Skip to main content

Manage access to Cloud for 1C

Access to Cloud for 1C is regulated by:

For access via API use keys.

Read more about access management in the Access management in Selectel products guide.

Access within roles

Access to Cloud for 1C is granted by Cloud for 1C roles and global roles. Read more in the Role reference guide.

Role groupRoleAccess
Cloud for 1C rolesgo1c.adminManage Cloud for 1C resources
go1c.viewerView Cloud for 1C resources
Global rolesmemberManage Cloud for 1C resources and other products, account, billing, and projects
billingManage billing for Cloud for 1C and other products
iam.adminManage access to Cloud for 1C and other products
iam.viewerView access to Cloud for 1C and other products
readerView Cloud for 1C and other product resources, account, billing, and projects

Cloud for 1C roles

go1c.admin

The go1c.admin role provides access to manage Cloud for 1C resources. Does not provide access to other products.

Access scopes
  • account;
  • project
Who can be assigned
  • users;
  • service users;
  • user groups
Available operations in Cloud for 1C

In the Account access scope:

  • manage 1C server clusters in all projects:

    • create a server cluster;
    • scale a cluster;
    • change cluster settings (enable automatic disk scaling, web server, web publication, and debug mode; manage IP address allowlist for accessing web publications; add custom domains);
    • manage storage (connect and disconnect S3 buckets) *;
    • connect to a private network **;;
    • rent 1C licenses;
    • change maintenance window;
    • terminate user sessions;
    • restart a cluster;
    • delete a cluster;
  • manage info-bases in all projects:

    • create an info-base;
    • upload an info-base from a .dt file *;
    • manage scheduled job execution;
    • configure user sessions (block, allow, terminate);
    • create a backup;
    • change web publication configuration;
    • delete an info-base;
  • manage databases in all projects:

    • create databases;
    • scale a database;
    • manage automatic disk scaling;
    • change maintenance window;
    • delete a database;
  • manage backups in all projects:

    • create a backup storage *;
    • edit storage *;
  • manage Prometheus tokens for collecting metrics in all projects

In the Project access scope:

  • manage 1C server clusters in your project:

    • create a server cluster;
    • scale a cluster;
    • change cluster settings (enable automatic disk scaling, web server, web publication, and debug mode; manage IP address allowlist for accessing web publications; add custom domains);
    • manage storage (connect and disconnect S3 buckets) *;
    • connect to a private network **;;
    • rent 1C licenses;
    • change maintenance window;
    • terminate user sessions;
    • restart a cluster;
    • delete a cluster;
  • manage info-bases in your project:

    • create an info-base;
    • manage scheduled job execution;
    • configure user sessions (block, allow, terminate);
    • create a backup;
    • change web publication configuration;
    • delete an info-base;
  • manage databases in your project:

    • create databases;
    • scale a database;
    • manage automatic disk scaling;
    • change maintenance window;
    • delete a database;
  • manage backups in your project:

    • create a backup storage *;
    • edit storage *;
  • manage Prometheus tokens for collecting metrics in your project

* To manage connecting backup storage, cluster data storage, and uploading an info-base from a .dt file, you additionally need a combination of the s3.admin and iam.admin roles.

** To manage connecting a cluster to a private network that has already been created in a project, you additionally need the vpc.private_network.viewer role.

go1c.viewer

The go1c.viewer role provides access to view everything that go1c.admin manages.

Access scopes
  • account;
  • project
Who can be assigned
  • users;
  • service users;
  • user groups
Available operations in Cloud for 1C

In the Account access scope:

  • view 1C server clusters in all projects;
  • view info-bases in all projects;
  • view databases in all projects;
  • view backups in all projects;
  • view a list of generated Prometheus tokens for collecting metrics in all projects

In the Project access scope:

  • view 1C server clusters in your project;
  • view info-bases in your project;
  • view databases in your project;
  • view backups in your project;
  • view a list of generated Prometheus tokens for collecting metrics in your project

Global roles

member

The member role provides full access to all services. Does not provide access to manage control panel users, service users, user groups, and federations.

