Skip to main content

Manage access to private DNS

Access to private DNS is governed by:

Role-based access

member

A user with full access to all services. Cannot manage access to: users, service users, user groups, and federations.

Access scopes
  • Account;
  • Project
Who can be assigned
  • Users;
  • service users;
  • user groups
Available operations in private DNS

In the Account scope:

  • viewing information about connecting a network to a private DNS resolver, viewing a list of zones and resource records in zones across all projects;

  • managing private DNS across all projects:

    • managing zones (creating, updating, deleting, connecting a network to a zone, etc.);
    • managing resource records (adding, updating, deleting records);
    • managing connections to a private DNS resolver (creating a connection, deleting a connection);
  • managing projects, their limits, and quotas;

  • managing billing

In the Project scope:

  • viewing information about connecting a network to a private DNS resolver, viewing a list of zones and resource records and information about them in the selected project;

  • managing private DNS in the selected project:

    • managing zones (creating, updating, deleting, connecting a network to a zone, etc.);
    • managing resource records (adding, updating, deleting records);
    • managing connections to a private DNS resolver (creating a connection, deleting a connection)

billing

A user with access to billing management and without access to service management.

Access scopesAccount
Who can be assigned
  • Users;
  • service users;
  • user groups
Available operations in private DNS
  • Managing billing

iam.admin

A user with access to user management and without access to services and billing. Cannot manage their account: change permissions, manage notifications, or delete the user. The first user with the iam.admin role is created by the Account Owner.

Access scopesAccount
Who can be assigned
  • Users;
  • service users;
  • user groups
Available operations in private DNS

iam.viewer

A user with access to view everything managed by iam.admin.

Access scopesAccount
Who can be assigned
  • Users;
  • service users;
  • user groups
Available operations in private DNS

reader

A user with access to view everything managed by member in the same access scope.

Access scopes
  • Account;
  • Project
Who can be assigned
  • Users;
  • service users;
  • user groups
Available operations in private DNS

In the Account scope:

  • viewing information about connecting a network to a private DNS resolver, viewing a list of zones and resource records in zones across all projects

In the Project scope:

  • viewing information about connecting a network to a private DNS resolver, viewing a list of zones and resource records in zones across all projects

vpc.private_network.admin

A user with access to managing private networks, subnets, and ports, as well as private DNS.

Adding ports to a cloud server and deleting ports added to a cloud server is not available; this requires the member role.

Access scopes
  • Account;
  • Project
Who can be assigned
  • Users;
  • service users;
  • user groups
Available operations with private DNS

In the Account scope:

  • viewing information about connecting a network to a private DNS resolver, viewing a list of zones and resource records in zones across all projects;

  • managing private DNS across all projects:

    • managing zones (creating, updating, deleting, connecting a network to a zone, etc.);
    • managing resource records (adding, updating, deleting records);
    • managing connections to a private DNS resolver (creating a connection, deleting a connection)

In the Project scope:

  • viewing information about connecting a network to a private DNS resolver, viewing a list of zones and resource records and information about them in the selected project;

  • managing private DNS in the selected project:

    • managing zones (creating, updating, deleting, connecting a network to a zone, etc.);
    • managing resource records (adding, updating, deleting records);
    • managing connections to a private DNS resolver (creating a connection, deleting a connection)

vpc.private_network.viewer

A user with access to view everything managed by vpc.private_network.admin in the same access scope.

Access scopes
  • Account;
  • Project
Who can be assigned
  • Users;
  • service users;
  • user groups
Available operations with private DNS

In the Account scope:

  • viewing information about connecting a network to a private DNS resolver, viewing a list of zones and resource records in zones across all projects

In the Project scope:

  • viewing information about connecting a network to a private DNS resolver, viewing a list of zones and resource records and information about them in the selected project