Skip to main content

Role reference

A role is a set of permitted operations on specific types of resources.

Roles are assigned within permissions. A role applies to the scope specified in the permission; learn more in the Access management in Selectel products instructions.

Some roles can be assigned only in a specific access scope, and may also have a different set of manageable resources across different access scopes.

Depending on the resources and settings they grant access to, roles are divided into:

  • into global roles: define access to resources of all products in the selected scope (except for products that do not support access management), as well as to account, billing, and access settings;
  • and product roles: determine access to resources of one or more products in the selected access scope. They do not allow managing other products, or account, billing, and access settings.

Full access to manage the account and resources, as well as exclusive permissions, belongs to the Account Owner — the user who registered the account. The Account Owner status is not a role and cannot be changed or assigned to anyone.

Role list

Role groupRole listWhat it manages
Global rolesmemberAll products, account, billing, projects
billingBilling
iam.adminAccess settings
iam.viewerView access settings only
readerAll products, account, billing, projects (view only)
audit_logsaudit_logs.adminAudit logs
compute
  • cloud servers and flavors;
  • cloud server placement groups;
  • cloud server network drives and snapshots;
  • cloud server images;
  • cloud server network drive backups
dedicated
  • dedicated servers;
  • colocated equipment;
  • firewalls;
  • basic firewall;
  • storage system;
  • network drives for dedicated servers;
  • leased network equipment
filestorageFile storage
global_routerGlobal router
go1cTurnkey 1C Cloud
logsLogs
metricsmetrics.adminMetrics
mobile_farmMobile farm
secretsSecrets Manager
s3 and object_storageS3
vpc
  • Cloud Platform networks;
  • cloud firewalls;
  • security groups;
  • cloud load balancers;
  • private DNS

Global roles

member

The member role provides full access to manage all products and resources. It does not provide access to manage users, service users, user groups, and federations.

Access scopes
  • account;
  • project
Assignable to
  • users;
  • service users;
  • user groups
Available operations

In the Account access scope:

  • manage projects, their limits, and quotas;
  • manage billing;
  • manage resources in all projects;
  • manage resources outside projects;
  • work with audit logs

In the Project access scope:

  • manage resources in the selected project

billing

The billing role provides access to billing management without access to service management.

Access scopesAccount
Assignable to
  • users;
  • service users;
  • user groups
Available operations
  • manage billing:

    • top up balance and transfer funds between balances;
    • manage auto-recharge, monthly payments, deferred payments;
    • manage balance notifications;
    • manage bank cards;
    • view reporting documents;
    • manage partner program and withdrawals;
  • view active services and service statuses

iam.admin

The iam.admin role provides access to user management without access to services and billing. Cannot manage its own account: edit permissions, manage notifications, or delete the user. The first user with the iam.admin role can only be created by the Account Owner.

Access scopesAccount
Assignable to
  • users;
  • service users;
  • user groups
Available operations
  • manage users, service users, user groups;
  • manage federations;
  • issue keys to users;
  • manage notifications of other users;
  • configure account access restrictions

iam.viewer

The iam.viewer role provides view access to everything managed by iam.admin.

Access scopesAccount
Assignable to
  • users;
  • service users;
  • user groups
Available operations

reader

The reader role provides view access to everything managed by member in the same scope.

Access scopes
  • account;
  • project
Assignable to
  • users;
  • service users;
  • user groups
Available operations

In the Account access scope:

  • view resources across all projects, as well as resources not assigned to a project;
  • view settings of all projects, their limits, and quotas;
  • view billing data (balance, bank cards, reporting documents, partner program, etc.)

In the Project access scope:

  • view resources in the selected project

audit_logs roles

audit_logs.admin

The audit_logs.admin role provides access to audit logs; learn more in the Manage access to audit logs instructions.

Access scopes

Account

Assignable to
  • users;
  • service users;
  • user groups
Available operations

Export audit logs

compute roles

compute.admin

The compute.admin role provides access to manage:

Access scopes
  • account;
  • project
Assignable to
  • users;
  • service users;
  • user groups
Available operations

In the Account access scope:

  • view quotas of all projects (default quotas, modified quota values, and used quotas);
  • manage cloud servers (create, edit, delete) * in all projects;
  • use the console;
  • manage flavors (create, edit, delete) in all projects;
  • manage SSH keys (add, delete) in all projects;
  • manage placement groups (create, delete) in all projects

In the Project access scope:

  • view project quotas (default quotas, modified quota values, and used quotas);
  • manage cloud servers (create, edit, delete) * in their project;
  • use the console;
  • manage flavors (create private flavors, edit, delete) in their project;
  • manage SSH keys (add, delete) in their project;
  • manage placement groups (create, delete) in their project

* To manage cloud servers, an additional role with access to manage Cloud Platform networks is required.

compute.viewer

The compute.viewer role provides view access to everything managed by compute.admin.

