Manage access to private DNS
Access to private DNS is governed by:
- projects — define access within an isolated group of resources;
- role model — defines access for different users within an account and project. For more information about role-based access, see the Access management in Selectel products instructions.
Role-based access
member
A user with full access to all services. Cannot manage access to: users, service users, user groups, and federations.
billing
A user with access to billing management and without access to service management.
iam.admin
A user with access to user management and without access to services and billing. Cannot manage their account: change permissions, manage notifications, or delete the user. The first user with the iam.admin role is created by the Account Owner.
iam.viewer
A user with access to view everything managed by iam.admin.
reader
A user with access to view everything managed by member in the same access scope.
vpc.private_network.admin
A user with access to managing private networks, subnets, and ports, as well as private DNS.
Adding ports to a cloud server and deleting ports added to a cloud server is not available; this requires the member role.
vpc.private_network.viewer
A user with access to view everything managed by vpc.private_network.admin in the same access scope.