Skip to main content

Role reference

A role is a set of permitted operations on specific types of resources.

Roles are assigned as part of permissions. The role applies to the access scope specified in the permission; for details, see Access management in Servercore products.

Some roles can only be assigned within a specific access scope and have a different set of managed resources in different access scopes.

Depending on the resources and settings they provide access to, roles are divided into:

  • global roles — determine access to resources of all products in the selected access scope (except products that do not support access management), as well as to account, billing, and access settings;
  • and product roles — determine access to resources of one or more products in the selected access scope. They do not allow managing other products, as well as account, billing, and access settings.

Full access to manage the account and resources, as well as exclusive permissions, is held by the Account Owner — the user who registered the account. The Account Owner status is not a role and cannot be changed or assigned to anyone.

Role list

Role groupRole listWhat it manages
Global rolesmemberAll products, account, billing, projects
billingBilling
iam.adminAccess settings
iam.viewerView access settings only
readerAll products, account, billing, projects (view only)
audit_logsaudit_logs.adminAudit logs
compute
  • cloud servers and flavors;
  • cloud server placement groups;
  • cloud server network volumes and snapshots;
  • cloud server images;
  • cloud server network volume backups
dedicated
  • dedicated servers;
  • colocated equipment;
  • firewalls;
  • basic firewall;
  • data storage system;
  • network volumes for dedicated servers;
  • leased network equipment
filestorageFile storage
global_routerGlobal router
go1cCloud for 1C
logsLogs
metricsmetrics.adminMetrics
mobile_farmMobile farm
secretsSecrets Manager
s3 and object_storageS3
vpc
  • Cloud Platform networks;
  • cloud firewalls;
  • security groups;
  • cloud load balancers;
  • private DNS

Global roles

member

The member role grants full access to managing all products and resources. It does not have access to manage users, service users, user groups, or federations.

Access scopes
  • account;
  • project
Who can be assigned
  • users;
  • service users;
  • user groups
Available operations

In the Account access scope:

  • managing projects, their limits and quotas;
  • managing billing;
  • managing resources in all projects;
  • managing resources outside projects;
  • working with audit logs

In the Project access scope:

  • managing resources of the selected project

billing

The billing role grants access to billing management without access to service management.

Access scopesAccount
Who can be assigned
  • users;
  • service users;
  • user groups
Available operations
  • billing management:

    • topping up the balance and transferring funds between balances;
    • managing autobills, monthly payments, payment deferrals;
    • managing balance notifications;
    • managing bank cards;
    • viewing reporting documents;
    • managing the partner program and withdrawing funds;
  • viewing connected services and service statuses

iam.admin

The iam.admin role grants access to user management without access to services and billing. Cannot manage their own account: change permissions, manage notifications, delete the user. The first user with the iam.admin role can only be created by the Account Owner.

Access scopesAccount
Who can be assigned
  • users;
  • service users;
  • user groups
Available operations
  • managing users, service users, user groups;
  • managing federations;
  • issuing keys to users;
  • managing other users' notifications;
  • configuring account access restrictions

iam.viewer

The iam.viewer role grants access to view everything managed by iam.admin.

Access scopesAccount
Who can be assigned
  • users;
  • service users;
  • user groups
Available operations
  • viewing users, service users, user groups;
  • viewing federations;
  • viewing user keys;
  • viewing other users' notifications;
  • viewing account access restrictions

reader

The reader role grants access to view everything managed by member in the same access scope.

Access scopes
  • account;
  • project
Who can be assigned
  • users;
  • service users;
  • user groups
Available operations

In the Account access scope:

  • viewing resources in all projects, as well as resources that are not attached to a project;
  • viewing settings of all projects, their limits and quotas;
  • viewing billing data (balance, bank cards, reporting documents, partner program, etc.)

In the Project access scope:

  • viewing resources of the selected project

audit_logs roles

audit_logs.admin

The audit_logs.admin role grants access to audit logs; for details, see Manage access to audit logs.

Access scopes

Account

Who can be assigned
  • users;
  • service users;
  • user groups
Available operations

Downloading audit logs

compute roles

compute.admin

The compute.admin role grants access to manage:

Access scopes
  • account;
  • project
Who can be assigned
  • users;
  • service users;
  • user groups
Available operations

In the Account access scope:

  • viewing quotas of all projects (default quotas, modified quota values, and used quotas);
  • managing cloud servers (creating, modifying, deleting) * in all projects;
  • using the console;
  • managing flavors (creating, modifying, deleting) in all projects;
  • managing SSH keys (adding, deleting) in all projects;
  • managing placement groups (creating, deleting) in all projects

In the Project access scope:

  • viewing project quotas (default quotas, modified quota values, and used quotas);
  • managing cloud servers (creating, modifying, deleting) * in your project;
  • using the console;
  • managing flavors (creating private flavors, modifying, deleting) in your project;
  • managing SSH keys (adding, deleting) in your project;
  • managing placement groups (creating, deleting) in your project

* To manage cloud servers, you also need a role with access to manage Cloud Platform networks.

compute.viewer

The compute.viewer role grants access to view everything managed by compute.admin.