Access scopes
  • account;
  • project
Assignable to
  • users;
  • service users;
  • user groups
Available operations

In the Account access scope:

  • view quotas of all projects (default quotas, modified quota values, and used quotas);
  • view a list of cloud servers and information about them (server type, configuration type, vCPU count, memory size, attached drives, security groups, network settings, tags) in all projects;
  • view cloud server statistics in all projects;
  • view a list of flavors and information about them (flavor name, vCPU count, RAM, and local drive size) in all projects;
  • view a list of SSH keys and information about them in all projects;
  • view a list of placement groups and information about them (group name, placement policy condition) in all projects

In the Project access scope:

  • view project quotas (default quotas, modified quota values, and used quotas);
  • view a list of cloud servers and information about them (server type, configuration type, vCPU count, memory size, attached drives, security groups, network settings, tags) in their project;
  • view cloud server statistics in their project;
  • view a list of flavors and information about them (flavor name, vCPU count, RAM, and local drive size) in their project;
  • view a list of SSH keys and information about them in their project;
  • view a list of placement groups and information about them (group name, placement policy condition) in their project

compute.server.user

The compute.server.user role provides access to manage cloud servers; learn more in the Manage access to cloud servers and flavors instructions.

Access scopes
  • account;
  • project
Assignable to
  • users;
  • service users;
  • user groups
Available operations

In the Account access scope:

  • view quotas of all projects (default quotas, modified quota values, and used quotas);
  • manage cloud servers (create, edit, delete) * in all projects;
  • use the console;
  • view a list of flavors and information about them in all projects: flavor name, vCPU count, RAM, and local drive size in all projects;
  • manage SSH keys (add, delete) in all projects

In the Project access scope:

  • view project quotas (default quotas, modified quota values, and used quotas);
  • manage cloud servers (create, edit, delete) * in their project;
  • use the console;
  • view a list of flavors and information about them in their project: flavor name, vCPU count, RAM, and local drive size;
  • manage SSH keys (add, delete) in their project

* To manage cloud servers, an additional role with access to manage Cloud Platform networks, volumes, images, and backups is required.

compute.server.viewer

The compute.server.viewer role provides view access to everything managed by compute.server.user.

Access scopes
  • account;
  • project
Assignable to
  • users;
  • service users;
  • user groups
Available operations

In the Account access scope:

  • view quotas of all projects (default quotas, modified quota values, and used quotas);
  • view a list of cloud servers and information about them in all projects: server type, configuration type, vCPU count, memory size, attached drives, security groups, network settings, tags;
  • view cloud server statistics in all projects;
  • view a list of flavors and information about them in all projects: flavor name, vCPU count, RAM, and local drive size;
  • view a list of SSH keys and information about them in all projects

In the Project access scope:

  • view project quotas (default quotas, modified quota values, and used quotas);
  • view a list of cloud servers and information about them in their project: server type, configuration type, vCPU count, memory size, attached drives, security groups, network settings, tags;
  • view cloud server statistics in their project;
  • view a list of flavors and information about them in their project: flavor name, vCPU count, RAM, and local drive size;
  • view a list of SSH keys and information about them in their project

compute.flavor.admin

The compute.flavor.admin role provides access to manage cloud server flavors; learn more in the Manage access to cloud servers and flavors instructions.

Access scopes
  • account;
  • project
Assignable to
  • users;
  • service users;
  • user groups
Available operations

In the Account access scope:

  • view quotas of all projects (default quotas) in all projects;
  • manage flavors (create private flavors, edit, delete) in all projects;
  • view a list of SSH keys and information about them in all projects

In the Project access scope:

  • view project quotas (default quotas) in their project;
  • manage flavors (create private flavors, edit, delete) in their project;
  • view a list of SSH keys and information about them in their project

compute.flavor.viewer

The compute.flavor.viewer role provides view access to everything managed by compute.flavor.admin.

Access scopes
  • account;
  • project
Assignable to
  • users;
  • service users;
  • user groups
Available operations

In the Account access scope:

  • view quotas of all projects (default quotas);
  • view a list of flavors and information about them in all projects: flavor name, vCPU count, RAM, and local drive size;
  • view a list of SSH keys and information about them in all projects

In the Project access scope:

  • view project quotas (default quotas);
  • view a list of flavors and information about them in their project: flavor name, vCPU count, RAM, and local drive size;
  • view a list of SSH keys and information about them in their project

compute.server_group.admin

The compute.server_group.admin role provides access to manage cloud server placement groups; learn more in the Manage access to cloud server placement groups instructions.

