access get Load Balancer list by subnet Id. |
|
|
|
| List | route-table |
|
29 | List Cluster SecGroup | Grant permission to access a Cluster's list of Sec Groups |
|
|
|
| List | cluster |
|
30 | List Cluster SecGroup Default | Grant permission to access the list of Sec Groups of a Cluster |
|
|
|
| List | cluster |
|
31 | List Persistent Volume | Grant permission to access access the list of Persistent Volume |
|
|
|
| List |
|
|
32 | Get By Artifact Id | Grant permission to access receive user service using artifactid. |
|
|
|
| List |
|
|
33 | List Backup Server Restore Point | Grant permission to access Backup Server's list of Restore Points |
|
|
|
| List | backup-server |
|
34 | List Backup Policy | Grant permission to access the Backup Policy list |
|
|
|
| List |
|
|
35 | List Backup Restore Histories | Grant permission to access Restore Point history |
|
|
|
| List |
|
|
36 | List Server | Grant permission to access the Server list |
|
|
|
| List |
|
|
37 | List Quota Limits | Grant permission to access the limited capacity list for the resources of the vServer product |
|
|
|
| List |
|
|
38 | List Server By Security Groups | Grant permission to access Security Group's Server information. |
|
|
|
| List | secgroup |
|
39 | List Network Interface | Grant permission to access the Network Interface list |
|
|
|
| List |
|
|
40 | List Server Groups | Grant permission to access the list of Server Groups |
|
|
|
| List |
|
|
41 | List Load Balancers | Grant permission to access the list of Load Balancers |
|
|
|
| List |
|
|
42 | List Load Balancer Pools | Grant permission to access the List Load balancer Pool list by the List Balancer's ID |
|
|
|
| List | load-balancer |
|
43 | List Certificate Authority | Grant permission to access the list of Certificate authorities |
|
|
|
| List |
|
|
44 | Get List Network Acl | Grant permission to access the Network ACL list |
|
|
|
| List |
|
|
45 | List Cluster Nodes | Grant permission to access the list of Cluster Nodes |
|
|
|
| List | cluster |
|
46 | List Cluster Pools | Grant permission to access the list of Cluster Pools |
|
|
|
| List | cluster |
|
47 | List Resource Billing | Grant permission rights to the Resource Billing list |
|
|
|
| List |
|
|
48 | Get Backup Server | Grant permission to access Backup Server details |
|
|
|
| Read | backup-server |
|
49 | List Backup Volume Points For Restore | Grant permission to access the detailed restore point list of the Backup Volume for Restore |
|
|
|
| Read |
|
|
50 | Get Boot Volume By Server | Grant permission to access the list of Boot volumes by Server |
|
|
|
| Read | server |
|
51 | Get Console Log | Grant permission to Console Log |
|
|
|
| Read | server |
|
52 | Server Security Group Detail | Grant permission to access Detail Security Group details |
|
|
|
| Read | server |
|
53 | Get Security Group | Grant permission to access Detail Security Group details |
|
|
|
| Read | secgroup |
|
54 | Get Network Interface | Grant permission to access Network Interface details |
|
|
|
| Read | network-interface |
|
55 | Get Load Balancer | Grant permission to access Load Balancer details |
|
|
|
| Read | load-balancer |
|
56 | Get LoadBalancer Pool | Grant permission to access Load Balancer Pool details |
|
|
|
| Read | load-balancer load-balancer-listener |
|
57 | Get Detail Route Table | Grant permission to access Detail Route Table details |
|
|
|
| Read | route-table |
|
58 | Get Cluster Config | Grant permission to access download Cluster's Configuration |
|
|
|
| Read | cluster |
|
59 | Get Cluster Node Groups | Grant permission to access Cluster Node Group details |
|
|
|
| Read | cluster-node-group |
|
60 | Get Backup Policy | Grant permission to access Backup Policy details |
|
|
|
| Read | backup-policy |
|
61 | Get Volume | Grant permission to access Volume details |
|
|
|
| Read | volume |
|
62 | Get Server Get Server Health Monitor | Grant permission to access access Server details Grant permission to access Server Health Monitor details |
|
|
|
| Read | server |
|
63 | List Action Server | Grant permission to access detailed information about actions on the Server |
|
|
|
| Read | server |
|
64 | Get VPC | Grant permission to access VPC details |