Access scopes
  • account;
  • project
Who can be assigned
  • users;
  • service users;
  • user groups
Available operations

In the Account access scope:

  • viewing quotas of all projects (default quotas, modified quota values, and used quotas);
  • viewing the list of cloud servers and information about them (server type, configuration type, number of vCPUs, memory size, attached volumes, security groups, network settings, tags) in all projects;
  • viewing statistics on cloud servers in all projects;
  • viewing the list of flavors and information about them (flavor name, number of vCPUs, RAM, and local disk size) in all projects;
  • viewing the list of SSH keys and information about them in all projects;
  • viewing the list of placement groups and information about them (group name, placement policy condition) in all projects

In the Project access scope:

  • viewing project quotas (default quotas, modified quota values, and used quotas);
  • viewing the list of cloud servers and information about them (server type, configuration type, number of vCPUs, memory size, attached volumes, security groups, network settings, tags) in your project;
  • viewing statistics on cloud servers in your project;
  • viewing the list of flavors and information about them (flavor name, number of vCPUs, RAM, and local disk size) in your project;
  • viewing the list of SSH keys and information about them in your project;
  • viewing the list of placement groups and information about them (group name, placement policy condition) in your project

compute.server.user

The compute.server.user role grants access to manage cloud servers; for details, see Manage access to cloud servers and flavors.

Access scopes
  • account;
  • project
Who can be assigned
  • users;
  • service users;
  • user groups
Available operations

In the Account access scope:

  • viewing quotas of all projects (default quotas, modified quota values, and used quotas);
  • managing cloud servers (creating, modifying, deleting) * in all projects;
  • using the console;
  • viewing the list of flavors and information about them in all projects: flavor name, number of vCPUs, RAM, and local disk size in all projects;
  • managing SSH keys (adding, deleting) in all projects

In the Project access scope:

  • viewing project quotas (default quotas, modified quota values, and used quotas);
  • managing cloud servers (creating, modifying, deleting) * in your project;
  • using the console;
  • viewing the list of flavors and information about them in your project: flavor name, number of vCPUs, RAM, and local disk size;
  • managing SSH keys (adding, deleting) in your project

* To manage cloud servers, you also need a role with access to manage Cloud Platform networks, network volumes, images and backups.

compute.server.viewer

The compute.server.viewer role grants access to view everything managed by compute.server.user.

Access scopes
  • account;
  • project
Who can be assigned
  • users;
  • service users;
  • user groups
Available operations

In the Account access scope:

  • viewing quotas of all projects (default quotas, modified quota values, and used quotas);
  • viewing the list of cloud servers and information about them in all projects: server type, configuration type, number of vCPUs, memory size, attached volumes, security groups, network settings, tags;
  • viewing statistics on cloud servers in all projects;
  • viewing the list of flavors and information about them in all projects: flavor name, number of vCPUs, RAM, and local disk size;
  • viewing the list of SSH keys and information about them in all projects

In the Project access scope:

  • viewing project quotas (default quotas, modified quota values, and used quotas);
  • viewing the list of cloud servers and information about them in your project: server type, configuration type, number of vCPUs, memory size, attached volumes, security groups, network settings, tags;
  • viewing statistics on cloud servers in your project;
  • viewing the list of flavors and information about them in your project: flavor name, number of vCPUs, RAM, and local disk size;
  • viewing the list of SSH keys and information about them in your project

compute.flavor.admin

The compute.flavor.admin role grants access to manage cloud server flavors; for details, see Manage access to cloud servers and flavors.

Access scopes
  • account;
  • project
Who can be assigned
  • users;
  • service users;
  • user groups
Available operations

In the Account access scope:

  • viewing quotas of all projects (default quotas) in all projects;
  • managing flavors (creating private flavors, modifying, deleting) in all projects;
  • viewing the list of SSH keys and information about them in all projects

In the Project access scope:

  • viewing project quotas (default quotas) in your project;
  • managing flavors (creating private flavors, modifying, deleting) in your project;
  • viewing the list of SSH keys and information about them in your project

compute.flavor.viewer

The compute.flavor.viewer role grants access to view everything managed by compute.flavor.admin.

Access scopes
  • account;
  • project
Who can be assigned
  • users;
  • service users;
  • user groups
Available operations

In the Account access scope:

  • viewing quotas of all projects (default quotas);
  • viewing the list of flavors and information about them in all projects: flavor name, number of vCPUs, RAM, and local disk size;
  • viewing the list of SSH keys and information about them in all projects

In the Project access scope:

  • viewing project quotas (default quotas);
  • viewing the list of flavors and information about them in your project: flavor name, number of vCPUs, RAM, and local disk size;
  • viewing the list of SSH keys and information about them in your project

compute.server_group.admin

The compute.server_group.admin role grants access to manage cloud server placement groups; for details, see Manage access to cloud server placement groups.

