Cloud DB for MySQL permissions management

Prev Next

Available in VPC

You can set different access permissions for Cloud DB for MySQL using NAVER Cloud Platform's Sub Account service. Sub Account offers both system-managed (System Managed) and user-defined (User Created) policies to help you configure management and operation permissions.

Note

Sub Account is a free service with no additional charges. For more information about Sub Account, see Services > Management & Governance > Sub Account on the NAVER Cloud Platform portal and the Sub Account user guide.

System-managed policies

System-managed policies are pre-built, role-based policies that NAVER Cloud Platform provides for your convenience. When you assign one of these policies to a sub account, that account gets access to Cloud DB for MySQL. Here are the available system-managed policies for Cloud DB for MySQL:

Policy name Policy description
NCP_ADMINISTRATOR Full access to all services, with the same scope as the main account
NCP_INFRA_MANAGER Access to all services, except the My Account > Billing Information and Cost Management > Billing and Payment Management menu in the console
NCP_FINANCE_MANAGER Access only to the Cost Explorer service and the My Account > Billing Information and Cost Management > Billing and Payment Management menu in the console
NCP_VPC_CLOUD_DB_FOR_MYSQL_MANAGER Full access to all Cloud DB for MySQL features on the VPC platform
NCP_VPC_CLOUD_DB_FOR_MYSQL_VIEWER View-only access to list and query VPC-based Cloud DB for MySQL

User-defined policies

User-defined policies let you create custom permissions. When you assign a user-defined policy to a sub account, that account can only perform the specific actions, you've allowed. Here are the available user-defined policies for Cloud DB for Cloud DB for MySQL:

| Type | Action | Related action | Resource type | Group by resource type | Action description |
| ---- | ---- | ---- | ---- | ---- | ---- |
| View | View/getDBBackupDetail |