|
|
|
| Read | vpc |
|
65 | Get Security Group Rule | Grant permission to access Security Group Rule details |
|
|
|
| Read | secgroup secgroup-rule |
|
66 | Get Server Group | Grant permission to access Server Group details by Server Group ID |
|
|
|
| Read | server-group |
|
67 | Get Load Balancer Listener | Grant permission to access detailed information Load Balancer Listener |
|
|
|
| Read | load-balancer load-balancer-listener |
|
68 | Get Load Balancer Health Monitor | Grant permission to access Load Balancer Health Monitor details |
|
|
|
| Read | load-balancer load-balancer-listener |
|
69 | Get Detail Network Acl By Uuid | Grant permission to access Detail Network ACL details according to Uuid |
|
|
|
| Read | network-acl |
|
70 | Get Console Of Node | Granting Get Console access of a Node in the Cluster |
|
|
|
| Read | server |
|
71 | List Backup Server Points For Restore | Grant permission to access Backup Server Point details for Restore |
|
|
|
| Read | backup |
|
72 | List Volume ByServer | Grant permission to access detailed information of Volume list by Server |
|
|
|
| Read | server |
|
73 | Get Console Url | Grant permission to access Console Url |
|
|
|
| Read | server |
|
74 | Server Network Interface Detail | Grant permission to access detailed information of Server Network Interface details |
|
|
|
| Read | server |
|
75 | Get Subnet | Grant permission to access Subnet details |
|
|
|
| Read | vpc subnet |
|
76 | Get SSH Key | Grant permission to access SSH Key details |
|
|
|
| Read | ssh-key |
|
77 | Get User Image | Grant permission to access detailed User Image information |
|
|
|
| Read | user-image |
|
78 | Get Load Balancer L7 Policy | Granting permission to access details Load Balancer L7 Policy |
|
|
|
| Read | load-balancer load-balancer-l7policy |
|
79 | Get Certificate Authority | Grant permission to access Certificate Authority details |
|
|
|
| Read | certificate-authority |
|
80 | Get Cluster | Grant permission to access Cluster details |
|
|
|
| Read | cluster |
|
81 | Get Cluster Nodes By Node Group | Grant permission to access Cluster Node details by Node Group |
|
|
|
| Read | cluster cluster-node-group |
|
82 | Create Backup Server | Grant permission to create backup Server |
|
|
|
| Write |
|
|
83 | Enable Backup Server | Grant permission to enable automatic creation of Backup Server according to the schedule Policy |
|
|
|
| Write |
|
|
84 | Delete Backup Policy | Grant permission to delete Backup Server |
|
|
|
| Write | backup-policy |
|
85 | Attach Volume | Grant permission rights to attach Volume to Server |
|
|
|
| Write | volume server |
|
86 | Resize Volume | Grant permission rights to Resize Volume |
|
|
|
| Write | volume |
|
87 | Create Server | Grant permission to create Server |
|
|
|
| Write |
|
|
88 | Start Server | Grant permission to Start Server |
|
|
|
| Write | server |
|
89 | Reboot Server | Grant permission to Reboot Server |
|
|
|
| Write | server |
|
90 | Server Attach FloatingIp | Grant permission rights Attach Floating Ip to Server |
|
|
|
| Write | server floatingIp |
|
91 | Server Detach Internal Network Interface | Grant permission to Detach Internal Network Interface from the Server |
NetworkInterface |
NetworkInterface |
NetworkInterface |
| Write | server |
|
92 | Delete VPC | Grant permission to remove VPC from the list page |
|
|
|
| Write | vpc |
|
93 | Create Subnet | Grant permission to create Subnet |
|
|
|
| Write | vpc |
|
94 | Create Security Group | Grant permission to create Security Group |
|
|
|
| Write |
|
|
95 | Create Security Group Rule | Grant permission to create Security Group Rule |
|
|
|
| Write | secgroup |
|
96 | Create SSH Key | Grant permission to generate SSH Key |
|
|
|
| Write |
|
|
97 | Delete Floating Ip | Grant permission to delete Floating IP |
|
|
|
| Write | floatingIp |
|
98 | Delete Network Interface | Grant permission to delete Network Interface |
|
|
|
| Write | network-interface |
|
99 | Delete Virtual Ip Address | Grant permission rights to delete Virtual IP Address |
|
|
|
| Write | virtual-ip-address |
|
100 | Create Server Group | Grant permission to create Server Group |
|
|
|
| Write |
|
|
101 | Delete User Image | Grant permission to delete User Image |
