Skip to main content

Access management in Selectel products

To manage access to Selectel products, projects and users are used.

Upon account registration, a primary user is automatically created — the Account Owner, who has access to manage all account resources. The Account Owner can create additional users. Users can be of different types and can be granted permissions by assigning roles within a specific access scope.

Besides the Account Owner, users with the iam.admin role can manage other users. Learn more about the capabilities of each role in the Role Reference guide.

Users can be added to groups to manage multiple users as one.

You can manage users and roles in the Control panel, via the IAM API, or with Terraform.

Records of access management operations are stored in audit logs.

Access management in certain Selectel products is restricted.

Access management restrictions in certain products

Some products and services do not support dividing resources into projects and may additionally have their own access system:

  • VMware-based cloud products: VMware-based Public Cloud, Disaster Recovery to VMware-based Cloud, Remote Desktop Rental;
  • Selectel Mail Service;
  • Direct Connect;
  • Global Connect;
  • IP address management;
  • DDoS protection;
  • Fault-tolerant load balancer;
  • AI marketplace, ML platform;
  • backup and recovery products: Agent-based Backup (Veeam Agent), Veeam Cloud Connect Cloud Repository, Cyber Backup Cloud;
  • Availability Check (formerly Monitoring);
  • Logs.

In S3, user access to a bucket can be modified according to the access policy; for more details, see the Manage access in S3 guide.