Managing Cloud Data Streaming Service permissions
    • PDF

    Managing Cloud Data Streaming Service permissions

    • PDF

    Article Summary

    Available in VPC

    By using Sub Account, NAVER Cloud Platform's account management service, you can set various access permissions for Cloud Data Streaming Service. Sub Account provides System Managed policies and User Created policies for setting management and administration permissions.

    Note

    Sub Account is a service provided free of charge upon subscription request. For more details about Sub Account, refer to the Services > Management & Governance > Sub Account menu in the NAVER Cloud Platform portal, and Sub Account Guide.

    System Managed policies

    System Managed policies are role-based policies defined by NAVER Cloud Platform for user convenience. Once System Managed policies are granted to a sub account created in Sub Account, that sub account can use Cloud Data Streaming Service. The following is a brief description about System Managed policies of Cloud Data Streaming Service.

    Policy NamePolicy description
    NCP_ADMINISTRATORPermission to access the portal and console in NAVER Cloud Platform in the same manner as main accounts
    NCP_INFRA_MANAGERPermission to use all services in NAVER Cloud Platform and access My Page > Manage notifications in the portal
    NCP_VPC_CLOUD_DATA_STREAMING_SERVICE_MANAGERPermission to use all features of Cloud Data Streaming Service.
    NCP_VPC_CLOUD_DATA_STREAMING_SERVICE_VIEWERPermission to only use the View list and Search features in Cloud Data Streaming Service.

    User Created policies

    User Created policies are policies that users may create. Once User Created policies are granted to a sub account created in Sub Account, that sub account can only use the user-assigned action combinations. The following is a brief description about User Created policies of Cloud Data Streaming Service.

    ClassificationAction nameRelated action(s)Resource typeGroup by resource typeAction description
    ViewView/downloadCertificateView/getClusterDetail
    View/getClusterList
    ClusterViewDownload certificate
    ViewView/getClusterACGDetailView/getClusterDetail
    View/getClusterList
    ClusterViewCheck ACG details
    ViewView/getClusterDetailView/getClusterListClusterViewCheck cluster details
    ViewView/getClusterList--ViewCheck cluster list
    ViewView/getClusterMonitorView/getClusterDetail
    View/getClusterNodeList
    View/getClusterList
    ClusterViewCluster monitoring
    ViewView/getClusterNodeListView/getClusterDetail
    View/getClusterList
    ClusterViewCheck cluster node list
    ViewView/getKafkaConfigGroupDetail-ConfigGroupViewCheck config group details
    ViewView/getKafkaConfigGroupListView/getKafkaConfigGroupDetail-ViewCheck config group list
    ViewView/getKafkaConfigGroupUsingClusterListView/getKafkaConfigGroupListConfigGroupViewCheck list of clusters where config group is applied
    ViewView/getLoadBalancerInstanceDetailView/getLoadBalancerInstanceListVPCLoadBalancer:LoadBalancerViewSelect a load balancer to set as advertised listener.
    ViewView/getLoadBalancerInstanceList--ViewCheck list of load balancers to set as advertised listeners
    ViewView/getSubnetDetailView/getSubnetListVPC:SubnetViewSelect a subnet to place the cluster in.
    ViewView/getSubnetList--ViewCheck subnet list
    ViewView/getVPCDetailView/getVPCListVPC:VPCViewSelect a VPC to place the cluster in.
    ViewView/getVPCList--ViewCheck VPC list
    ViewView/getNodeSpecDetailView/getClusterDetail
    View/getClusterList
    ClusterViewView changeable specs of cluster nodes
    ChangeChange/changeCountOfBrokerNodeView/getClusterDetail
    View/getClusterList
    ClusterChangeAdd broker nodes in the cluster
    ChangeChange/createClusterView/getSubnetList
    View/getSubnetDetail
    View/getClusterList
    View/getVPCDetail
    View/getVPCList
    -ChangeCreate Cluster
    ChangeChange/createKafkaConfigGroupView/getKafkaConfigGroupList-ChangeCreate config group.
    ChangeChange/deleteClusterView/getClusterDetail
    View/getClusterList
    ClusterChangeDelete cluster
    ChangeChange/deleteKafkaConfigGroupView/getKafkaConfigGroupDetail
    View/getKafkaConfigGroupList
    ConfigGroupChangeDelete config group.
    ChangeChange/editKafkaConfigView/getKafkaConfigGroupDetail
    View/getClusterDetail
    View/getKafkaConfigGroupList
    View/getClusterList
    ConfigGroupChangeEdit config group information.
    ChangeChange/resetCMAKPasswordView/getClusterDetail
    View/getClusterList
    ClusterChangeReset CMAK connection password
    ChangeChange/restartCMAKServiceView/getClusterDetail
    View/getClusterList
    ClusterChangeRestart the cluster's CMAK service.
    ChangeChange/restartKafkaServiceView/getClusterDetail
    View/getClusterNodeList
    View/getClusterList
    ClusterChangeRestart the Kafka and Zookeeper service of the cluster.
    ChangeChange/setBrokerNodePublicEndpointView/getClusterDetail
    View/getClusterList
    View/getLoadBalancerInstanceList
    View/getLoadBalancerInstanceDetail
    ClusterChangeChange broker node public endpoint settings.
    ChangeChange/setKafkaConfigGroupView/getKafkaConfigGroupDetail
    View/getClusterDetail
    View/getKafkaConfigGroupList
    View/getClusterList
    ClusterChangeApply config group.
    ChangeChange/setPublicDomainView/getClusterDetail
    View/getClusterList
    ClusterChangeEnable/disable public domain of CMAK server.
    ChangeChange/changSpecOfNodeView/getClusterDetail
    View/getClusterList
    View/getNodeSpecDetail
    ClusterChangeChange cluster nodes specifications
    Caution

    Even when you are granted permission for a specific action, if you are not also granted permissions for the related actions that are required, then you won't be able to perform jobs properly. To prevent such issues, Sub Account provides a feature that automatically grants permissions for related actions when granting action permissions. However, if you deselect related actions that are automatically granted, then the system determines that it was done intentionally by the main account user and does not forcibly include them. Thus, be careful when setting permissions.


    Was this article helpful?

    Changing your password will log you out immediately. Use the new password to log back in.
    First name must have atleast 2 characters. Numbers and special characters are not allowed.
    Last name must have atleast 1 characters. Numbers and special characters are not allowed.
    Enter a valid email
    Enter a valid password
    Your profile has been successfully updated.