Role reference
A role is a set of permitted operations on specific types of resources.
Roles are assigned as part of permissions. The role applies to the access scope specified in the permission; for details, see Access management in Servercore products.
Some roles can only be assigned within a specific access scope and have a different set of managed resources in different access scopes.
Depending on the resources and settings they provide access to, roles are divided into:
- global roles — determine access to resources of all products in the selected access scope (except products that do not support access management), as well as to account, billing, and access settings;
- and product roles — determine access to resources of one or more products in the selected access scope. They do not allow managing other products, as well as account, billing, and access settings.
Full access to manage the account and resources, as well as exclusive permissions, is held by the Account Owner — the user who registered the account. The Account Owner status is not a role and cannot be changed or assigned to anyone.
Role list
Global roles
member
The member role grants full access to managing all products and resources. It does not have access to manage users, service users, user groups, or federations.
billing
The billing role grants access to billing management without access to service management.
iam.admin
The iam.admin role grants access to user management without access to services and billing. Cannot manage their own account: change permissions, manage notifications, delete the user. The first user with the iam.admin role can only be created by the Account Owner.
iam.viewer
The iam.viewer role grants access to view everything managed by iam.admin.
reader
The reader role grants access to view everything managed by member in the same access scope.
audit_logs roles
audit_logs.admin
The audit_logs.admin role grants access to audit logs; for details, see Manage access to audit logs.
compute roles
compute.admin
The compute.admin role grants access to manage:
- cloud servers and flavors; for details, see Manage access to cloud servers and flavors;
- placement groups; for details, see Manage access to cloud server placement groups.
* To manage cloud servers, you also need a role with access to manage Cloud Platform networks.
compute.viewer
The compute.viewer role grants access to view everything managed by compute.admin.
compute.server.user
The compute.server.user role grants access to manage cloud servers; for details, see Manage access to cloud servers and flavors.
* To manage cloud servers, you also need a role with access to manage Cloud Platform networks, network volumes, images and backups.
compute.server.viewer
The compute.server.viewer role grants access to view everything managed by compute.server.user.
compute.flavor.admin
The compute.flavor.admin role grants access to manage cloud server flavors; for details, see Manage access to cloud servers and flavors.
compute.flavor.viewer
The compute.flavor.viewer role grants access to view everything managed by compute.flavor.admin.
compute.server_group.admin
The compute.server_group.admin role grants access to manage cloud server placement groups; for details, see Manage access to cloud server placement groups.
compute.server_group.viewer
The compute.server_group.viewer role grants access to view everything managed by compute.server_group.admin.
compute.volume.admin
The compute.volume.admin role grants access to manage cloud server network volumes; for details, see Manage access to cloud server network volumes and snapshots.
compute.volume.user
The compute.volume.user role grants access to manage cloud server network volumes; for details, see Manage access to cloud server network volumes and snapshots.
compute.volume.viewer
The compute.volume.viewer role grants access to view everything managed by compute.volume.user.
compute.snapshot.admin
The compute.snapshot.admin role grants access to manage network volume snapshots; for details, see Manage access to cloud server network volumes and snapshots.
compute.snapshot.viewer
The compute.snapshot.viewer role grants access to view everything managed by compute.snapshot.admin.
compute.image.admin
The compute.image.admin role grants access to manage images and configure image sharing; for details, see Manage access to cloud server images.
compute.image.user
The compute.image.user role grants access to manage images; for details, see Manage access to cloud server images.
compute.backup.admin
The compute.backup.admin role grants access to manage network volume backups and backup plans; for details, see Manage access to cloud server network volume backups.
compute.backup.viewer
The compute.backup.viewer role grants access to view everything managed by compute.backup.admin.
dedicated roles
dedicated.admin
The dedicated.admin role grants access to manage:
- dedicated servers; for details, see Manage access to dedicated servers;
- colocated equipment; for details, see Manage access to colocated equipment;
- firewalls; for details, see Manage access to firewalls;
- the basic firewall; for details, see Manage access to the basic firewall;
- the data storage system; for details, see Manage access to DSS;
- network volumes for dedicated servers; for details, see Manage access to network volumes;
- leased network equipment; for details, see Manage access to leased network hardware.
dedicated.viewer
A user with access to view everything managed by dedicated.admin in the same access scope.
filestorage roles
filestorage.admin
The filestorage.admin role grants access to manage file storage; for details, see Manage access to file storage.