Access scopes
  • account;
  • project
Assignable to
  • users;
  • service users;
  • user groups
Available operations

In the Account access scope:

  • view quotas of all projects (default quotas);
  • manage placement groups (create, delete) in all projects;
  • view a list of flavors and information about them in all projects: flavor name, vCPU count, RAM, and local drive size;
  • view a list of SSH keys and information about them in all projects

In the Project access scope:

  • view project quotas (default quotas) in their project;
  • manage placement groups (create, delete) in their project;
  • view a list of flavors and information about them in their project: flavor name, vCPU count, RAM, and local drive size;
  • view a list of SSH keys and information about them in their project

compute.server_group.viewer

The compute.server_group.viewer role provides view access to everything managed by compute.server_group.admin.

Access scopes
  • account;
  • project
Assignable to
  • users;
  • service users;
  • user groups
Available operations

In the Account access scope:

  • get quotas of all projects;
  • view a list of placement groups and information about them in all projects: group name, placement policy condition;
  • view a list of flavors and information about them in all projects: flavor name, vCPU count, RAM, and local drive size;
  • view a list of SSH keys and information about them in all projects

In the Project access scope:

  • get project quotas;
  • view a list of placement groups and information about them in their project: group name, placement policy condition;
  • view a list of flavors and information about them in their project: flavor name, vCPU count, RAM, and local drive size;
  • view a list of SSH keys and information about them in their project

compute.volume.admin

The compute.volume.admin role provides access to manage cloud server volumes; learn more in the Manage access to cloud server volumes and snapshots instructions.

Access scopes
  • account;
  • project
Assignable to
  • users;
  • service users;
  • user groups
Available operations

In the Account access scope:

  • view a list of all network drives and information about them in all projects: drive type, drive size;
  • manage drives (create, edit, delete) in all projects;
  • transfer drives between projects;
  • view information about drive transfers in all projects

In the Project access scope:

  • view a list of all network drives and information about them in their project: drive type, drive size;
  • manage drives (create, edit, delete) in their project;
  • transfer drives from their project to another;
  • view information about drive transfers in their project

compute.volume.user

The compute.volume.user role provides access to manage cloud server volumes; learn more in the Manage access to cloud server volumes and snapshots instructions.

Access scopes
  • account;
  • project
Assignable to
  • users;
  • service users;
  • user groups
Available operations

In the Account access scope:

  • view a list of all network drives and information about them (drive type, drive size) in all projects;
  • manage drives (create, edit, delete) in all projects

In the Project access scope:

  • view a list of all network drives and information about them (drive type, drive size) in their project;
  • manage drives (create, edit, delete) in their project

compute.volume.viewer

The compute.volume.viewer role provides view access to everything managed by compute.volume.user.

Access scopes
  • account;
  • project
Assignable to
  • users;
  • service users;
  • user groups
Available operations

In the Account access scope:

  • view a list of network drives and information about them (drive type, drive size) in all projects

In the Project access scope:

  • view a list of network drives and information about them (drive type, drive size) in their project

compute.snapshot.admin

The compute.snapshot.admin role provides access to manage volume snapshots; learn more in the Manage access to cloud server volumes and snapshots instructions.

Access scopes
  • account;
  • project
Assignable to
  • users;
  • service users;
  • user groups
Available operations

In the Account access scope:

  • view a list of snapshots and information about them (snapshot size, creation date, and status) in all projects;
  • manage snapshots (create, delete) in all projects

In the Project access scope:

  • view a list of snapshots and information about them (snapshot size, creation date, and status) in their project;
  • manage snapshots (create, delete) in their project

compute.snapshot.viewer

The compute.snapshot.viewer role provides view access to everything managed by compute.snapshot.admin.

Access scopes
  • account;
  • project
Assignable to
  • users;
  • service users;
  • user groups
Available operations

In the Account access scope:

  • view a list of snapshots and information about them (snapshot size, creation date, and status) in all projects

In the Project access scope:

  • view a list of snapshots and information about them (snapshot size, creation date, and status) in their project

compute.image.admin

The compute.image.admin role provides access to manage images and configure image sharing; learn more in the Manage access to cloud server images instructions.

Access scopes
  • account;
  • project
Assignable to
  • users;
  • service users;
  • user groups
Available operations

In the Account access scope:

  • view a list of images and information about them in all projects: image size, image and container format, minimum image requirements;
  • manage images (upload, create, edit, delete) in all projects;
  • configure sharing images with projects in the same account or from other accounts

In the Project access scope:

  • view a list of images and information about them in their project: image size, image and container format, minimum image requirements;
  • manage images (upload, create, edit, delete) in their project;
  • configure sharing images with projects in the same account or from other accounts

compute.image.user

The compute.image.user role provides access to manage images; learn more in the Manage access to cloud server images instructions.

Access scopes
  • account;
  • project
Assignable to
  • users;
  • service users;
  • user groups
Available operations

In the Account access scope:

  • view a list of images and information about them in all projects: image size, image and container format, minimum image requirements;
  • manage images (upload, create, edit, delete) in all projects

In the Project access scope:

  • view a list of images and information about them in their project: image size, image and container format, minimum image requirements;
  • manage images (upload, create, edit, delete) in their project

compute.backup.admin

The compute.backup.admin role provides access to manage volume backups and backup plans; learn more in the Manage access to cloud server volume backups instructions.

