Manage access to security groups
Access to security groups is regulated by:
- projects — define access within an isolated group of resources;
- role-based model — determines access of different users within an account and a project.
Access within the role model
Learn more about access within the role-based model in the Access management in Selectel products instructions.
member
User with full access to all services. Cannot manage access for: users, service users, user groups, and federations.
iam.admin
User with access to user management and without access to services and billing. Cannot manage their own account: change permissions, manage notifications, or delete the user. The first user with the iam.admin role is created by the Account Owner.
iam.viewer
User with access to view everything managed by iam.admin.
reader
User with access to view everything managed by member in the same scope.
vpc.admin
User with access to manage cloud platform networks (private networks and subnets, public subnets and public IP addresses, cloud routers), cloud firewalls, security groups, and cloud load balancers.
vpc.viewer
User with access to view everything managed by vpc.admin in the same scope.
vpc.network_security.admin
Manage tools for traffic restriction — cloud firewalls, security groups.
vpc.network_security.user
User with access to view everything managed by vpc.network_security.admin in the same scope. Also has access to managing security groups on ports in a private or public network.
vpc.network_security.viewer
User with access to view everything managed by vpc.network_security.admin in the same scope.