Skip to main content

Manage access to security groups

Access to security groups is regulated by:

Access within the role model

Learn more about access within the role-based model in the Access management in Selectel products instructions.

member

User with full access to all services. Cannot manage access for: users, service users, user groups, and federations.

Access scopes
  • Account;
  • Project
Who can be assigned
  • Users;
  • service users;
  • user groups
Available operations with security groups

In the Account access scope:

  • viewing the list of security groups and information about them in all projects;
  • creating and deleting security groups in all projects;
  • editing the name, description, and tags of a group in all projects;
  • assigning a group to a port and detaching a group from a port in all projects;
  • adding and removing rules in a group in all projects;
  • downloading the security group report for all projects

In the Project access scope:

  • viewing the list of security groups and information about them in the selected project;
  • creating and deleting a security group in the selected project;
  • editing the name, description, and tags of a group in the selected project;
  • assigning a group to a port and detaching a group from a port in the selected project;
  • adding and removing rules in a group in the selected project;
  • downloading the security group report for the selected project

iam.admin

User with access to user management and without access to services and billing. Cannot manage their own account: change permissions, manage notifications, or delete the user. The first user with the iam.admin role is created by the Account Owner.

Access scopesAccount
Who can be assigned
  • Users;
  • service users;
  • user groups
Available operations with security groups

iam.viewer

User with access to view everything managed by iam.admin.

Access scopesAccount
Who can be assigned
  • Users;
  • service users;
  • user groups
Available operations with security groups

reader

User with access to view everything managed by member in the same scope.

Access scopes
  • Account;
  • Project
Who can be assigned
  • Users;
  • service users;
  • user groups
Available operations with security groups

In the Account access scope:

  • viewing the list of security groups and information about them in all projects

In the Project access scope:

  • viewing the list of security groups and information about them in the selected project

vpc.admin

User with access to manage cloud platform networks (private networks and subnets, public subnets and public IP addresses, cloud routers), cloud firewalls, security groups, and cloud load balancers.

Access scopes
  • Account;
  • Project
Who can be assigned
  • Users;
  • service users;
  • user groups
Available operations with security groups

In the Account access scope:

  • viewing the list of security groups and information about them in all projects;
  • creating and deleting security groups in all projects;
  • editing the name, description, and tags of a group in all projects;
  • assigning a group to a port and detaching a group from a port in all projects;
  • adding and removing rules in a group in all projects;
  • downloading the security group report for all projects

In the Project access scope:

  • viewing the list of security groups and information about them in the selected project;
  • creating and deleting a security group in the selected project;
  • editing the name, description, and tags of a group in the selected project;
  • assigning a group to a port and detaching a group from a port in the selected project;
  • adding and removing rules in a group in the selected project;
  • downloading the security group report for the selected project

vpc.viewer

User with access to view everything managed by vpc.admin in the same scope.

Access scopesAccount
Who can be assigned
  • Users;
  • service users;
  • user groups
Available operations with security groups

In the Account access scope:

  • viewing the list of security groups and information about them in all projects;
  • downloading the security group report for all projects

In the Project access scope:

  • viewing the list of security groups and information about them in the selected project;
  • downloading the security group report for the selected project

vpc.network_security.admin

Manage tools for traffic restriction — cloud firewalls, security groups.

Access scopes
  • Account;
  • Project
Who can be assigned
  • Users;
  • service users;
  • user groups
Available operations with security groups

In the Account access scope:

In the Project access scope:

vpc.network_security.user

User with access to view everything managed by vpc.network_security.admin in the same scope. Also has access to managing security groups on ports in a private or public network.

Access scopes
  • Account;
  • Project
Who can be assigned
  • Users;
  • service users;
  • user groups
Available operations with security groups

In the Account access scope:

  • viewing the list of security groups and information about them in all projects;
  • assigning a group to a port and detaching a group from a port in all projects. In the Control panel, this action is available for the role only through the security group page (in the top menu, click Products → Cloud Servers → Security Groups → group page);
  • downloading a security group report in all projects (additionally requires a combination of the vpc.private_network.viewer and vpc.external_access.viewer roles, or the vpc.viewer role)

In the Project access scope:

  • viewing the list of security groups and information about them in the selected project;
  • assigning a group to a port and detaching a group from a port in the selected project;
  • downloading a security group report in the selected project (additionally requires a combination of the vpc.private_network.viewer and vpc.external_access.viewer roles, or the vpc.viewer role)

vpc.network_security.viewer

User with access to view everything managed by vpc.network_security.admin in the same scope.

Access scopes
  • Account;
  • Project
Who can be assigned
  • Users;
  • service users;
  • user groups
Available operations with security groups

In the Account access scope:

In the Project access scope: