Role reference
A role is a set of permitted operations on specific types of resources.
Roles are assigned within permissions. A role applies to the scope specified in the permission; learn more in the Access management in Selectel products instructions.
Some roles can be assigned only in a specific access scope, and may also have a different set of manageable resources across different access scopes.
Depending on the resources and settings they grant access to, roles are divided into:
- into global roles: define access to resources of all products in the selected scope (except for products that do not support access management), as well as to account, billing, and access settings;
- and product roles: determine access to resources of one or more products in the selected access scope. They do not allow managing other products, or account, billing, and access settings.
Full access to manage the account and resources, as well as exclusive permissions, belongs to the Account Owner — the user who registered the account. The Account Owner status is not a role and cannot be changed or assigned to anyone.
Role list
Global roles
member
The member role provides full access to manage all products and resources. It does not provide access to manage users, service users, user groups, and federations.
billing
The billing role provides access to billing management without access to service management.
iam.admin
The iam.admin role provides access to user management without access to services and billing. Cannot manage its own account: edit permissions, manage notifications, or delete the user. The first user with the iam.admin role can only be created by the Account Owner.
iam.viewer
The iam.viewer role provides view access to everything managed by iam.admin.
reader
The reader role provides view access to everything managed by member in the same scope.
audit_logs roles
audit_logs.admin
The audit_logs.admin role provides access to audit logs; learn more in the Manage access to audit logs instructions.
compute roles
compute.admin
The compute.admin role provides access to manage:
- cloud servers and flavors; learn more in the Manage access to cloud servers and flavors instructions;
- placement groups; learn more in the Manage access to cloud server placement groups instructions.
* To manage cloud servers, an additional role with access to manage Cloud Platform networks is required.
compute.viewer
The compute.viewer role provides view access to everything managed by compute.admin.
compute.server.user
The compute.server.user role provides access to manage cloud servers; learn more in the Manage access to cloud servers and flavors instructions.
* To manage cloud servers, an additional role with access to manage Cloud Platform networks, volumes, images, and backups is required.
compute.server.viewer
The compute.server.viewer role provides view access to everything managed by compute.server.user.
compute.flavor.admin
The compute.flavor.admin role provides access to manage cloud server flavors; learn more in the Manage access to cloud servers and flavors instructions.
compute.flavor.viewer
The compute.flavor.viewer role provides view access to everything managed by compute.flavor.admin.
compute.server_group.admin
The compute.server_group.admin role provides access to manage cloud server placement groups; learn more in the Manage access to cloud server placement groups instructions.
compute.server_group.viewer
The compute.server_group.viewer role provides view access to everything managed by compute.server_group.admin.
compute.volume.admin
The compute.volume.admin role provides access to manage cloud server volumes; learn more in the Manage access to cloud server volumes and snapshots instructions.
compute.volume.user
The compute.volume.user role provides access to manage cloud server volumes; learn more in the Manage access to cloud server volumes and snapshots instructions.
compute.volume.viewer
The compute.volume.viewer role provides view access to everything managed by compute.volume.user.
compute.snapshot.admin
The compute.snapshot.admin role provides access to manage volume snapshots; learn more in the Manage access to cloud server volumes and snapshots instructions.
compute.snapshot.viewer
The compute.snapshot.viewer role provides view access to everything managed by compute.snapshot.admin.
compute.image.admin
The compute.image.admin role provides access to manage images and configure image sharing; learn more in the Manage access to cloud server images instructions.
compute.image.user
The compute.image.user role provides access to manage images; learn more in the Manage access to cloud server images instructions.
compute.backup.admin
The compute.backup.admin role provides access to manage volume backups and backup plans; learn more in the Manage access to cloud server volume backups instructions.
compute.backup.viewer
The compute.backup.viewer role provides view access to everything managed by compute.backup.admin.
dedicated roles
dedicated.admin
The dedicated.admin role provides access to manage:
- dedicated servers; learn more in the Manage access to dedicated servers instructions;
- colocated equipment; learn more in the Manage access to colocated equipment instructions;
- firewalls; learn more in the Manage access to firewalls instructions;
- basic firewall; learn more in the Manage access to basic firewall instructions;
- storage systems; learn more in the Manage access to storage systems instructions;
- network drives for dedicated servers; learn more in the Manage access to network drives instructions;
- leased network hardware; learn more in the Manage access to leased network hardware instructions.
dedicated.viewer
A user with view access to everything managed by dedicated.admin in the same scope.
filestorage roles
filestorage.admin
The filestorage.admin role provides access to manage file storage; learn more in the Manage access to file storage instructions.