Access scopes
  • account;
  • project
Who can be assigned
  • users;
  • service users;
  • user groups
Available operations

In the Account access scope:

  • viewing quotas of all projects (default quotas);
  • managing placement groups (creating, deleting) in all projects;
  • viewing the list of flavors and information about them in all projects: flavor name, number of vCPUs, RAM, and local disk size;
  • viewing the list of SSH keys and information about them in all projects

In the Project access scope:

  • viewing project quotas (default quotas) in your project;
  • managing placement groups (creating, deleting) in your project;
  • viewing the list of flavors and information about them in your project: flavor name, number of vCPUs, RAM, and local disk size;
  • viewing the list of SSH keys and information about them in your project

compute.server_group.viewer

The compute.server_group.viewer role grants access to view everything managed by compute.server_group.admin.

Access scopes
  • account;
  • project
Who can be assigned
  • users;
  • service users;
  • user groups
Available operations

In the Account access scope:

  • getting quotas of all projects;
  • viewing the list of placement groups and information about them in all projects: group name, placement policy condition;
  • viewing the list of flavors and information about them in all projects: flavor name, number of vCPUs, RAM, and local disk size;
  • viewing the list of SSH keys and information about them in all projects

In the Project access scope:

  • getting project quotas;
  • viewing the list of placement groups and information about them in your project: group name, placement policy condition;
  • viewing the list of flavors and information about them in your project: flavor name, number of vCPUs, RAM, and local disk size;
  • viewing the list of SSH keys and information about them in your project

compute.volume.admin

The compute.volume.admin role grants access to manage cloud server network volumes; for details, see Manage access to cloud server network volumes and snapshots.

Access scopes
  • account;
  • project
Who can be assigned
  • users;
  • service users;
  • user groups
Available operations

In the Account access scope:

  • viewing the list of all network volumes and information about them in all projects: volume type, volume size;
  • managing volumes (creating, modifying, deleting) in all projects;
  • moving volumes between projects;
  • viewing information about moving volumes in all projects

In the Project access scope:

  • viewing the list of all network volumes and information about them in your project: volume type, volume size;
  • managing volumes (creating, modifying, deleting) in your project;
  • transferring volumes from your project to another;
  • viewing information about moving volumes in your project

compute.volume.user

The compute.volume.user role grants access to manage cloud server network volumes; for details, see Manage access to cloud server network volumes and snapshots.

Access scopes
  • account;
  • project
Who can be assigned
  • users;
  • service users;
  • user groups
Available operations

In the Account access scope:

  • viewing the list of all network volumes and information about them (volume type, volume size) in all projects;
  • managing volumes (creating, modifying, deleting) in all projects

In the Project access scope:

  • viewing the list of all network volumes and information about them (volume type, volume size) in your project;
  • managing volumes (creating, modifying, deleting) in your project

compute.volume.viewer

The compute.volume.viewer role grants access to view everything managed by compute.volume.user.

Access scopes
  • account;
  • project
Who can be assigned
  • users;
  • service users;
  • user groups
Available operations

In the Account access scope:

  • viewing the list of network volumes and information about them (volume type, volume size) in all projects

In the Project access scope:

  • viewing the list of network volumes and information about them (volume type, volume size) in your project

compute.snapshot.admin

The compute.snapshot.admin role grants access to manage network volume snapshots; for details, see Manage access to cloud server network volumes and snapshots.

Access scopes
  • account;
  • project
Who can be assigned
  • users;
  • service users;
  • user groups
Available operations

In the Account access scope:

  • viewing the list of snapshots and information about them (snapshot size, creation date, and status) in all projects;
  • managing snapshots (creating, deleting) in all projects

In the Project access scope:

  • viewing the list of snapshots and information about them (snapshot size, creation date, and status) in your project;
  • managing snapshots (creating, deleting) in your project

compute.snapshot.viewer

The compute.snapshot.viewer role grants access to view everything managed by compute.snapshot.admin.

Access scopes
  • account;
  • project
Who can be assigned
  • users;
  • service users;
  • user groups
Available operations

In the Account access scope:

  • viewing the list of snapshots and information about them (snapshot size, creation date, and status) in all projects

In the Project access scope:

  • viewing the list of snapshots and information about them (snapshot size, creation date, and status) in your project

compute.image.admin

The compute.image.admin role grants access to manage images and configure image sharing; for details, see Manage access to cloud server images.

Access scopes
  • account;
  • project
Who can be assigned
  • users;
  • service users;
  • user groups
Available operations

In the Account access scope:

  • viewing the list of images and information about them in all projects: image size, image and container format, minimum image requirements;
  • managing images (uploading, creating, modifying, deleting) in all projects;
  • configuring image sharing in projects from the same account or from other accounts

In the Project access scope:

  • viewing the list of images and information about them in your project: image size, image and container format, minimum image requirements;
  • managing images (uploading, creating, modifying, deleting) in your project;
  • configuring image sharing in projects from the same account or from other accounts

compute.image.user

The compute.image.user role grants access to manage images; for details, see Manage access to cloud server images.

