Manage access to cloud firewall
Access to cloud firewall is regulated by:
- projects — define access within an isolated group of resources;
- role model — defines access for different users within an account and a project.
Access within the role model
Learn more about access within the role model in the Access management in Servercore products instruction.
member
User with full access to all services.Access management is unavailable for users, service users, user groups, and federations.
iam.admin
User with access to user management and without access to services and billing.Cannot manage their account: modify permissions, manage notifications, delete the user.The first user with the iam.admin role is created by the Account Owner.
iam.viewer
A user with access to view everything that the iam.admin manages.
reader
A user with access to view everything that the member manages in the same access area.
vpc.admin
A user with access to managing cloud platform networks (private networks and subnets, public subnets and public IP addresses, cloud routers), cloud firewalls, security groups, and cloud load balancers.
vpc.viewer
A user with access to view everything that the vpc.admin manages in the same access area.
vpc.network_security.admin
A user with access to managing traffic restriction tools in cloud platform networks — cloud firewalls, security groups.
vpc.network_security.user
A user with access to view everything that the vpc.network_security.admin manages in the same access area.
vpc.network_security.viewer
A user with access to view everything that the vpc.network_security.admin manages in the same access area.