Access scopes
  • account;
  • project
Assignable to
  • users;
  • service users;
  • user groups
Available operations

In the Account access scope:

  • view a list of backups and information about them (backup type, size, attached backup plans, status) in all projects;
  • manage backups (create, delete) in all projects;
  • view a list of backup plans in all projects;
  • manage backup plans (create, edit, delete) in all projects

In the Project access scope:

  • view a list of backups and information about them (backup type, size, attached backup plans, status) in their project;
  • manage backups (create, delete) in their project;
  • view a list of all backup plans in their project;
  • manage backup plans (create, edit, delete) in their project

compute.backup.viewer

The compute.backup.viewer role provides view access to everything managed by compute.backup.admin.

Access scopes
  • account;
  • project
Assignable to
  • users;
  • service users;
  • user groups
Available operations

In the Account access scope:

  • view a list of backups and information about them (backup type, size, attached backup plans, status) in all projects;
  • view a list of backup plans in all projects

In the Project access scope:

  • view a list of backups and information about them (backup type, size, attached backup plans, status) in their project;
  • view a list of backup plans in their project

dedicated roles

dedicated.admin

The dedicated.admin role provides access to manage:

Access scopes
  • account;
  • project
Assignable to
  • users;
  • service users;
  • user groups
Available operations

In the Account access scope:

  • view the list of projects;
  • manage dedicated servers (order, change, cancel) in all projects;
  • manage colocated equipment (order, change, cancel) in all projects;
  • manage networks;
  • enable and disable additional services;
  • view a list of SSH keys, add SSH keys to storage, and manage added SSH keys;
  • manage firewalls (order, change, cancel);
  • manage network drives (create, edit, delete);
  • manage storage systems (order, change, cancel);
  • manage the basic firewall (create, edit, delete);
  • manage leased equipment (order, change, cancel)

In the Project access scope:

  • manage dedicated servers (order, change, cancel) in their project;

  • manage colocated equipment (order, change, cancel) in their project;

  • enable and disable additional services;

  • view a list of SSH keys added to storage and information about them;

  • cannot view or manage:

    • networks;
    • firewalls;
    • network drives and storage systems;
    • the basic firewall;
    • leased network equipment

dedicated.viewer

A user with view access to everything managed by dedicated.admin in the same scope.

Access scopes
  • account;
  • project
Assignable to
  • users;
  • service users;
  • user groups
Available operations

In the Account access scope:

  • view a list of all dedicated servers and information about them in all projects;
  • view a list of colocated equipment and information about it in all projects;
  • view a list of all VLANs, public and private subnets, SAN networks, and information about them;
  • view a list of network drives and storage systems and information about them;
  • view a list of firewalls and information about them;
  • view a list of basic firewalls and information about them;
  • view a list of leased network equipment and information about it;
  • view a list of SSH keys added to storage and information about them

In the Project access scope:

  • view a list of dedicated servers and information about them in their project;

  • view a list of colocated equipment and information about it in their project;

  • view a list of SSH keys added to storage and information about them;

  • cannot view or manage:

    • networks;
    • network drives and storage systems;
    • firewalls;
    • the basic firewall;
    • leased network equipment

filestorage roles

filestorage.admin

The filestorage.admin role provides access to manage file storage; learn more in the Manage access to file storage instructions.

Access scopes
  • account;
  • project
Assignable to
  • users;
  • service users;
  • user groups
Available operations

In the Account access scope:

  • view a list of file storages and information about them in all projects: name, size, storage type and protocol, IP and network name, status;
  • view access rules for file storages in all projects;
  • create and manage file storages * in all projects;
  • create and manage access rules in all projects

In the Project access scope:

  • view a list of file storages and information about them in their project: name, size, storage type and protocol, IP and network name, status;
  • view access rules for file storages in their project;
  • create and manage file storages * in their project;
  • create and manage access rules in their project

* To work with file storage, an additional role with access to manage Cloud Platform networks is required to connect the file storage network.

filestorage.viewer

The filestorage.viewer role provides view access to everything managed by filestorage.admin.

Access scopes
  • account;
  • project
Assignable to
  • users;
  • service users;
  • user groups
Available operations

In the Account access scope:

  • view a list of file storages and information about them in all projects: name, size, storage type and protocol, IP and network name, status;
  • view access rules for file storages in all projects

In the Project access scope:

  • view a list of file storages and information about them in their project: name, size, storage type and protocol, IP and network name, status;
  • view access rules for file storages in their project

global_router roles

global_router.admin

The global_router.admin role provides access to manage global routers in an account; learn more in the Manage access to global router instructions.

