Available in VPC
You can set different access permissions for Cloud Data Streaming Service using NAVER Cloud Platform's Sub Account service. Sub Account offers both system-managed (System Managed) and user-defined (User Created) policies to help you configure management and operation permissions.
Sub Account is a free service with no additional charges. For more information about Sub Account, see Services > Management & Governance > Sub Account on the NAVER Cloud Platform portal and the Sub Account user guide.
System-managed policies
System-managed policies are pre-built, role-based policies that NAVER Cloud Platform provides for your convenience. When you assign one of these policies to a sub account, that account gets access to Cloud Data Streaming Service. Here are the available system-managed policies for Cloud Data Streaming Service:
| Policy name | Policy description |
|---|---|
| NCP_ADMINISTRATOR | Full access to all services, same as the main account |
| NCP_INFRA_MANAGER | Access to all services, except My Account > Manage billing information and expense > Manage billing and payment on the console |
| NCP_FINANCE_MANAGER | Access limited to the Cost Explorer services and My Account > Manage billing information and expense > Manage billing and payment on the console |
| NCP_VPC_CLOUD_DATA_STREAMING_SERVICE_MANAGER | Full access to all Cloud Data Streaming Service features |
| NCP_VPC_CLOUD_DATA_STREAMING_SERVICE_VIEWER | View-only access to all Cloud Data Streaming Service features and lists |
User-defined policies
User-defined policies let you create custom permissions. When you assign a user-defined policy to a sub account, that account can only perform the specific actions you've allowed. Here are the available user-defined policies for Cloud Data Streaming Service:
| Type | Action | Related action | Resource type | Group by resource type | Action description |
| ---- | ---- | ---- | ---- | ---- | ---- |
| View | View/downloadCertificate |
- View/getClusterDetail
- View/getClusterList
| View | View/getClusterACGDetail |
- View/getClusterDetail
- View/getClusterList
| View | View/getClusterDetail | View/getClusterList | Cluster | View | Check cluster details |
| View | View/getClusterList | - | - | View | Check cluster list |
| View | View/getClusterMonitor |
- View/getClusterDetail
- View/getClusterNodeList
- View/getClusterList
| View | View/getClusterNodeList |
- View/getClusterDetail
- View/getClusterList
| View | View/getKafkaConfigGroupDetail | - | ConfigGroup | View | Check ConfigGroup details |
| View | View/getKafkaConfigGroupList | - | - | View | Check ConfigGroup list |
| View | View/getKafkaConfigGroupUsingClusterList |
- View/getKafkaConfigGroupList
- View/getKafkaConfigGroupDetail
| View | View/getLoadBalancerInstanceDetail | View/getLoadBalancerInstanceList | VPCLoadBalancer:LoadBalancer | View | Select a load balancer to set as an advertised listener |
| View | View/getLoadBalancerInstanceList | - | - | View | Check the list of load balancers to set as advertised listeners |
| View | View/getSubnetDetail | View/getSubnetList | VPC:Subnet | View | Select a subnet to place the cluster in |
| View | View/getSubnetList | - | - | View | Check subnet list |
| View | View/getVPCDetail | View/getVPCList | VPC:VPC | View | Select a VPC to place the cluster in |
| View | View/getVPCList | - | - | View | Check VPC list |
| View | View/getNodeSpecDetail |
- View/getClusterDetail
- View/getClusterList
| Change | Change/changeCountOfBrokerNode |
- View/getClusterDetail
- View/getClusterList
| Change | Change/createCluster |
- View/getSubnetList
- View/getSubnetDetail
- View/getClusterList
- View/getKafkaConfigGroupList
- View/getVPCDetail
- View/getVPCList
| Change | Change/createKafkaConfigGroup |
- View/getKafkaConfigGroupList
- View/getKafkaConfigGroupDetail
| Change | Change/deleteCluster |
- View/getClusterDetail
- View/getClusterList
| Change | Change/deleteKafkaConfigGroup |
- View/getKafkaConfigGroupDetail
- View/getKafkaConfigGroupList
| Change | Change/editKafkaConfig |
- View/getKafkaConfigGroupDetail
- View/getClusterDetail
- View/getKafkaConfigGroupList
- View/getClusterList
| Change | Change/resetMGMTPassword |
- View/getClusterDetail
- View/getClusterList
| Change | Change/restartKafkaService |
- View/getClusterDetail
- View/getClusterNodeList
- View/getClusterList
| Change | Change/setBrokerNodePublicEndpoint |
- View/getClusterDetail
- View/getClusterList
- View/getLoadBalancerInstanceList
- View/getLoadBalancerInstanceDetail
| Change | Change/setKafkaConfigGroup |
- View/getKafkaConfigGroupDetail
- View/getClusterDetail
- View/getKafkaConfigGroupList
- View/getClusterList
| Change | Change/setPublicDomain |
- View/getClusterDetail
- View/getClusterList
| Change | Change/changeSpecOfNode |
- View/getClusterDetail
- View/getClusterList
- View/getNodeSpecDetail
| Change | Change/changeClusterNodeDiskSize |
- View/getClusterList
- View/getClusterDetail
| Change | Change/rollingRestartCluster |
- View/getClusterList
- View/getClusterDetail
- View/getNodeSpecDetail
| Change | Change/rollingUpgradeCluster |
- View/getClusterList
- View/getClusterDetail
- View/getKafkaConfigGroupDetail
- View/getKafkaConfigGroupList
- View/getNodeSpecDetail
If you grant someone access to a specific action but not to the required related actions, they won't be able to complete their tasks. Sub Account automatically includes these related permissions to prevent this issue. However, if you manually uncheck these auto-selected related actions, the system assumes this was intentional and won't override your selection.