Skip to main content

Access management in Selectel products

To manage access to Selectel products, projects and users are used.

When registering an account, a primary user is automatically created — Account Owner, who has access to manage all account resources. The Account Owner can create additional users. Users can be of different types, and you can grant them permissions — assign roles within a specific access scope.

Besides the Account Owner, users with the iam.admin role can manage other users. Learn more about the capabilities of each role in the Role Reference.

Users can be added to groups to manage multiple users as one.

You can manage users and roles in the control panel, using IAM API or Terraform.

Records of access management operations are saved in audit logs.

Access management in certain Selectel products is restricted.

Access management limitations in certain products

Some products and services do not support the division of resources into projects and may additionally have their own access system:

  • VMware-based cloud products: Public Cloud powered by VMware, Disaster Recovery to the cloud powered by VMware, Virtual Desktop Infrastructure;
  • Selectel Mail;
  • Direct Connect;
  • Global Connect;
  • IP address accounting;
  • DDoS protection;
  • Fault-tolerant load balancer;
  • AI Marketplace, ML Platform;
  • backup and recovery products: Agent Backup (Veeam Agent), Veeam Cloud Connect repository, Cyber Backup Cloud;
  • Availability check (formerly — Monitoring);
  • Logs.

In S3, user access to a bucket can be changed according to the access policy, see the Manage access in S3 instruction.