Actions, resources, and required conditions for vServer Access Decentralization

VNG Cloud Identity and access management (prefix: viIAM) provides the following service-specific resources, actions, and condition contexts for use in the IAM permissions policy.

STT

vServer Features

Feature Description

Permission to perform feature (Action)

Permission to perform feature (Action)

Permission to perform feature (Action)

vServer policies grant permissions

Access level

Required resources

Required conditions

STT

vServer Features

Feature Description

vServer Portal

vServer API

Terraform

vServer policies grant permissions

Access level

Required resources

Required conditions

1

List Volume Usage

Grant permission to access the Volume Usage list

  • ListVolumeUsage

  • Not support

  • Not support

  • vBackupFullAccess

  • vBackupReadOnlyAccess

List

backup-server

  • Not required

  • or by epoch time

2

List Backup Server Volumes

Grant permission to access the list of Volumes attached to the Backup Server to create a Backup

  • ListBackupServer

  • GetBackupServer

  • ListBackupServerVolumes

  • Not support

  • Not support

  • vBackupFullAccess

  • vBackupReadOnlyAccess

List

backup-server

  • Not required

  • or by epoch time

3

List Backup Location

Grant permission to access the list of backup locations (Backup)

  • ListBackupLocation

  • Not support

  • Not support

  • vBackupFullAccess

  • vBackupReadOnlyAccess

List

  • Not required

  • or by epoch time

4

List Backup Server For Restore

Grant permission to access the list of Backup Server copies that can be used for recovery (Restore)

  • ListBackupServerForRestore

  • Not support

  • Not support

  • vBackupFullAccess

  • vBackupReadOnlyAccess

List

  • Not required

  • or by epoch time

5

List VPCs

Grant permission to access the list of VPCs

  • ListVPCs

  • ListVPCs

  • ListVPCs

  • vServerFullAccess

  • vServerReadOnlyAccess

List

vpc

  • Not required

  • or by epoch time

6

List Security Groups

Grant permission to access the list of Security Groups

  • ListSecurityGroups

  • ListSecurityGroups

  • ListSecurityGroups

  • vServerFullAccess

  • vServerReadOnlyAccess

List

  • Not required

  • or by epoch time

7

List SSH Keys

Grant permission to access list of SSH Keys

  • ListSSHKeys

  • ListSSHKeys

  • ListSSHKeys

  • vServerFullAccess

  • vServerReadOnlyAccess

List

  • Not required

  • or by epoch time

8

List Virtual Ip Addresses

Grant permission to access the list of Virtual IP Address

  • ListVirtualIpAddresses

  • ListVirtualIpAddresses

  • ListVirtualIpAddresses

  • vServerFullAccess

  • vServerReadOnlyAccess

List

  • Not required

  • or by epoch time

9

List User Image

Grant permission to access the list of User Image

  • ListUserImage

  • ListUserImage

  • ListUserImage

  • vServerFullAccess

  • vServerReadOnlyAccess

List

  • Not required

  • or by epoch time

10

List Load Balancer Listeners

Grant permission to access the list of Load Balancer Listeners

  • ListLoadBalancerListeners

  • ListLoadBalancerListeners

  • ListLoadBalancerListeners

  • vLBFullAccess

  • vLBReadOnlyAccess

List

load-balancer

  • Not required

  • or by epoch time

11

List Load Balancer Members

Grant permission to access the list of Load Balancer Members

  • ListLoadBalancerMembers

  • ListLoadBalancerMembers

  • ListLoadBalancerMembers

  • vLBFullAccess

  • vLBReadOnlyAccess

List

load-balancer load-balancer-listener

  • Not required

  • or by epoch time

12

List Route Table

Grant permission to access the Route Table list

  • ListRouteTable

  • ListRouteTable

  • ListRouteTable

  • vServerFullAccess

  • vServerReadOnlyAccess

List

  • Not required

  • or by epoch time

13

List Clusters

Grant permission to access the list of Clusters

  • ListClusters

  • ListClusters

  • ListClusters

  • vServerFullAccess

  • vServerReadOnlyAccess

List

  • Not required

  • or by epoch time

14

List Cluster Volumes

Grant permission to access the list of Cluster Volumes

  • ListClusterVolumes

  • ListClusterVolumes

  • ListClusterVolumes

  • vServerFullAccess

  • vServerReadOnlyAccess

List

cluster

  • Not required

  • or by epoch time

15

List Cluster Node Groups

Grant permission to access the Cluster Node Group list of the Cluster

  • ListClusterNodeGroups

  • ListClusterNodeGroups

  • ListClusterNodeGroups

  • vServerFullAccess

  • vServerReadOnlyAccess

List

cluster

  • Not required

  • or by epoch time

16

List By Status And Resource Type

Grant user service permissions by state and resource type.

  • ListByStatusAndResourceType

  • ListByStatusAndResourceType

  • ListByStatusAndResourceType

  • vServerFullAccess

  • vServerReadOnlyAccess

List

  • Not required

  • or by epoch time

17

List Backup Server

Grant permission to access the Backup Server List

  • ListBackupServer

  • ListBackupServer

  • ListBackupServer

  • vBackupFullAccess

  • vBackupReadOnlyAccess

List

  • Not required

  • or by epoch time

18

Update Backup Server Volumes

Grant the right to update more or less Volume associated with Backup Server

  • ListBackupServer

  • GetBackupServer

  • UpdateBackupServerVolumes

  • Not support

  • Not support

  • vBackupFullAccess

  • vBackupReadOnlyAccess

List

backup-server

  • Not required

  • or by epoch time

19

List Backup Server Histories

Grant permission to access Backup Server history at History page

  • ListBackupServerHistories

  • ListBackupServerHistories

  • ListBackupServerHistories

  • vBackupFullAccess

  • vBackupReadOnlyAccess

List

  • Not required

  • or by epoch time

20

List Volumes

Grant permission to access the list of Volumes

  • ListVolumes

  • ListVolumes

  • ListVolumes

  • vServerFullAccess

  • vServerReadOnlyAccess

List

  • Not required

  • or by epoch time

21

List Subnets

Grant permission to access Networks' list of Subnets

  • ListVPCs

  • ListSubnets

  • ListSubnets

  • ListSubnets

  • vServerFullAccess

  • vServerReadOnlyAccess

List

vpc

  • Not required

  • or by epoch time

22

List Security Group Rules

Grant permission to access security group rules by security group Id.

  • ListSecurityGroupRules

  • ListSecurityGroupRules

  • ListSecurityGroupRules

  • vServerFullAccess

  • vServerReadOnlyAccess

List

secgroup

  • Not required

  • or by epoch time

23

List Floating Ips

Grant permission to access the list of Floating Ips

  • ListFloatingIps

  • ListFloatingIps

  • ListFloatingIps

  • vServerFullAccess

  • vServerReadOnlyAccess

List

  • Not required

  • or by epoch time

24

List Address Pairs

Grant permission to access the Virtual IP Address Address Pair list.

  • ListVirtualIPAddress

  • ListAddressPairs

  • ListAddressPairs