|
|
|
| Write | user-image |
|
102 | Delete Load Balancer | Grant permission to delete Load Balancer |
|
|
|
| Write | load-balancer |
|
103 | Delete Load Balancer Listener | Grant permission to delete Load Balancer Listener |
|
|
|
| Write | Load-balancer load-balancer-listener |
|
104 | Delete Load Balancer L7Policy | Grant permission to delete Load Balancer L7Policy |
|
|
|
| Write | load-balancer load-balancer-l7policy |
|
105 | Update Load Balancer Pool | Grant permission to update Load Balancer Pool |
|
|
|
| Write | load-balancer load-balancer-listener |
|
106 | Delete Certificate Authority | Grant permission to delete Certificate Authority |
|
|
|
| Write | certificate-authority |
|
107 | Edit List Route From Route Table | Grant permission to update Route List from Route Table |
|
|
|
| Write | route-table |
|
108 | Update Associated Subnets Of Network ACL | Grant permission toupdate Subnet Link ACLs of Network Acl |
|
|
|
| Write | network-acl |
|
109 | Create Cluster | Grant permission to create Cluster |
|
|
|
| Write |
|
|
110 | Update Cluster SecGroup | Grant permission to update Cluster SecGroup |
|
|
|
| Write | cluster |
|
111 | Create Cluster Node Groups | Grant permission to create Cluster Node Groups |
|
|
|
| Write | cluster |
|
112 | Order Creation | Grant permission to create orders |
|
|
|
| Write |
|
|
113 | Stop POC Resource | Grant permission to stop POC Resource |
|
|
|
| Write |
|
|
114 | Delete Backup Server | Grant permission to delete Backup Server |
|
|
|
| Write | backup-server |
|
115 | Disable Backup Server | Grant permission to turn off the automatic creation of Backup Server according to the schedule Policy |
|
|
|
| Write | backup-server |
|
116 | Update Backup Policy | Grant permission to update Backup Policy |
|
|
|
| Write | backup-policy |
|
117 | Detach Volume | Grant permission to detach Volume from the Server |
|
|
|
| Write | volume server |
|
118 | Create Volume | Grant permission to create Volume |
|
|
|
| Write |
|
|
119 | Resize Server | Grant permission rights to resize Server |
|
|
|
| Write | server |
|
120 | Stop Server | Grant permission to stop Server |
|
|
|
| Write | server |
|
121 | Update SecGroup Server | Grant permission rights to update SecGroup for Server at Server list page |
|
|
|
| Write | server |
|
122 | Server Detach FloatingIp | Grant permission permission to detach Floating Ip from Server |
|
|
|
| Write | server floatingIp |
|
123 | Server Attach External Network Interface | Grant permission to attach External Interface to Server |
NetworkInterface |
NetworkInterface |
NetworkInterface |
| Write | server |
|
124 | Create VPC | Grant permission to create VPC |
|
|
|
| Write |
|
|
125 | Edit Subnet | Grant permission to edit Subnet |
|
|
|
| Write | vpc subnet |
|
126 | Update Security Group | Grant permission to update Security Group |
|
|
|
| Write | secgroup |
|
127 | Delete Security Group Rule | Grant permission to delete Security Group Rule |
|
|
|
| Write | secgroup secgroup-rule |
|
128 | Import SSH Key | Grant permission to Import SSH Key |
|
|
|
| Write |
|
|
129 | Create Network Interface | Grant permission to create Network Interface |
|
|
|
| Write |
|
|
130 | Create Virtual Ip Address | Grant permission to create Virtual Ip Address |
|
|
|
| Write |
|
|
131 | Create Address Pair | Grant permission to create Address Pair |
|
|
|
| Write | virtual-ip-address |
|
132 | Update Server Group | Grant permission to update Server Group |
|
|
|
| Write | server-group |
|
133 | Create User Image | Grant permission to create Create User Image |
|
|
|
| Write | server |
|
134 | Create Load Balancer Listener | Grant permission to create Load Balancer Listener |
|
|
|
| Write | load-balancer |
|
135 | Create Load Balancer L7Policy | Granting access to create Load Balancer L7Policy |
|
|
|
| Write | load-balancer load-balancer-listener |
|
136 | Reorder L7Policies | Grant permission to re-order L7Policies |
|
|
|
| Write | load-balancer load-balancer-listener |
|
137 | Delete Load Balancer Pool | Grant permission to delete Load Balancer Pool |
|
|
|
| Write | load-balancer load-balancer-listener |
|
138 | Import Certificate Authority | Grant permission to import Certificate Authority |