Access scopes
  • account;
  • project
Who can be assigned
  • users;
  • service users;
  • user groups
Available operations

In the Account access scope:

  • viewing the list of images and information about them in all projects: image size, image and container format, minimum image requirements;
  • managing images (uploading, creating, modifying, deleting) in all projects

In the Project access scope:

  • viewing the list of images and information about them in your project: image size, image and container format, minimum image requirements;
  • managing images (uploading, creating, modifying, deleting) in your project

compute.backup.admin

The compute.backup.admin role grants access to manage network volume backups and backup plans; for details, see Manage access to cloud server network volume backups.

Access scopes
  • account;
  • project
Who can be assigned
  • users;
  • service users;
  • user groups
Available operations

In the Account access scope:

  • viewing the list of backups and information about them (backup type, size, connected backup plans, status) in all projects;
  • managing backups (creating, deleting) in all projects;
  • viewing the list of backup plans in all projects;
  • managing backup plans (creating, modifying, deleting) in all projects

In the Project access scope:

  • viewing the list of backups and information about them (backup type, size, connected backup plans, status) in your project;
  • managing backups (creating, deleting) in your project;
  • viewing the list of all backup plans in your project;
  • managing backup plans (creating, modifying, deleting) in your project

compute.backup.viewer

The compute.backup.viewer role grants access to view everything managed by compute.backup.admin.

Access scopes
  • account;
  • project
Who can be assigned
  • users;
  • service users;
  • user groups
Available operations

In the Account access scope:

  • viewing the list of backups and information about them (backup type, size, connected backup plans, status) in all projects;
  • viewing the list of backup plans in all projects

In the Project access scope:

  • viewing the list of backups and information about them (backup type, size, connected backup plans, status) in your project;
  • viewing the list of backup plans in your project

dedicated roles

dedicated.admin

The dedicated.admin role grants access to manage:

Access scopes
  • account;
  • project
Who can be assigned
  • users;
  • service users;
  • user groups
Available operations

In the Account access scope:

  • viewing the project list;
  • managing dedicated servers (ordering, modifying, canceling) in all projects;
  • managing colocated equipment (ordering, modifying, canceling) in all projects;
  • managing networks;
  • enabling and disabling additional services;
  • viewing the list of SSH keys, adding SSH keys to the storage, and managing added SSH keys;
  • managing firewalls (ordering, modifying, canceling);
  • managing network volumes (creating, modifying, deleting);
  • managing DSS (ordering, modifying, canceling);
  • managing the basic firewall (creating, modifying, deleting);
  • managing leased equipment (ordering, modifying, canceling)

In the Project access scope:

  • managing dedicated servers (ordering, modifying, canceling) in your project;

  • managing colocated equipment (ordering, modifying, canceling) in your project;

  • enabling and disabling additional services;

  • viewing the list of SSH keys added to the storage and information about them;

  • viewing and managing are unavailable for:

    • networks;
    • firewalls;
    • network volumes and DSS;
    • basic firewall;
    • leased network equipment

dedicated.viewer

A user with access to view everything managed by dedicated.admin in the same access scope.

Access scopes
  • account;
  • project
Who can be assigned
  • users;
  • service users;
  • user groups
Available operations

In the Account access scope:

  • viewing the list of all dedicated servers and information about them in all projects;
  • viewing the list of colocated equipment and information about it in all projects;
  • viewing the list of all VLANs, public and private subnets, SANs, and information about them;
  • viewing the list of network volumes and DSS, and information about them;
  • viewing the list of firewalls and information about them;
  • viewing the list of basic firewalls and information about them;
  • viewing the list of leased network equipment and information about it;
  • viewing the list of SSH keys added to the storage and information about them

In the Project access scope:

  • viewing the list of dedicated servers and information about them in your project;

  • viewing the list of colocated equipment and information about it in your project;

  • viewing the list of SSH keys added to the storage and information about them;

  • viewing and managing are unavailable for:

    • networks;
    • network volumes and DSS;
    • firewalls;
    • basic firewall;
    • leased network equipment

filestorage roles

filestorage.admin

The filestorage.admin role grants access to manage file storage; for details, see Manage access to file storage.

Access scopes
  • account;
  • project
Who can be assigned
  • users;
  • service users;
  • user groups
Available operations

In the Account access scope:

  • viewing the list of file storages and information about them in all projects: name, size, storage type and protocol, network IP and name, status;
  • viewing access rules for file storages in all projects;
  • creating and managing file storages * in all projects;
  • creating and managing access rules in all projects

In the Project access scope:

  • viewing the list of file storages and information about them in your project: name, size, storage type and protocol, network IP and name, status;
  • viewing access rules for file storages in your project;
  • creating and managing file storages * in your project;
  • creating and managing access rules in your project

* To work with file storage, you also need a role with access to manage Cloud Platform networks to connect the file storage network.

filestorage.viewer

The filestorage.viewer role grants access to view everything managed by filestorage.admin.