* To work with file storage, an additional role with access to manage Cloud Platform networks is required to connect the file storage network.
filestorage.viewer
The filestorage.viewer role provides view access to everything managed by filestorage.admin.
global_router roles
global_router.admin
The global_router.admin role provides access to manage global routers in an account; learn more in the Manage access to global router instructions.
* To manage connecting networks to a global router, the member role in the Project or Account scope is additionally required.
global_router.viewer
The global_router.viewer role provides view access to everything managed by global_router.admin.
go1c roles
go1c.admin
The go1c.admin role provides access to manage Turnkey 1C Cloud resources; learn more in the Manage access to Turnkey 1C Cloud instructions.
* To manage connecting backup storage, cluster data storage, and uploading an infobase from a .dt file, a combination of the s3.admin and iam.admin roles is additionally required.
** To manage connecting a cluster to a private network that has already been created in the project, the vpc.private_network.viewer role is additionally required.
go1c.viewer
The go1c.viewer role provides view access to everything managed by go1c.admin; learn more in the Manage access to Turnkey 1C Cloud instructions.
logs roles
logs.admin
The logs.admin role provides access to manage logs; learn more in the Manage access to logs instructions.
logs.writer
The logs.writer role provides access to add logs to the Logs service; learn more in the Manage access to logs instructions.
logs.viewer
The logs.viewer role provides view access to logs; learn more in the Manage access to logs instructions.
metrics roles
metrics.admin
The metrics.admin role provides access to manage metrics; learn more in the Manage access to metrics instructions.
mobile_farm roles
mobile_farm.admin
The mobile_farm.admin role provides access to manage mobile farm in their project; learn more in the Manage access to mobile farm instructions.
mobile_farm.user
The mobile_farm.user role provides access to use mobile farm devices in their project; learn more in the Manage access to mobile farm instructions.
mobile_farm.viewer
The mobile_farm.viewer role provides view access to everything managed by mobile_farm.admin.
secrets roles
secrets.admin
The secrets.admin role provides access to manage secrets in Secrets Manager; learn more in the Manage access to Secrets Manager instructions.
secrets.viewer
The secrets.viewer role provides view access to everything managed by secrets.admin; learn more in the Manage access to Secrets Manager instructions.
secrets.consumer
The secrets.consumer role provides access to view and use secrets in Secrets Manager; learn more in the Manage access to Secrets Manager instructions.
s3 and object_storage roles
s3.admin
The s3.admin role provides access to manage S3 within a project; learn more in the Manage access to S3 instructions.
s3.user
The s3.user role provides access to view the list of buckets in a project and manage an S3 bucket if an access policy is configured on the bucket that allows access to this user; learn more in the Manage access to S3 instructions. The level of access to a bucket is determined by the access policy settings. If no access policy is created, the user has no access to the bucket.
Differs from a user with the s3.bucket.user role only in that it has access to view the list of buckets in the project.
s3.bucket.user
The s3.bucket.user role provides access to an S3 bucket if an access policy is configured on the bucket that allows access to this user; learn more in the Manage access to S3 instructions. The level of access to a bucket is determined by the access policy settings. If no access policy is created, the user has no access to the bucket.
Differs from a user with the s3.user role only in that it does not have access to view the list of buckets in the project.
object_storage:admin
The object_storage:admin role will be removed soon and cannot be assigned to new users. Existing users with the object_storage:admin role continue to work.
Legacy version of the s3.admin role. Has identical permissions.
object_storage_user
The object_storage_user role will be removed soon and cannot be assigned to new users. Existing users with the object_storage_user role continue to work.