* To work with file storage, you also need a role with access to manage Cloud Platform networks to connect the file storage network.
filestorage.viewer
The filestorage.viewer role grants access to view everything managed by filestorage.admin.
global_router roles
global_router.admin
The global_router.admin role grants access to manage global routers in the account; for details, see Manage access to the global router.
* To manage connecting networks to a global router, the member role in the Project or Account scope is additionally required.
global_router.viewer
The global_router.viewer role grants view access to everything managed by global_router.admin.
go1c roles
go1c.admin
The go1c.admin role grants access to manage Managed 1С Cloud resources; for details, see Manage access to Managed 1С Cloud.
* To manage connecting backup storage, cluster data storage, and uploading an infobase from a .dt file, the combination of s3.admin and iam.admin. is additionally required.
** To manage connecting a cluster to a private network that has already been created in the project, the vpc.private_network.viewer. role is additionally required.
go1c.viewer
The go1c.viewer role grants view access to everything managed by go1c.admin; for details, see Manage access to Managed 1С Cloud.
logs roles
logs.admin
The logs.admin role grants access to manage logs; for details, see Manage access to logs.
logs.writer
The logs.writer role grants access to add logs to the Logs service; for details, see Manage access to logs.
logs.viewer
The logs.viewer role grants access to view logs; for details, see Manage access to logs.
metrics roles
metrics.admin
The metrics.admin role grants access to manage metrics; for details, see Manage access to metrics.
mobile_farm roles
mobile_farm.admin
The mobile_farm.admin role grants access to manage the mobile farm in your project; for details, see Manage access to the mobile farm.
mobile_farm.user
The mobile_farm.user role grants access to use mobile farm devices in your project; for details, see Manage access to the mobile farm.
mobile_farm.viewer
The mobile_farm.viewer role grants view access to everything managed by mobile_farm.admin.
secrets roles
secrets.admin
The secrets.admin role grants access to manage secrets in Secrets Manager; for details, see Manage access to Secrets Manager.
secrets.viewer
The secrets.viewer role grants view access to everything managed by secrets.admin; for details, see Manage access to Secrets Manager.
secrets.consumer
The secrets.consumer role grants access to view and use secrets in Secrets Manager; for details, see Manage access to Secrets Manager.
s3 and object_storage roles
s3.admin
The s3.admin role grants access to manage S3 within a project; for details, see Manage access to S3.
s3.user
The s3.user role grants access to view the list of buckets in a project and manage an S3 bucket if the bucket has an access policy configured that allows access to the bucket for this user; for details, see Manage access to S3. The level of bucket access is determined by the access policy settings. If no access policy has been created, the user has no access to the bucket.
Differs from a user with the s3.bucket.user role only in having access to view the list of buckets in the project.
s3.bucket.user
The s3.bucket.user role grants access to an S3 bucket if the bucket has an access policy configured that allows access to the bucket for this user; for details, see Manage access to S3. The level of bucket access is determined by the access policy settings. If no access policy has been created, the user has no access to the bucket.
Differs from a user with the s3.user role only in not having access to view the list of buckets in the project.
object_storage:admin
The object_storage:admin role will be removed soon; it cannot be assigned to new users. Existing users with the object_storage:admin role continue to work.
A deprecated version of the s3.admin role. Has identical permissions.
object_storage_user
The object_storage_user role will be removed soon; it cannot be assigned to new users. Existing users with the object_storage_user role continue to work.