Access scopes
  • account;
  • project
Who can be assigned
  • users;
  • service users;
  • user groups
Available operations

In the Account access scope:

  • viewing the list of file storages and information about them in all projects: name, size, storage type and protocol, network IP and name, status;
  • viewing access rules for file storages in all projects

In the Project access scope:

  • viewing the list of file storages and information about them in your project: name, size, storage type and protocol, network IP and name, status;
  • viewing access rules for file storages in your project

global_router roles

global_router.admin

The global_router.admin role grants access to manage global routers in the account; for details, see Manage access to the global router.

Access scopesAccount
Who can be assigned
  • users;
  • service users;
  • user groups
Available operations
  • viewing the list of global routers, networks and subnets connected to them, and the list of static routes on the router;
  • managing global routers (creating, modifying, deleting);
  • adding, modifying, and deleting static routes on the global router;
  • changing names of networks and subnets connected to the global router;
  • connecting an existing or new Cloud Platform network and subnet to a global router *;
  • connecting an existing or new dedicated server network and subnet to a global router *;
  • removing a Cloud Platform network or subnet from the global router network, including deleting the Cloud Platform network or subnet itself *;
  • removing a dedicated server network or subnet from the global router network *

* To manage connecting networks to a global router, the member role in the Project or Account scope is additionally required.

global_router.viewer

The global_router.viewer role grants view access to everything managed by global_router.admin.

Access scopesAccount
Who can be assigned
  • users;
  • service users;
  • user groups
Available operationsViewing the list of global routers, networks and subnets connected to them, and the list of static routes on the router

go1c roles

go1c.admin

The go1c.admin role grants access to manage Managed 1С Cloud resources; for details, see Manage access to Managed 1С Cloud.

Access scopes
  • account;
  • project
Who can be assigned
  • users;
  • service users;
  • user groups
Available operations

In the Account access scope:

  • managing 1C server clusters across all projects * **;;
  • managing infobases across all projects *;
  • managing databases in all projects;
  • managing backups across all projects *;
  • managing Prometheus tokens for metric collection in all projects

In the Project access scope:

  • managing 1C server clusters in your project * **;;
  • managing infobases in your project;
  • managing databases in your project *;
  • managing backups in your project *;
  • managing Prometheus tokens for metric collection in your project

* To manage connecting backup storage, cluster data storage, and uploading an infobase from a .dt file, the combination of s3.admin and iam.admin. is additionally required.

** To manage connecting a cluster to a private network that has already been created in the project, the vpc.private_network.viewer. role is additionally required.

go1c.viewer

The go1c.viewer role grants view access to everything managed by go1c.admin; for details, see Manage access to Managed 1С Cloud.

Access scopes
  • account;
  • project
Who can be assigned
  • users;
  • service users;
  • user groups
Available operations

In the Account access scope:

  • viewing 1C server clusters in all projects;
  • viewing infobases in all projects;
  • viewing databases in all projects;
  • viewing backups in all projects;
  • viewing the list of generated Prometheus tokens for collecting metrics in all projects

In the Project access scope:

  • viewing 1C server clusters in your project;
  • viewing infobases in your project;
  • viewing databases in your project;
  • viewing backups in your project;
  • viewing the list of generated Prometheus tokens for collecting metrics in your project

logs roles

logs.admin

The logs.admin role grants access to manage logs; for details, see Manage access to logs.

Access scopes
  • account;
  • project
Who it can be assigned to
  • users;
  • service users;
  • user groups
Available operations

In the Account access scope:

  • viewing logs in the control panel and using available tools in all projects;
  • managing user logs in all projects;
  • managing log groups and event streams in all projects

In the Project access scope:

  • viewing logs in the control panel and using available tools in your project;
  • managing user logs in your project;
  • managing log groups and event streams in your project

logs.writer

The logs.writer role grants access to add logs to the Logs service; for details, see Manage access to logs.

Access scopes
  • account;
  • project
Who it can be assigned to
  • users;
  • service users;
  • user groups
Available operations

In the Account access scope:

  • adding logs from custom storage using available tools in all projects;
  • creating log groups and event streams in all projects

In the Project access scope:

  • adding logs from custom storage using available tools in your project;
  • creating log groups and event streams in your project

logs.viewer

The logs.viewer role grants access to view logs; for details, see Manage access to logs.

Access scopes
  • account;
  • project
Who it can be assigned to
  • users;
  • service users;
  • user groups
Available operations

In the Account access scope:

  • viewing logs in the control panel and using available tools in all projects

In the Project access scope:

  • viewing logs in the control panel and using available tools in your project

metrics roles

metrics.admin

The metrics.admin role grants access to manage metrics; for details, see Manage access to metrics.

Access scopes
  • account;
  • project
Who it can be assigned to
  • users;
  • service users;
  • user groups
Available operations

In the Account access scope:

  • collecting metrics in all projects

In the Project access scope:

  • collecting metrics in your project

mobile_farm roles

mobile_farm.admin

The mobile_farm.admin role grants access to manage the mobile farm in your project; for details, see Manage access to the mobile farm.

