Skip to main content

Access management in Selectel products

To manage access to Selectel products, projects and users are used.

When registering an account, a primary user is automatically created — the Account Owner, who has access to manage all account resources. The Account Owner can create additional users. Users can be of different types, and you can grant them permissions — assign roles in a specific access scope.

In addition to the Account Owner, other users with the iam.admin role can manage other users. You can find more information about the capabilities of each role in the Role Reference.

Users can be added to groups to manage multiple users as one.

You can manage users and roles in the control panel, using IAM API or Terraform.

Records of access management operations are saved in audit logs.

Access management in certain Selectel products is restricted.

Permissions

A permission (Permission) determines which operations a user can perform and on which group of resources.

A permission consists of an access scope and a role.

Permissions can be assigned to different entities: panel users, service users, or a user group. You can assign multiple permissions at once and change them.

Access scopes

A permission scope is a group of resources to which the permission is granted. The permission scope can be:

  • account (account) — all account resources, including the resources of all projects;
  • projects (project) — resources of selected projects.

Roles⁠​

A role is a set of predefined rights that determine which actions a user can perform on resources of a certain type or on account settings.

A role determines access within the scope, which is specified in the permission. The scopes available to a specific role depend on the user type. For more information about the capabilities of each role, see the Role Reference.

Access management limitations in certain products

Some products and services do not support the division of resources into projects and may additionally have their own access system:

  • VMware-based cloud products: Public Cloud powered by VMware, Disaster Recovery to the cloud powered by VMware, Virtual Desktop Infrastructure;
  • Selectel Email Service;
  • Direct Connect;
  • Global Connect;
  • IP address management;
  • DDoS protection;
  • Fault-tolerant load balancer;
  • AI Marketplace, ML Platform;
  • backup and recovery products: Agent-based backup (Veeam Agent), Veeam Cloud Connect, Cyber Backup Cloud;
  • Availability Check (formerly Monitoring);
  • Logs.

In S3, user access to a bucket can be modified in accordance with an access policy; for more details, see the Managing S3 access guide.