Manage cloud platform network access
Cloud platform network access is governed by:
- projects — define access within an isolated group of resources;
- role model — defines access for different users within an account and project.
Access within the role model
Read more about access within the role model in the instruction Access management in Selectel products.
This instruction describes roles for accessing cloud platform network resources: private networks, subnets and ports, public subnets and ports, public IP addresses, and cloud routers. Access to load balancers, cloud firewalls and security groups is regulated separately.
member
User with full access to all services. Access management is not available for: users, service users, user groups, and federations.
iam.admin
User with access to manage users and no access to services or billing. Cannot manage their own account: change permissions, manage notifications, or delete the user. The first user with the iam.admin role is created by the Account Owner.
iam.viewer
User with access to view everything managed by iam.admin.
reader
User with access to view everything managed by member in the same access scope.
vpc.admin
User with access to manage cloud platform networks (private networks and subnets, public subnets and public IP addresses, cloud routers), cloud firewalls, security groups, and cloud load balancers.
Adding ports to a cloud server and deleting ports added to a cloud server are not available; this requires the member role.
vpc.viewer
User with access to view everything managed by vpc.admin in the same access scope.
vpc.private_network.admin
User with access to manage private networks, subnets, and ports.
Adding ports to a cloud server and deleting ports added to a cloud server are not available; this requires the member role.
vpc.private_network.viewer
User with access to view everything managed by vpc.private_network.admin in the same access scope.
vpc.external_access.admin
User with access to manage internet access objects — public subnets, public IP addresses, and cloud routers.
Adding ports to a cloud server and deleting ports added to a cloud server are not available; this requires the member role.
vpc.external_access.user
User with access to view everything managed by vpc.external_access.admin in the same access scope, as well as access to manage public IP addresses.
vpc.external_access.viewer
User with access to view everything managed by vpc.external_access.admin in the same access scope.