Access scopesProject
Who it can be assigned to
  • users;
  • service users;
  • user groups
Available operations
  • viewing mobile farm consumption in your project;
  • adding and deleting mobile farm devices in your project;
  • using mobile farm devices in your project;
  • changing billing for mobile farm devices in your project;
  • adding ADB and Proxy keys to your profile;
  • changing mobile farm firewall rules

mobile_farm.user

The mobile_farm.user role grants access to use mobile farm devices in your project; for details, see Manage access to the mobile farm.

Access scopesProject
Who it can be assigned to
  • users;
  • service users;
  • user groups
Available operations
  • viewing mobile farm consumption in your project;
  • using mobile farm devices in your project;
  • adding ADB and Proxy keys to your profile;
  • viewing mobile farm firewall rules

mobile_farm.viewer

The mobile_farm.viewer role grants view access to everything managed by mobile_farm.admin.

Access scopesProject
Who it can be assigned to
  • users;
  • service users;
  • user groups
Available operations
  • viewing mobile farm consumption in your project;
  • viewing mobile farm devices in your project;
  • adding ADB and Proxy keys to your profile;
  • viewing mobile farm firewall rules

secrets roles

secrets.admin

The secrets.admin role grants access to manage secrets in Secrets Manager; for details, see Manage access to Secrets Manager.

Access scopes
  • account;
  • project
Who it can be assigned to
  • users;
  • service users;
  • user groups
Available operations

In the Account access scope:

  • managing secrets (adding, deleting) in all projects;
  • managing secret versions (adding, changing the current version, deleting) in all projects;
  • viewing secret contents in all projects

In the Project access scope:

  • managing secrets (adding, deleting) in your project;
  • managing secret versions (adding, changing the current version, deleting) in your project;
  • viewing secret contents in your project

secrets.viewer

The secrets.viewer role grants view access to everything managed by secrets.admin; for details, see Manage access to Secrets Manager.

Access scopes
  • account;
  • project
Who it can be assigned to
  • users;
  • service users;
  • user groups
Available operations

In the Account access scope:

  • viewing the list of secrets and information about them, except for secret contents, in all projects

In the Project access scope:

  • viewing the list of secrets and information about them, except for secret contents, in your project

secrets.consumer

The secrets.consumer role grants access to view and use secrets in Secrets Manager; for details, see Manage access to Secrets Manager.

Access scopes
  • account;
  • project
Who it can be assigned to
  • users;
  • service users;
  • user groups
Available operations

In the Account access scope:

  • viewing the list of secrets and information about them in all projects;
  • viewing secret contents in all projects

In the Project access scope:

  • viewing the list of secrets and information about them in your project;
  • viewing secret contents in your project

s3 and object_storage roles

s3.admin

The s3.admin role grants access to manage S3 within a project; for details, see Manage access to S3.

Access scopesProject
Who it can be assigned toService users
Available operations
  • viewing the list of buckets in your project;
  • viewing bucket contents in your project;
  • managing bucket objects (uploading, changing, deleting) in your project;
  • changing bucket settings in your project;
  • configuring bucket access policies in your project

s3.user

The s3.user role grants access to view the list of buckets in a project and manage an S3 bucket if the bucket has an access policy configured that allows access to the bucket for this user; for details, see Manage access to S3. The level of bucket access is determined by the access policy settings. If no access policy has been created, the user has no access to the bucket.

Differs from a user with the s3.bucket.user role only in having access to view the list of buckets in the project.

Access scopesProject
Who it can be assigned toService users
Available operations
  • viewing the list of buckets in your project;
  • operations in a specific bucket that are allowed by its access policy

s3.bucket.user

The s3.bucket.user role grants access to an S3 bucket if the bucket has an access policy configured that allows access to the bucket for this user; for details, see Manage access to S3. The level of bucket access is determined by the access policy settings. If no access policy has been created, the user has no access to the bucket.

Differs from a user with the s3.user role only in not having access to view the list of buckets in the project.

Access scopesProject
Who it can be assigned toService users
Available operationsOperations in a specific bucket that are allowed by its access policy

object_storage:admin

For your information

The object_storage:admin role will be removed soon; it cannot be assigned to new users. Existing users with the object_storage:admin role continue to work.

A deprecated version of the s3.admin role. Has identical permissions.

object_storage_user

For your information

The object_storage_user role will be removed soon; it cannot be assigned to new users. Existing users with the object_storage_user role continue to work.

A deprecated version of the s3.user role. Has identical permissions.

vpc roles

vpc.admin

The vpc.admin role grants access to manage:

Adding ports to a cloud server and deleting ports added to a cloud server is not available; this requires the compute.admin or compute.server.user. role.