A deprecated version of the s3.user role. Has identical permissions.
vpc roles
vpc.admin
The vpc.admin role grants access to manage:
- Cloud Platform networks (private networks and subnets, public subnets and public IP addresses, cloud routers); for details, see Manage access to Cloud Platform networks;
- cloud firewalls; for details, see Manage access to a cloud firewall;
- security groups; for details, see Manage access to security groups;
- cloud load balancers; for details, see Manage access to a cloud load balancer.
Adding ports to a cloud server and deleting ports added to a cloud server is not available; this requires the compute.admin or compute.server.user. role.
* To manage connecting a subnet to a global router, the global_router.admin. role is additionally required.
vpc.viewer
The vpc.viewer role grants view access to everything managed by vpc.admin within the same access scope.
vpc.private_network.admin
The vpc.private_network.admin role grants access to manage:
- Cloud Platform networks (private networks, subnets, and ports); for details, see Manage access to Cloud Platform networks;
- private DNS; for details, see Manage access to private DNS.
Adding ports to a cloud server and deleting ports added to a cloud server is not available; this requires the member. role.
* To manage connecting a subnet to a cloud router, the vpc.external_access.admin role is additionally required. To connect to a global router — the global_router.admin. role.
vpc.private_network.viewer
The vpc.private_network.viewer role grants view access to everything managed by vpc.private_network.admin within the same access scope.
vpc.external_access.admin
The vpc.external_access.admin role grants access to manage internet access objects — public subnets, direct public IP addresses and public floating IP addresses, cloud routers. For details, see Manage access to Cloud Platform networks.
Adding ports to a cloud server and deleting ports added to a cloud server is not available; this requires the compute.admin or compute.server.user. role.
* To manage connecting a private subnet to a cloud router, the vpc.private_network.admin. role is additionally required.
vpc.external_access.user
The vpc.external_access.user role grants access:
- to view everything managed by vpc.external_access.admin within the same access scope;
- to manage public floating IP addresses; for details, see Manage access to Cloud Platform networks.
Adding ports to a cloud server and deleting ports added to a cloud server is not available; this requires the compute.admin or compute.server.user. role.
vpc.external_access.viewer
The vpc.external_access.viewer role grants view access to everything managed by vpc.external_access.admin within the same access scope.
vpc.network_security.admin
The vpc.network_security.admin role grants access to manage traffic restriction tools:
- cloud firewalls; for details, see Manage access to a cloud firewall;
- security groups; for details, see Manage access to security groups.
* To view security groups and manage port assignments, the vpc.private_network.viewer or vpc.external_access.viewer. role is additionally required.
** To download the report, the combination of the vpc.private_network.viewer and vpc.external_access.viewer roles, or the vpc.viewer. role is additionally required.
vpc.network_security.user
The vpc.network_security.user role grants access:
- to view everything managed by vpc.network_security.admin within the same access scope;
- to manage security groups on ports in a private or public network; for details, see Manage access to security groups.
* To download the report, the combination of the vpc.private_network.viewer and vpc.external_access.viewer roles, or the vpc.viewer. role is additionally required.
vpc.network_security.viewer
The vpc.network_security.viewer role grants view access to everything managed by vpc.network_security.admin within the same access scope.
* To download the report, the combination of the vpc.private_network.viewer and vpc.external_access.viewer roles, or the vpc.viewer. role is additionally required.
vpc.load_balancer.admin
The vpc.load_balancer.admin role grants access to manage a cloud load balancer; for details, see Manage access to a cloud load balancer.
* To create a load balancer, one or more additional roles are required. The additional roles depend on the network in which the load balancer will be created:
- vpc.admin to create a load balancer in any subnet;
- vpc.private_network.admin to create a load balancer in a private subnet;
- vpc.external_access.admin to create a load balancer in a public subnet;
- the combination of vpc.private_network.admin and vpc.external_access.admin roles to create a load balancer in a private subnet with a public IP address;
vpc.load_balancer.viewer
The vpc.load_balancer.viewer role grants view access to everything managed by vpc.load_balancer.admin within the same access scope.