Access scopesAccount
Assignable to
  • users;
  • service users;
  • user groups
Available operations
  • view a list of global routers, networks and subnets connected to them, list of static routes on a router;
  • manage global routers (create, edit, delete);
  • add, edit, and delete static routes on a global router;
  • change names of networks and subnets connected to a global router;
  • connect an existing or new Cloud Platform network and subnet to a global router *;
  • connect an existing or new dedicated server network and subnet to a global router *;
  • remove a Cloud Platform network or subnet from a global router network, including deleting the Cloud Platform network or subnet itself *;
  • remove a dedicated server network or subnet from a global router network *

* To manage connecting networks to a global router, the member role in the Project or Account scope is additionally required.

global_router.viewer

The global_router.viewer role provides view access to everything managed by global_router.admin.

Access scopesAccount
Assignable to
  • users;
  • service users;
  • user groups
Available operationsView a list of global routers, networks and subnets connected to them, list of static routes on a router

go1c roles

go1c.admin

The go1c.admin role provides access to manage Turnkey 1C Cloud resources; learn more in the Manage access to Turnkey 1C Cloud instructions.

Access scopes
  • account;
  • project
Assignable to
  • users;
  • service users;
  • user groups
Available operations

In the Account access scope:

  • manage 1C server clusters in all projects * **;
  • manage infobases in all projects *;
  • manage databases in all projects;
  • manage backups in all projects *;
  • manage Prometheus tokens for metric collection in all projects

In the Project access scope:

  • manage 1C server clusters in their project * **;
  • manage infobases in their project;
  • manage databases in their project *;
  • manage backups in their project *;
  • manage Prometheus tokens for metric collection in their project

* To manage connecting backup storage, cluster data storage, and uploading an infobase from a .dt file, a combination of the s3.admin and iam.admin roles is additionally required.

** To manage connecting a cluster to a private network that has already been created in the project, the vpc.private_network.viewer role is additionally required.

go1c.viewer

The go1c.viewer role provides view access to everything managed by go1c.admin; learn more in the Manage access to Turnkey 1C Cloud instructions.

Access scopes
  • account;
  • project
Assignable to
  • users;
  • service users;
  • user groups
Available operations

In the Account access scope:

  • view 1C server clusters in all projects;
  • view infobases in all projects;
  • view databases in all projects;
  • view backups in all projects;
  • view a list of generated Prometheus tokens for metric collection in all projects

In the Project access scope:

  • view 1C server clusters in their project;
  • view infobases in their project;
  • view databases in their project;
  • view backups in their project;
  • view a list of generated Prometheus tokens for metric collection in their project

logs roles

logs.admin

The logs.admin role provides access to manage logs; learn more in the Manage access to logs instructions.

Access scopes
  • account;
  • project
Assignable to
  • users;
  • service users;
  • user groups
Available operations

In the Account access scope:

  • view logs in the control panel and using available tools in all projects;
  • manage custom logs in all projects;
  • manage log groups and event streams in all projects

In the Project access scope:

  • view logs in the control panel and using available tools in their project;
  • manage custom logs in their project;
  • manage log groups and event streams in their project

logs.writer

The logs.writer role provides access to add logs to the Logs service; learn more in the Manage access to logs instructions.

Access scopes
  • account;
  • project
Assignable to
  • users;
  • service users;
  • user groups
Available operations

In the Account access scope:

  • add logs from custom storage using available tools in all projects;
  • create log groups and event streams in all projects

In the Project access scope:

  • add logs from custom storage using available tools in their project;
  • create log groups and event streams in their project

logs.viewer

The logs.viewer role provides view access to logs; learn more in the Manage access to logs instructions.

Access scopes
  • account;
  • project
Assignable to
  • users;
  • service users;
  • user groups
Available operations

In the Account access scope:

  • view logs in the control panel and using available tools in all projects

In the Project access scope:

  • view logs in the control panel and using available tools in their project

metrics roles

metrics.admin

The metrics.admin role provides access to manage metrics; learn more in the Manage access to metrics instructions.

Access scopes
  • account;
  • project
Assignable to
  • users;
  • service users;
  • user groups
Available operations

In the Account access scope:

  • collect metrics in all projects

In the Project access scope:

  • collect metrics in their project

mobile_farm roles

mobile_farm.admin

The mobile_farm.admin role provides access to manage mobile farm in their project; learn more in the Manage access to mobile farm instructions.

Access scopesProject
Assignable to
  • users;
  • service users;
  • user groups
Available operations
  • view Mobile Device Farm consumption in their project;
  • add and delete Mobile Device Farm devices in their project;
  • use Mobile Device Farm devices in their project;
  • change billing for Mobile Device Farm devices in their project;
  • add ADB and Proxy keys to their profile;
  • modify Mobile Device Farm firewall rules

mobile_farm.user

The mobile_farm.user role provides access to use mobile farm devices in their project; learn more in the Manage access to mobile farm instructions.