Legacy version of the s3.user role. Has identical permissions.
vpc roles
vpc.admin
The vpc.admin role provides access to manage:
- Cloud Platform networks (private networks and subnets, public subnets and public IP addresses, cloud routers); learn more in the Manage access to Cloud Platform networks instructions;
- cloud firewalls; learn more in the Manage access to cloud firewall instructions;
- security groups; learn more in the Manage access to security groups instructions;
- cloud load balancers; learn more in the Manage access to cloud load balancer instructions.
Adding ports to a cloud server and deleting ports added to a cloud server is unavailable; the compute.admin or compute.server.user role is required for this.
* To manage connecting a subnet to a global router, the global_router.admin role is additionally required.
vpc.viewer
The vpc.viewer role provides view access to everything managed by vpc.admin in the same scope.
vpc.private_network.admin
The vpc.private_network.admin role provides access to manage:
- Cloud Platform networks (private networks, subnets, and ports); learn more in the Manage access to Cloud Platform networks instructions;
- private DNS; learn more in the Manage access to private DNS instructions.
Adding ports to a cloud server and deleting ports added to a cloud server is unavailable; the member role is required for this.
* To manage connecting a subnet to a cloud router, the vpc.external_access.admin role is additionally required. To connect to a global router, the global_router.admin role is required.
vpc.private_network.viewer
The vpc.private_network.viewer role provides view access to everything managed by vpc.private_network.admin in the same scope.
vpc.external_access.admin
The vpc.external_access.admin role provides access to manage objects for internet access: public subnets, direct public IP addresses and public floating IP addresses, and cloud routers. Learn more in the Manage access to Cloud Platform networks instructions.
Adding ports to a cloud server and deleting ports added to a cloud server is unavailable; the compute.admin or compute.server.user role is required for this.
* To manage connecting a private subnet to a cloud router, the vpc.private_network.admin role is additionally required.
vpc.external_access.user
The vpc.external_access.user role provides access:
- to view everything managed by vpc.external_access.admin in the same scope;
- to manage public floating IP addresses; learn more in the Manage access to Cloud Platform networks instructions.
Adding ports to a cloud server and deleting ports added to a cloud server is unavailable; the compute.admin or compute.server.user role is required for this.
vpc.external_access.viewer
The vpc.external_access.viewer role provides view access to everything managed by vpc.external_access.admin in the same scope.
vpc.network_security.admin
The vpc.network_security.admin role provides access to manage traffic restriction tools:
- cloud firewalls; learn more in the Manage access to cloud firewall instructions;
- security groups; learn more in the Manage access to security groups instructions.
* To view security groups and manage port assignments, the vpc.private_network.viewer or vpc.external_access.viewer role is additionally required.
** To download a report, a combination of the vpc.private_network.viewer and vpc.external_access.viewer roles, or the vpc.viewer role is additionally required.
vpc.network_security.user
The vpc.network_security.user role provides access:
- to view everything managed by vpc.network_security.admin in the same scope;
- to manage security groups on ports in a private or public network; learn more in the Manage access to security groups instructions.
* To download a report, a combination of the vpc.private_network.viewer and vpc.external_access.viewer roles, or the vpc.viewer role is additionally required.
vpc.network_security.viewer
The vpc.network_security.viewer role provides view access to everything managed by vpc.network_security.admin in the same scope.
* To download a report, a combination of the vpc.private_network.viewer and vpc.external_access.viewer roles, or the vpc.viewer role is additionally required.
vpc.load_balancer.admin
The vpc.load_balancer.admin role provides access to manage cloud load balancers; learn more in the Manage access to cloud load balancer instructions.
* To create a load balancer, one or more roles are additionally required. Additional roles depend on the network where the load balancer will be created:
- vpc.admin to create a load balancer in any subnet;
- vpc.private_network.admin to create a load balancer in a private subnet;
- vpc.external_access.admin to create a load balancer in a public subnet;
- a combination of the vpc.private_network.admin and vpc.external_access.admin roles to create a load balancer in a private subnet with a public IP address;
vpc.load_balancer.viewer
The vpc.load_balancer.viewer role provides view access to everything managed by vpc.load_balancer.admin in the same scope.