Access management in Selectel products
To segregate access to Selectel products, projects and users are used.
Upon account registration, a primary user is automatically created — the Account Owner, who has access to manage all account resources. The Account Owner can create additional users. Users can be of different types and can be granted permissions — assigning roles in a specific scope.
In addition to the Account Owner, other users can be managed by users with the iam.admin role. Learn more about the capabilities of each role in the Role Reference guide.
Users can be added to groups to manage multiple users as one.
You can manage users and roles in the Control Panel, using the IAM API, or with Terraform.
Records of access management operations are stored in audit logs.
Access management in some Selectel products is restricted.
Access management restrictions in some products
Some products and services do not support segregating resources into projects and may additionally have their own access system:
- VMware-based cloud products: VMware-based Public Cloud, Disaster Recovery to VMware-based Cloud, Remote Desktop Rental;
- Selectel Mail Service;
- Direct Connect;
- Global Connect;
- IP address management;
- DDoS protection;
- Resilient load balancer;
- AI marketplace, ML platform;
- backup and recovery products: Agent Backup (Veeam Agent), Veeam Cloud Connect Cloud Repository, Cyber Backup Cloud;
- Health Check (formerly Monitoring);
- Logs.
In S3, user access to a bucket can be modified according to an access policy; learn more in the Manage access to S3 guide.