Access scopes
  • account;
  • project
Who it can be assigned to
  • users;
  • service users;
  • user groups
Available operations

In the Account access scope:

  • viewing the list of:

    • all cloud platform network resources and information about them in all projects;
    • all load balancer objects and information about them in all projects: load balancers, rules and HTTP policies, target groups and servers in them, health checks;
    • cloud firewalls and information about them in all projects;
    • security groups and information about them in all projects;
  • managing private networks, subnets, and ports across all projects *;

  • managing public subnets, direct public IP addresses, and public floating IP addresses in all projects;

  • managing cloud routers in all projects;

  • managing load balancers, rules and HTTP policies, target groups, health checks, load balancer logging in all projects, as well as viewing load balancer statistics in all projects;

  • managing cloud firewalls in all projects;

  • managing security groups, rules, and ports in all projects, as well as downloading a report on security groups in all projects

In the Project access scope:

  • viewing the list of:

    • all cloud platform network resources and information about them in your project;
    • all load balancer objects and information about them in your project: load balancers, rules and HTTP policies, target groups and servers in them, health checks;
    • cloud firewalls and information about them in your project;
    • security groups and information about them in your project;
  • managing private networks, subnets, and ports in your project *;

  • managing public subnets, direct public IP addresses, and public floating IP addresses in your project;

  • managing cloud routers in your project;

  • managing load balancers, rules and HTTP policies, target groups, health checks, load balancer logging in all projects, as well as viewing load balancer statistics in your project;

  • managing cloud firewalls in your project;

  • managing security groups, rules, and ports in your project, as well as downloading a report on security groups in your project

* To manage connecting a subnet to a global router, the global_router.admin. role is additionally required.

vpc.viewer

The vpc.viewer role grants view access to everything managed by vpc.admin within the same access scope.

Access scopesAccount
Who it can be assigned to
  • users;
  • service users;
  • user groups
Available operations

In the Account access scope:

  • viewing the list of:

    • all cloud platform network resources and information about them in all projects;
    • cloud firewalls and information about them in all projects;
    • the list of security groups and information about them in all projects;
  • downloading a report on security groups in all projects

In the Project access scope:

  • viewing the list of:
    • all cloud platform network resources and information about them in your project
    • cloud firewalls and information about them in your project;
    • the list of security groups and information about them in your project;
  • downloading a report on security groups in your project

vpc.private_network.admin

The vpc.private_network.admin role grants access to manage:

Adding ports to a cloud server and deleting ports added to a cloud server is not available; this requires the member. role.

Access scopes
  • account;
  • project
Who it can be assigned to
  • users;
  • service users;
  • user groups
Available operations

In the Account access scope:

  • viewing:

    • the list of private networks, subnets, ports, and information about them in all projects;
    • information about connecting a network to a private DNS resolver, viewing the list of zones and resource records in zones in all projects;
  • managing private networks, subnets, and ports across all projects *;

  • managing private DNS in all projects

In the Project access scope:

  • viewing:

    • the list of private networks, subnets, ports, and information about them in your project;
    • information about connecting a network to a private DNS resolver, viewing the list of zones and resource records in zones in your project;
  • managing private networks, subnets, and ports in your project *;

  • managing private DNS in your project

* To manage connecting a subnet to a cloud router, the vpc.external_access.admin role is additionally required. To connect to a global router — the global_router.admin. role.

vpc.private_network.viewer

The vpc.private_network.viewer role grants view access to everything managed by vpc.private_network.admin within the same access scope.

Access scopes
  • account;
  • project
Who it can be assigned to
  • users;
  • service users;
  • user groups
Available operations

In the Account access scope:

  • viewing the list of private networks, subnets, ports, and information about them in all projects;
  • viewing information about connecting a network to a private DNS resolver, viewing the list of zones and resource records in zones in all projects

In the Project access scope:

  • viewing the list of private networks, subnets, ports, and information about them in your project;
  • viewing information about connecting a network to a private DNS resolver, viewing the list of zones and resource records and information about them in your project

vpc.external_access.admin

The vpc.external_access.admin role grants access to manage internet access objects — public subnets, direct public IP addresses and public floating IP addresses, cloud routers. For details, see Manage access to Cloud Platform networks.

Adding ports to a cloud server and deleting ports added to a cloud server is not available; this requires the compute.admin or compute.server.user. role.

Access scopes
  • account;
  • project
Who it can be assigned to
  • users;
  • service users;
  • user groups
Available operations

In the Account access scope:

  • viewing the list of public subnets and public IP addresses, ports in public networks, cloud routers, and information about them in all projects;
  • managing public subnets in all projects;
  • managing direct public IP addresses in all projects;
  • managing public floating IP addresses in all projects;
  • managing cloud routers across all projects *

In the Project access scope:

  • viewing the list of public subnets and public IP addresses, ports in public networks, cloud routers, and information about them in your project;
  • managing public subnets in your project;
  • managing direct public IP addresses in your project;
  • managing public floating IP addresses in your project;
  • managing cloud routers in your project *

* To manage connecting a private subnet to a cloud router, the vpc.private_network.admin. role is additionally required.

vpc.external_access.user

The vpc.external_access.user role grants access:

Adding ports to a cloud server and deleting ports added to a cloud server is not available; this requires the compute.admin or compute.server.user. role.