Access scopes
  • account;
  • project
Who can be assigned
  • users;
  • service users;
  • user groups
Available operations in Cloud for 1C

In the Account access scope:

  • manage 1C server clusters in all projects:

    • create a server cluster;
    • scale a cluster;
    • change cluster settings (enable automatic disk scaling, web server, web publication, and debug mode; manage IP address allowlist for accessing web publications; add custom domains);
    • manage storage (connect and disconnect S3 buckets) *;
    • connect to a private network;
    • rent 1C licenses;
    • change maintenance window;
    • terminate user sessions;
    • restart a cluster;
    • delete a cluster;
  • manage info-bases in all projects:

    • create an info-base;
    • upload an info-base from a .dt file *;
    • manage scheduled job execution;
    • configure user sessions (block, allow, terminate);
    • create a backup;
    • change web publication configuration;
    • delete an info-base;
  • manage databases in all projects:

    • create databases;
    • scale a database;
    • manage automatic disk scaling;
    • change maintenance window;
    • delete a database;
  • manage backups in all projects:

    • create a backup storage *;
    • edit storage *;
  • manage Prometheus tokens for collecting metrics in all projects;

  • manage projects, their limits, and quotas;

  • manage billing in all projects

In the Project access scope:

  • manage 1C server clusters in your project:

    • create a server cluster;
    • scale a cluster;
    • change cluster settings (enable automatic disk scaling, web server, web publication, and debug mode; manage IP address allowlist for accessing web publications; add custom domains);
    • manage storage (connect and disconnect S3 buckets) *;
    • rent 1C licenses;
    • change maintenance window;
    • terminate user sessions;
    • restart a cluster;
    • delete a cluster;
  • manage info-bases in your project:

    • create an info-base;
    • manage scheduled job execution;
    • configure user sessions (block, allow, terminate);
    • create a backup;
    • change web publication configuration;
    • delete an info-base;
  • manage databases in your project:

    • create databases;
    • scale a database;
    • manage automatic disk scaling;
    • change maintenance window;
    • delete a database;
  • manage backups in your project:

    • create a backup storage *;
    • edit storage *;
  • manage Prometheus tokens for collecting metrics in your project;

  • manage limits and quotas in your project;

  • manage billing in your project

* To manage connecting backup storage, cluster data storage, and uploading an info-base from a .dt file, you additionally need the iam.admin role.

billing

The billing role provides access to manage billing without access to manage services.

Access scopesAccount
Who can be assigned
  • users;
  • service users;
  • user groups
Available operations in Cloud for 1C
  • manage billing;
  • view rented 1C licenses;
  • view Cloud for 1C consumption

iam.admin

The iam.admin role provides access to manage users. Does not provide access to services and billing, or to manage your own account: changing permissions, managing notifications, deleting a user. The first user with the iam.admin role is created by the Account Owner.

Access scopesAccount
Who can be assigned
  • users;
  • service users;
  • user groups
Available operations in Cloud for 1CManage users, service users, and user groups

iam.viewer

The iam.viewer role provides access to view everything that iam.admin manages.

Access scopesAccount
Who can be assigned
  • users;
  • service users;
  • user groups
Available operations in Cloud for 1CView control panel users, service users, and user groups

reader

The reader role provides access to view everything that member manages in the same access scope.

Access scopes
  • account;
  • project
Who can be assigned
  • users;
  • service users;
  • user groups
Available operations in Cloud for 1C

In the Account access scope:

  • view 1C server clusters in all projects;
  • view info-bases in all projects;
  • view databases in all projects;
  • view backups in all projects;
  • view a list of generated Prometheus tokens for collecting metrics in all projects;
  • view projects, their limits, and quotas;
  • view billing data and consumption

In the Project access scope:

  • view 1C server clusters in your project;
  • view info-bases in your project;
  • view databases in your project;
  • view backups in your project;
  • view a list of generated Prometheus tokens for collecting metrics in your project;
  • view limits and quotas in your project;
  • view billing data and consumption in your project

Keys for API access

Depending on the API type, you will need: