Role Directory
A role is a set of authorized operations on specific types of resources.
Roles are assigned within permissions, the role applies to the access area specified in the permission, for more information see Access Control in Servercore Products.
Some roles may only be assigned to a specific access area, and may have a different set of managed resources in different access areas.
member
User with full access to all services.Does not have access to manage: users, service users, user groups, federations.
billing
User with access to billing management and without access to service management.
iam.admin
User with access to user management and without access to services and billing.Cannot manage his account: change permissions, manage notifications, delete the user.The first user with the iam.admin role is created by the Account Owner.
reader
A user with access to view everything he controls member in the same access area.
dedicated.admin
The dedicated.admin role gives management access:
- For more information, see Managing access to dedicated servers;
- for more information on how to manage access to hosted equipment, see Managing Access to Hosted Equipment;
- For more information, see Manage access to firewalls;
- by the base firewall, for more information, see Manage access to the base firewall;
- storage system, for more information, see Managing Storage Access;
- network disks for dedicated servers, see the Manage access to network disks tutorial for more information;
- For more information, see Manage access to leased network equipment.
dedicated.viewer
User with access to view everything he manages dedicated.admin in the same access area.
vpc.admin
User with access to manage cloud platform networks (private networks and subnets, public subnets and public IP addresses, cloud routers), cloud firewalls, security groups, cloud load balancers.
It is not available to add ports to the cloud server or delete ports added to the cloud server, this requires the role of member.
vpc.viewer
User with access to view everything he controls vpc.admin in the same access area.
vpc.private_network.admin
User with access to private network, subnet and port management, and private DNS.
It is not available to add ports to the cloud server or delete ports added to the cloud server, this requires the role of member.
vpc.private_network.viewer.
A user with access to view everything they manage vpc.private_network.admin in the same access area.
vpc.external_access.admin
User with access to manage objects for internet access - public subnets, public IP addresses, cloud routers.
It is not available to add ports to the cloud server or delete ports added to the cloud server, this requires the role of member.
vpc.external_access.user
A user with access to view everything he controls vpc.external_access.admin in the same access area, and with access to manage public IP addresses.
vpc.external_access.viewer.
A user with access to view everything he controls vpc.external_access.admin in the same access area.
vpc.network_security.admin
Manage traffic restriction tools - cloud firewalls, security groups.
vpc.network_security.user
A user with access to view everything they manage vpc.network_security.admin in the same access area.
vpc.network_security.viewer.
A user with access to view everything they manage vpc.network_security.admin in the same access area.
vpc.load_balancer.admin
User with access to manage the cloud load balancer.For more information, see the Manage Access to Cloud Load Balancer instructions.
vpc.load_balancer.viewer
User with access to view everything he manages vpc.load_balancer.admin in the same access area.For more information, see the Manage Access to Cloud Load Balancer instructions.
compute.admin
User with access to manage cloud servers, flavors, and placement groups.Does not have access to other products.For more information, see the instructions Manage access to cloud servers and flavors and Manage access to cloud server placement groups.
* Except for the role compute.admin user must have a role with access to manage the cloud platform's cloud platform networks.
compute.viewer
User with access to view cloud servers, flavors, and placement groups.Does not have access to other products.For more information, see the instructions Manage access to cloud servers and flavors and Manage access to cloud server placement groups.
compute.server.user
User with access to manage cloud servers.Does not have access to other products.Read more in the Manage Access to Cloud Servers and Flavor instructions.
* In addition to the compute.server.user role, the user must have a role with access to manage cloud platform networks, network disks, images, and backups.
compute.server.viewer
A user with access to view cloud servers.Does not have access to other products.Read more in the instructions Manage access to cloud servers and flavors.
compute.flavor.admin
User with access to manage cloud server flavors.Does not have access to other products.Read more in the Manage Access to Cloud Servers and Flavors tutorial.
compute.flavor.viewer
A user with access to view cloud server flavors.Does not have access to other products.More information in the Manage Access to Cloud Servers and Flavors tutorial.
compute.server_group.admin
A user with access to manage cloud server placement groups.Does not have access to other products.For more information. see the Manage Access to Cloud Server Placement Groups tutorial.
compute.server_group.viewer.
A user with access to view cloud server placement groups.Does not have access to other products.For more information. see the Manage Access to Cloud Server Placement Groups tutorial.
compute.volume.admin
User with access to manage cloud server network disks.Does not have access to other products.For more information, see Manage access to cloud server network disks and snapshots in the instructions.
compute.volume.user
A user with access to manage cloud server network disks.Does not have access to other products in their project or to network disks in other projects.For more information, see Manage access to cloud server network disks and snapshots.
compute.volume.viewer
User with access to view network disks.Does not have access to other products.For more information. in the instructions Manage access to cloud server network disks and snapshots.
compute.snapshot.admin
User with access to network disk snapshot management.No access to other products.
Read more in the instructions Manage access to cloud server network disks and snapshots.
compute.snapshot.viewer
User with access to view network disk snapshots.Does not have access to other products.For more information, see the instructions Manage access to cloud server network disks and snapshots.
compute.image.admin
User with access to image management.Does not have access to other products.Read more in the Manage Cloud Server Image Access instructions.
compute.image.user
A user with access to image management.Does not have access to other products in their project or to images in other projects.Read more in the Manage Access to Cloud Server Images tutorial.
compute.backup.admin
User with access to manage network disk backups and backup plans.Does not have access to other products.Read more in the Manage Access to Cloud Server Network Disk Backups manual.
compute.backup.viewer
A user with access to view network disk backups.Does not have access to other products.For more information, see the Manage access to cloud server network disk backups instructions.
filestorage.admin
A user with access to manage file storage.Does not have access to other products.For details, see the Manage File Storage Access instructions.
* Except for the role filestorage.admin the user must have a role with access to manage cloud platform networks to connect the file storage network.
filestorage.viewer
A user with access to view file storage.Does not have access to other products.For more information. in the Manage File Storage Access instructions.
s3.admin
A user with full access to S3 management within a project.Does not have access to S3 in other projects or other products in their project.Read more in the Manage Access in S3 instructions.
s3.user
A user with access to the S3 bucket if an access policy is configured in the bucket that allows access to the bucket for that user, more details in the Manage Access in S3 instructions .The level of access is determined by the access policy settings.Does not have access to S3 in other projects and other products in their project.
Distinguished from a user with the role s3.bucket.user only by the fact that it has access to viewing the list of bucket in the project.
s3.bucket.user
A user with access to the S3 bucket if an access policy is configured in the bucket that allows access to the bucket for that user, more details in the Manage Access in S3 instructions .The level of access is determined by the access policy settings.Does not have access to S3 in other projects and other products in their project.
Distinguished from a user with the role s3.user only by the fact that it does not have access to viewing the list of bucket in the project.
object_storage:admin
The object_storage:admin role will soon be removed and cannot be assigned to new users.Existing users with the object_storage:admin role continue to work.
Outdated version of the role s3.admin.Possesses identical permissions.
object_storage_user
The object_storage_user role will soon be removed and cannot be assigned to new users.Existing users with the object_storage_user role continue to work.
Outdated version of the role s3.user.User has identical permissions.
global_router.admin
A user with access to manage global router management in the account.Does not have access to other products.For more information, see the Manage Global Router Access instructions.
global_router.viewer
A user with access to view global routers and their networks.Does not have access to other products.Read more in the Manage Global Router Access instructions.
audit_logs.admin
A user with access to audit logs.Does not have access to other products.See the Manage Audit Log Access instructions for details.
mobile_farm.admin
User with full access to manage the mobile farm in their project.Does not have access to the mobile farm in other projects and other products in their project.Read more in the Manage Access to Mobile Farm instructions.
mobile_farm.user
User with access to use Mobile Farm devices in their project.Does not have access to Mobile Farm in other projects and other products in their project.More information in the Manage Mobile Farm Access instructions.
mobile_farm.viewer
User with access to view devices and consume the mobile farm in their project.Does not have access to the mobile farm in other projects and other products in their project.Read more in the Manage Mobile Farm Access instructions.