Access scopes
  • account;
  • project
Who it can be assigned to
  • users;
  • service users;
  • user groups
Available operations

In the Account access scope:

  • viewing the list of public subnets, direct public IP addresses, and public floating IP addresses, ports in public networks, cloud routers, and information about them in all projects;
  • managing public floating IP addresses, except creating and deleting public floating IP addresses, in all projects

In the Project access scope:

  • viewing the list of public subnets, direct public IP addresses, and public floating IP addresses, ports in public networks, cloud routers, and information about them in your project;
  • managing public floating IP addresses, except creating and deleting public floating IP addresses, in your project

vpc.external_access.viewer

The vpc.external_access.viewer role grants view access to everything managed by vpc.external_access.admin within the same access scope.

Access scopes
  • account;
  • project
Who it can be assigned to
  • users;
  • service users;
  • user groups
Available operations

In the Account access scope:

  • viewing the list of public subnets, direct public IP addresses, and public floating IP addresses, ports in public networks, cloud routers, and information about them in all projects

In the Project access scope:

  • viewing the list of public subnets, direct public IP addresses, and public floating IP addresses, ports in public networks, cloud routers, and information about them in your project

vpc.network_security.admin

The vpc.network_security.admin role grants access to manage traffic restriction tools:

Access scopes
  • account;
  • project
Who it can be assigned to
  • users;
  • service users;
  • user groups
Available operations

In the Account access scope:

  • viewing the list of:

    • cloud firewalls and information about them in all projects;
    • security groups and information about them across all projects *;
  • managing cloud firewalls in all projects;

  • managing security groups, rules, and ports across all projects *;

  • downloading a security group report across all projects **

In the Project access scope:

  • viewing the list of:

    • cloud firewalls and information about them in your project;
    • security groups and information about them in your project *;
  • managing cloud firewalls in your project;

  • managing security groups, rules, and ports in your project *;

  • downloading a security group report in your project **

* To view security groups and manage port assignments, the vpc.private_network.viewer or vpc.external_access.viewer. role is additionally required.

** To download the report, the combination of the vpc.private_network.viewer and vpc.external_access.viewer roles, or the vpc.viewer. role is additionally required.

vpc.network_security.user

The vpc.network_security.user role grants access:

Access scopes
  • account;
  • project
Who it can be assigned to
  • users;
  • service users;
  • user groups
Available operations

In the Account access scope:

  • viewing the list of:

    • cloud firewalls and information about them in all projects;
    • security groups and information about them in all projects;
  • managing security group ports across all projects. In the Control panel, the action is available for this role only via the security group page (in the top menu, click Products → Cloud Servers → Security groups → group page);

  • downloading a security group report across all projects *

In the Project access scope:

  • viewing the list of:

    • cloud firewalls and information about them in your project;
    • security groups and information about them in your project;
  • managing security group ports in your project. In the Control panel, the action is available for this role only via the security group page (in the top menu, click Products → Cloud Servers → Security groups → group page);

  • downloading a security group report in your project *

* To download the report, the combination of the vpc.private_network.viewer and vpc.external_access.viewer roles, or the vpc.viewer. role is additionally required.

vpc.network_security.viewer

The vpc.network_security.viewer role grants view access to everything managed by vpc.network_security.admin within the same access scope.

Access scopes
  • account;
  • project
Who it can be assigned to
  • users;
  • service users;
  • user groups
Available operations

In the Account access scope:

  • viewing the list of:

    • cloud firewalls and information about them in all projects;
    • security groups and information about them in all projects;
  • downloading a security group report across all projects *

In the Project access scope:

  • viewing the list of:

    • cloud firewalls and information about them in your project;
    • security groups and information about them in your project;
  • downloading a security group report in your project *

* To download the report, the combination of the vpc.private_network.viewer and vpc.external_access.viewer roles, or the vpc.viewer. role is additionally required.

vpc.load_balancer.admin

The vpc.load_balancer.admin role grants access to manage a cloud load balancer; for details, see Manage access to a cloud load balancer.

Access scopes
  • account;
  • project
Who it can be assigned to
  • users;
  • service users;
  • user groups
Available operations

In the Account access scope:

  • viewing the list of all load balancer objects and information about them in all projects: load balancers, rules and HTTP policies, target groups and servers in them, health checks;
  • viewing load balancer statistics in all projects;
  • managing load balancer objects, except creating a load balancer, across all projects *;
  • enabling and disabling load balancer logging in all projects

In the Project access scope:

  • viewing the list of all load balancer objects and information about them in your project: load balancers, rules and HTTP policies, target groups and servers in them, health checks;
  • viewing load balancer statistics in your project;
  • managing load balancer objects, except creating a load balancer, in your project *;
  • enabling and disabling load balancer logging in your project

* To create a load balancer, one or more additional roles are required. The additional roles depend on the network in which the load balancer will be created:

vpc.load_balancer.viewer

The vpc.load_balancer.viewer role grants view access to everything managed by vpc.load_balancer.admin within the same access scope.

Access scopes
  • account;
  • project
Who it can be assigned to
  • users;
  • service users;
  • user groups
Available operations

In the Account access scope:

  • viewing the list of all load balancer objects and information about them in all projects: load balancers, rules and HTTP policies, target groups and servers in them, health checks

In the Project access scope:

  • viewing the list of all load balancer objects and information about them in your project: load balancers, rules and HTTP policies, target groups and servers in them, health checks