|
|
|
| Write |
|
|
139 | Delete Route Table | Grant permission to delete Route Table |
|
|
|
| Write | route-table |
|
140 | Update Inbound Outbound Of Network ACL | Grant permission to update Inbound/Outbound Rules for Network Account |
|
|
|
| Write | network-acl |
|
141 | Delete Cluster | Grant permission to delete Cluster |
|
|
|
| Write | cluster |
|
142 | Scale Minion Cluster | Grant permission to Scale Minion Cluster |
|
|
|
| Write | cluster cluster-node-group |
|
143 | Delete Cluster Node Groups | Grant permission to delete Cluster Node Group |
|
|
|
| Write | cluster-node-group |
|
144 | Check Resource Expired | Granting permission to check the Resource has expired |
|
|
|
| Write |
|
|
145 | Update Policy Of Backup Server
| Grant Policy to update Backup Server |
|
|
|
| Write | backup-server |
|
146 | Create Backup Policy | Grant permission to create Backup Policy |
|
|
|
| Write |
|
|
147 | Create Backup Server With Default Config | Grant permission to create Backup Server with Default Config when creating Backup at Server list page |
|
|
|
| Write |
|
|
148 | Delete Volume | Grant permission to delete Volume |
|
|
|
| Write | volume |
|
149 | Create Project | Grant permission to create Project for Account |
|
|
|
| Write | server |
|
150 | Delete Server | Grant permission to delete Server |
|
|
|
| Write |
|
|
151 | Migrate Server | Grant permission to migrate Server |
|
|
|
| Write | server |
|
152 | Rename Server | Grant permission rights to rename Server |
|
|
|
| Write | server |
|
153 | Server Attach Internal Network Interface | Grant permission to attach Internal Network Interface to the Server |
|
NetworkInterface
|
NetworkInterface
|
| Write | server |
|
154 | Server Detach External Network Interface | Grant permission to detach External Network Interface from the Server |
|
|
|
| Write | server |
|
155 | Edit VPC | Grant permission to edit VPC |
|
|
|
| Write | vpc |
|
156 | Delete Subnet | Grant permission to delete Subnet |
|
|
|
| Write | vpc subnet |
|
157 | Delete Security Group | Grant permission to delete Security Group |
|
|
|
| Write | secgroup |
|
158 | Update Security Group Rule | Grant permission to update Security Group Rule |
|
|
|
| Write | secgroup secgroup-rule |
|
159 | Delete SSHKey | Grant permission to delete SSH Key |
|
|
|
| Write | ssh-key |
|
160 | Rename Network Interface | Grant permission to rename Network Interface |
|
|
|
| Write | network-interface |
|
161 | Update Virtual IpAddress | Grant permission to update Virtual IP Address |
|
|
|
| Write | virtual-ip-address |
|
162 | Delete Address Pair | Grant permission to delete Address Pair |
|
|
|
| Write | virtual-ip-address address-pair |
|
163 | Delete Server Group | Grant permission to delete Server Group |
|
|
|
| Write | server-group |
|
164 | Create Load Balancer | Grant permission to create Load Balancer |
|
|
|
| Write |
|
|
165 | Update Load Balancer Listener | Grant permission to update Load Balancer Listener |
|
|
|
| Write | load-balancer load-balancer-listener |
|
166 | Update Load Balancer L7Policy | Grant permission to update Load Balancer L7Policy update access permission |
|
|
|
| Write | load-balancer load-balancer-l7policy |
|
167 | Create Load Balancer Pool | Grant permission to create Load Balancer Pool |
|
|
|
| Write | load-balancer |
|
168 | Update List Load Balancer Members | Grant permission to updated the List of Load Balancer Members |
|
|
|
| Write | load-balancer load-balancer-listener |
|
169 | Create Route Table | Grant permission to create Route Table |
|
|
|
| Write |
|
|
170 | Create Network Acl | Grant permission to create Network Acl |
|
|
|
| Write |
|
|
171 | Delete Network Acl | Grant permission to delete Network Acl |
|
|
|
| Write | network-acl |
|
172 | Update Cluster Description | Grant permission to update Cluster Description |
|
|
|
| Write | cluster |
|
173 | Attach Load Balancer To Cluster | Grant permission to Attach Load Balancer to Cluster |
|
|
|
| Write | cluster |
|
174 | Delete Persistent Volume | Grant permission to delete Persistent Volume |
|
|
|
| Write | persistent-volume |
|
175 | Auto Renew Resource | Grant permission to Auto Renew Resource |
|
|
|
| Write |
|
Last updated