Manage access to Secrets Manager
Access to Secrets Manager is governed by:
- projects — define access within an isolated group of resources;
- roles — define access for panel users, service users and groups within an account and project.
Access within projects
All secrets in Secrets Manager are added in a specific project. You can group secrets by different projects and configure user permissions based on which projects they need access to.
Access within roles
Access to Secrets Manager is granted by Secrets Manager roles and global roles. Read more about role types in the Role Reference.
Secrets Manager roles
secrets.admin
The secrets.admin role grants access to manage secrets in Secrets Manager.
secrets.viewer
The secrets.viewer role grants access to view everything that secrets.admin manages.
secrets.consumer
The secrets.consumer role grants access to view and use secrets in Secrets Manager.
Global roles
member
The member role grants full access to all services. It does not grant access to manage panel users, service users, user groups and federations.
iam.admin
The iam.admin role grants access to manage users and does not grant access to manage products and billing. It does not allow managing your own account: changing permissions, managing notifications, deleting a user. The first user with the iam.admin role is created by the Account Owner.
iam.viewer
The iam.viewer role grants access to view everything that iam.admin manages.
reader
The reader role grants access to view everything that member manages in the same access scope.