Access scopesProject
Assignable to
  • users;
  • service users;
  • user groups
Available operations
  • view Mobile Device Farm consumption in their project;
  • use Mobile Device Farm devices in their project;
  • add ADB and Proxy keys to their profile;
  • view Mobile Device Farm firewall rules

mobile_farm.viewer

The mobile_farm.viewer role provides view access to everything managed by mobile_farm.admin.

Access scopesProject
Assignable to
  • users;
  • service users;
  • user groups
Available operations
  • view Mobile Device Farm consumption in their project;
  • view Mobile Device Farm devices in their project;
  • add ADB and Proxy keys to their profile;
  • view Mobile Device Farm firewall rules

secrets roles

secrets.admin

The secrets.admin role provides access to manage secrets in Secrets Manager; learn more in the Manage access to Secrets Manager instructions.

Access scopes
  • account;
  • project
Assignable to
  • users;
  • service users;
  • user groups
Available operations

In the Account access scope:

  • manage secrets (add, delete) in all projects;
  • manage secret versions (add, change current version, delete) in all projects;
  • view secret contents in all projects

In the Project access scope:

  • manage secrets (add, delete) in their project;
  • manage secret versions (add, change current version, delete) in their project;
  • view secret contents in their project

secrets.viewer

The secrets.viewer role provides view access to everything managed by secrets.admin; learn more in the Manage access to Secrets Manager instructions.

Access scopes
  • account;
  • project
Assignable to
  • users;
  • service users;
  • user groups
Available operations

In the Account access scope:

  • view a list of secrets and information about them, except for secret contents, in all projects

In the Project access scope:

  • view a list of secrets and information about them, except for secret contents, in their project

secrets.consumer

The secrets.consumer role provides access to view and use secrets in Secrets Manager; learn more in the Manage access to Secrets Manager instructions.

Access scopes
  • account;
  • project
Assignable to
  • users;
  • service users;
  • user groups
Available operations

In the Account access scope:

  • view a list of secrets and information about them in all projects;
  • view secret contents in all projects

In the Project access scope:

  • view a list of secrets and information about them in their project;
  • view secret contents in their project

s3 and object_storage roles

s3.admin

The s3.admin role provides access to manage S3 within a project; learn more in the Manage access to S3 instructions.

Access scopesProject
Assignable toService users
Available operations
  • view a list of buckets in their project;
  • view bucket contents in their project;
  • manage bucket objects (upload, edit, delete) in their project;
  • change bucket settings in their project;
  • configure bucket access policies in their project

s3.user

The s3.user role provides access to view the list of buckets in a project and manage an S3 bucket if an access policy is configured on the bucket that allows access to this user; learn more in the Manage access to S3 instructions. The level of access to a bucket is determined by the access policy settings. If no access policy is created, the user has no access to the bucket.

Differs from a user with the s3.bucket.user role only in that it has access to view the list of buckets in the project.

Access scopesProject
Assignable toService users
Available operations
  • view a list of buckets in their project;
  • operations in a specific bucket permitted by its access policy

s3.bucket.user

The s3.bucket.user role provides access to an S3 bucket if an access policy is configured on the bucket that allows access to this user; learn more in the Manage access to S3 instructions. The level of access to a bucket is determined by the access policy settings. If no access policy is created, the user has no access to the bucket.

Differs from a user with the s3.user role only in that it does not have access to view the list of buckets in the project.

Access scopesProject
Assignable toService users
Available operationsOperations in a specific bucket permitted by its access policy

object_storage:admin

For your information

The object_storage:admin role will be removed soon and cannot be assigned to new users. Existing users with the object_storage:admin role continue to work.

Legacy version of the s3.admin role. Has identical permissions.

object_storage_user

For your information

The object_storage_user role will be removed soon and cannot be assigned to new users. Existing users with the object_storage_user role continue to work.

Legacy version of the s3.user role. Has identical permissions.

vpc roles

vpc.admin

The vpc.admin role provides access to manage:

Adding ports to a cloud server and deleting ports added to a cloud server is unavailable; the compute.admin or compute.server.user role is required for this.

Access scopes
  • account;
  • project
Assignable to
  • users;
  • service users;
  • user groups
Available operations

In the Account access scope:

  • view a list of:

    • all cloud platform network resources and information about them in all projects;
    • all balancer objects and information about them in all projects: load balancers, rules and HTTP policies, target groups and servers in them, health checks;
    • cloud firewalls and information about them in all projects;
    • security groups and information about them in all projects;
  • manage private networks, subnets, and ports in all projects *;

  • manage public subnets, direct public IP addresses, and public floating IP addresses in all projects;

  • manage cloud routers in all projects;

  • manage load balancers, rules and HTTP policies, target groups, health checks, balancer logging in all projects, as well as view load balancer statistics in all projects;

  • manage cloud firewalls in all projects;

  • manage security groups, rules, and ports in all projects, as well as download security group reports in all projects

In the Project access scope:

  • view a list of:

    • all cloud platform network resources and information about them in their project;
    • all balancer objects and information about them in their project: load balancers, rules and HTTP policies, target groups and servers in them, health checks;
    • cloud firewalls and information about them in their project;
    • security groups and information about them in their project;
  • manage private networks, subnets, and ports in their project *;

  • manage public subnets, direct public IP addresses, and public floating IP addresses in their project;

  • manage cloud routers in their project;

  • manage load balancers, rules and HTTP policies, target groups, health checks, balancer logging in all projects, as well as view load balancer statistics in their project;

  • manage cloud firewalls in their project;

  • manage security groups, rules, and ports in their project, as well as download security group reports in their project

* To manage connecting a subnet to a global router, the global_router.admin role is additionally required.

vpc.viewer

The vpc.viewer role provides view access to everything managed by vpc.admin in the same scope.

Access scopesAccount
Assignable to
  • users;
  • service users;
  • user groups
Available operations

In the Account access scope:

  • view a list of:

    • all cloud platform network resources and information about them in all projects;
    • cloud firewalls and information about them in all projects;
    • the list of security groups and information about them in all projects;
  • download security group reports in all projects

In the Project access scope:

  • view a list of:
    • all cloud platform network resources and information about them in their project
    • cloud firewalls and information about them in their project;
    • the list of security groups and information about them in their project;
  • download security group reports in their project

vpc.private_network.admin

The vpc.private_network.admin role provides access to manage:

Adding ports to a cloud server and deleting ports added to a cloud server is unavailable; the member role is required for this.

Access scopes
  • account;
  • project
Assignable to
  • users;
  • service users;
  • user groups
Available operations

In the Account access scope:

  • view:

    • a list of private networks, subnets, ports, and information about them in all projects;
    • information about connecting a network to a private DNS resolver, view a list of zones and resource records in zones in all projects;
  • manage private networks, subnets, and ports in all projects *;

  • manage private DNS in all projects

In the Project scope:

  • view:

    • a list of private networks, subnets, ports, and information about them in their project;
    • information about connecting a network to a private DNS resolver, viewing a list of zones and resource records in zones in their project;
  • manage private networks, subnets, and ports in their project *;

  • manage private DNS in their project

* To manage connecting a subnet to a cloud router, the vpc.external_access.admin role is additionally required. To connect to a global router, the global_router.admin role is required.

vpc.private_network.viewer

The vpc.private_network.viewer role provides view access to everything managed by vpc.private_network.admin in the same scope.

Scopes
  • account;
  • project
Who it can be assigned to
  • users;
  • service users;
  • user groups
Available operations

In the Account scope:

  • view a list of private networks, subnets, ports, and information about them in all projects;
  • view information about connecting a network to a private DNS resolver, view a list of zones and resource records in zones in all projects

In the Project scope:

  • view a list of private networks, subnets, ports, and information about them in their project;
  • view information about connecting a network to a private DNS resolver, view a list of zones and resource records and information about them in their project

vpc.external_access.admin

The vpc.external_access.admin role provides access to manage objects for internet access: public subnets, direct public IP addresses and public floating IP addresses, and cloud routers. Learn more in the Manage access to Cloud Platform networks instructions.

Adding ports to a cloud server and deleting ports added to a cloud server is unavailable; the compute.admin or compute.server.user role is required for this.

Scopes
  • account;
  • project
Who it can be assigned to
  • users;
  • service users;
  • user groups
Available operations

In the Account scope:

  • view a list of public subnets and public IP addresses, ports in public networks, cloud routers, and information about them in all projects;
  • manage public subnets in all projects;
  • manage direct public IP addresses in all projects;
  • manage public floating IP addresses in all projects;
  • manage cloud routers in all projects *

In the Project scope:

  • view a list of public subnets and public IP addresses, ports in public networks, cloud routers, and information about them in their project;
  • manage public subnets in their project;
  • manage direct public IP addresses in their project;
  • manage public floating IP addresses in their project;
  • manage cloud routers in their project *

* To manage connecting a private subnet to a cloud router, the vpc.private_network.admin role is additionally required.

vpc.external_access.user

The vpc.external_access.user role provides access:

Adding ports to a cloud server and deleting ports added to a cloud server is unavailable; the compute.admin or compute.server.user role is required for this.

Scopes
  • account;
  • project
Who it can be assigned to
  • users;
  • service users;
  • user groups
Available operations

In the Account scope:

  • view a list of public subnets, direct public IP addresses and public floating IP addresses, ports in public networks, cloud routers, and information about them in all projects;
  • manage public floating IP addresses, except for creating and deleting public floating IP addresses, in all projects

In the Project scope:

  • view a list of public subnets, direct public IP addresses and public floating IP addresses, ports in public networks, cloud routers, and information about them in their project;
  • manage public floating IP addresses, except for creating and deleting public floating IP addresses, in their project

vpc.external_access.viewer

The vpc.external_access.viewer role provides view access to everything managed by vpc.external_access.admin in the same scope.

Scopes
  • account;
  • project
Who it can be assigned to
  • users;
  • service users;
  • user groups
Available operations

In the Account scope:

  • view a list of public subnets, direct public IP addresses and public floating IP addresses, ports in public networks, cloud routers, and information about them in all projects

In the Project scope:

  • view a list of public subnets, direct public IP addresses and public floating IP addresses, ports in public networks, cloud routers, and information about them in their project

vpc.network_security.admin

The vpc.network_security.admin role provides access to manage traffic restriction tools:

Scopes
  • account;
  • project
Who it can be assigned to
  • users;
  • service users;
  • user groups
Available operations

In the Account scope:

  • view a list of:

    • cloud firewalls and information about them in all projects;
    • security groups and information about them in all projects *;
  • manage cloud firewalls in all projects;

  • manage security groups, rules, and ports in all projects *;

  • download a security group report in all projects **

In the Project scope:

  • view a list of:

    • cloud firewalls and information about them in their project;
    • security groups and information about them in their project *;
  • manage cloud firewalls in their project;

  • manage security groups, rules, and ports in their project *;

  • download a security group report in their project **

* To view security groups and manage port assignments, the vpc.private_network.viewer or vpc.external_access.viewer role is additionally required.

** To download a report, a combination of the vpc.private_network.viewer and vpc.external_access.viewer roles, or the vpc.viewer role is additionally required.

vpc.network_security.user

The vpc.network_security.user role provides access:

Scopes
  • account;
  • project
Who it can be assigned to
  • users;
  • service users;
  • user groups
Available operations

In the Account scope:

  • view a list of:

    • cloud firewalls and information about them in all projects;
    • security groups and information about them in all projects;
  • manage security group ports in all projects. In the Control Panel, the action is available for the role only via the security group page (in the top menu, click Products → Cloud Servers → Security Groups → group page);

  • download a security group report in all projects *

In the Project scope:

  • view a list of:

    • cloud firewalls and information about them in their project;
    • security groups and information about them in their project;
  • manage security group ports in their project. In the Control Panel, the action is available for the role only via the security group page (in the top menu, click Products → Cloud Servers → Security Groups → group page);

  • download a security group report in their project *

* To download a report, a combination of the vpc.private_network.viewer and vpc.external_access.viewer roles, or the vpc.viewer role is additionally required.

vpc.network_security.viewer

The vpc.network_security.viewer role provides view access to everything managed by vpc.network_security.admin in the same scope.

Scopes
  • account;
  • project
Who it can be assigned to
  • users;
  • service users;
  • user groups
Available operations

In the Account scope:

  • view a list of:

    • cloud firewalls and information about them in all projects;
    • security groups and information about them in all projects;
  • download a security group report in all projects *

In the Project scope:

  • view a list of:

    • cloud firewalls and information about them in their project;
    • security groups and information about them in their project;
  • download a security group report in their project *

* To download a report, a combination of the vpc.private_network.viewer and vpc.external_access.viewer roles, or the vpc.viewer role is additionally required.

vpc.load_balancer.admin

The vpc.load_balancer.admin role provides access to manage cloud load balancers; learn more in the Manage access to cloud load balancer instructions.

Scopes
  • account;
  • project
Who it can be assigned to
  • users;
  • service users;
  • user groups
Available operations

In the Account scope:

  • view a list of all load balancer objects and information about them in all projects: load balancers, rules and HTTP policies, target groups and member servers, health monitors;
  • view statistics of load balancers in all projects;
  • manage load balancer objects, except for creating a load balancer, in all projects *;
  • enable and disable load balancer logging in all projects

In the Project scope:

  • view a list of all load balancer objects and information about them in their project: load balancers, rules and HTTP policies, target groups and member servers, health monitors;
  • view statistics of load balancers in their project;
  • manage load balancer objects, except for creating a load balancer, in their project *;
  • enable and disable load balancer logging in their project

* To create a load balancer, one or more roles are additionally required. Additional roles depend on the network where the load balancer will be created:

vpc.load_balancer.viewer

The vpc.load_balancer.viewer role provides view access to everything managed by vpc.load_balancer.admin in the same scope.

Scopes
  • account;
  • project
Who it can be assigned to
  • users;
  • service users;
  • user groups
Available operations

In the Account scope:

  • view a list of all load balancer objects and information about them in all projects: load balancers, rules and HTTP policies, target groups and member servers, health monitors

In the Project scope:

  • view a list of all load balancer objects and information about them in their project: load balancers, rules and HTTP policies, target groups and member servers, health monitors