  • View/getDBBackupList
  • View/getDBServiceList
  • View/getDBServiceDetail
| Service | Service | View backup information for the service (DB) |
| View | View/getDBBackupList | View/getDBServiceList | - | Service | View backup information for the service (DB) |
| View | View/getDBDashboard |
  • View/getDBServiceList
  • View/getDBServiceDetail
| Service | Service | View the DB dashboard of Service (DB) |
| View | View/getDBLogs |
  • View/getDBServiceList
  • View/getDBServiceDetail
| Service | Service | View DB logs for the service (DB) |
| View | View/getDBServerEventDetail | View/getDBServerEventList | Service | Service | View detailed information about server (DB) events |
| View | View/getDBServerEventList | - | - | Service | View the list of server (DB) events |
| View | View/getDBServiceDetail | View/getDBServiceList | Service | Service | View detailed information about the service (DB) |
| View | View/getDBServiceList | - | - | Service | View a list of services (DB) |
| View | View/getExecutingBinary |
  • View/getDBServiceDetail
  • View/getDBServiceList
| Service | Service | View running binary logs of the selected DB server. |
| View | View/getOSDashboard |
  • View/getDBServiceList
  • View/getDBServiceDetail
| Service | Service | View the OS dashboard of services (DB). |
| View | View/getQueryTimeline |
  • View/getDBServiceList
  • View/getDBServiceDetail
| Service | Service | View the query timeline of services (DB). |
| View | View/exportQueryTimeline |
  • View/getQueryTimeline
  • View/getDBServiceList
  • View/getDBServiceDetail
| Service | Service | Download searched query timeline results of services (DB). |
| View | View/getSubnetDetail | View/getSubnetList | VPC:Subnet | Service | View subnets accessible for services (DB). |
| View | View/getSubnetList | - | - | Service | View the list of subnets required for services (DB). |
| View | View/getVPCDetail | View/getVPCList | VPC:VPC | Service | View VPCs accessible for services (DB). |
| View | View/getVPCList | - | - | Service | View the list of VPCs required for services (DB). |
| View | View/getDBServerLogs |
  • View/getDBServiceList
  • View/getDBServiceDetail
| Service | Service | View log files of the selected DB server. |
| View | View/getBucketList | - | - | Service | View the list of buckets to which the selected file can be exported |
| View | View/getBucketDetail | View/getBucketList | ObjectStorage:Bucket | Service | Select a bucket to which the selected file will be exported |
| View | View/exportDBServiceList | View/getDBServiceList | - | Service | Download a list of services (DB). |
| View | View/getSystemConfig |
  • View/getDBServiceList
  • View/getDBServiceDetail
| Service | Service | View system config options of services (DB). |
| View | View/getOperatingSystemConfig |
  • View/getDBServiceList
  • View/getDBServiceDetail
| Service | Service | View the settings required for upgrading the operating system of the service (DB) |
| Change | Change/addSlave |
  • View/getDBServiceList
  • View/getDBServiceDetail
  • View/getSubnetList
  • View/getSubnetDetail
| Service | Service | Add a slave DB to the service (DB) |
| Change | Change/changeDBServerLogConfig |
  • View/getDBServiceList
  • View/getDBServiceDetail
| Service | Service | Change DB server log settings of services (DB). |
| Change | Change/changeDBSpec |
  • View/getDBServiceList
  • View/getDBServiceDetail
| Service | Service | Change specifications of the service (DB) |
| Change | Change/changeMasterDB |
  • View/getDBServiceList
  • View/getDBServiceDetail
| Service | Service | Perform master DB failover for services (DB). |
| Change | Change/createDBService |
  • View/getVPCList
  • View/getVPCDetail
  • View/getSubnetList
  • View/getSubnetDetail
  • View/getDBServiceList
| - | Service | Create a service (DB) |
| Change | Change/createDBServiceWithRecoveryServer |
  • View/getDBServiceList
  • View/getDBServiceDetail
  • View/getVPCList
  • View/getSubnetList
| Service | Service | Create a new service using a recovery server. |
| Change | Change/deleteDBService |
  • View/getDBServiceList
  • View/getDBServiceDetail
| Service | Service | Delete the service (DB) (Master, Standalone) |
| Change | Change/deleteDBServer |
  • View/getDBServiceList
  • View/getDBServiceDetail
| Service | Service | Delete slave or recovery servers of services (DB). |
| Change | Change/deleteDBServerLog |
  • View/getDBServerLogs
  • View/getDBServiceList
  • View/getDBServiceDetail
| Service | Service | Delete log files for the selected DB server. |
| Change | Change/killDBServiceSession |
  • View/getDBServiceList
  • View/getDBServiceDetail
| Service | Service | Force-terminate sessions (IDs) of services (DB). |
| Change | Change/manageBackup |
  • View/getDBServiceList
  • View/getDBServiceDetail
| Service | Service | Manage backup settings for the service (DB) |
| Change | Change/manageDatabase |
  • View/getDBServiceList
  • View/getDBServiceDetail
| Service | Service | Manage databases |
| Change | Change/manageDBConfig |
  • View/getDBServiceList
  • View/getDBServiceDetail
| Service | Service | Manage config settings of services (DB). |
| Change | Change/manageDBServiceName |
  • View/getDBServiceList
  • View/getDBServiceDetail
| Service | Service | Change the DB service name |
| Change | Change/manageDBServerName |
  • View/getDBServiceList
  • View/getDBServiceDetail
| Service | Service | Change the DB server name |
| Change | Change/manageDBUser |
  • View/getDBServiceList
  • View/getDBServiceDetail
| Service | Service | Manage users for the service (DB) |
| Change | Change/recoveryToTime |
  • View/getDBServiceList
  • View/getDBBackupList
  • View/getDBBackupDetail
  • View/getDBServiceDetail
  • View/getSubnetList
  • View/getSubnetDetail
| Service | Service | Recover the service (DB) to a specific point in time. |
| Change | Change/recoveryWithBackupFile |
  • View/getDBServiceList
  • View/getDBBackupList
  • View/getDBBackupDetail
  • View/getDBServiceDetail
  • View/getSubnetList
  • View/getSubnetDetail
| Service | Service | Recover the service (DB) using a backup file. |
| Change | Change/reinstallSlaveDB |
  • View/getDBServiceList
  • View/getDBServiceDetail
| Service | Service | Reinstall the slave DB. |
| Change | Change/reinstallStandbyMasterDB |
  • View/getDBServiceList
  • View/getDBServiceDetail
| Service | Service | Reinstall the standby master DB. |
| Change | Change/restartDBService |
  • View/getDBServiceList
  • View/getDBServiceDetail
| Service | Service | Restart the service (DB) |
| Change | Change/setHA |
  • View/getDBServiceList
  • View/getDBServiceDetail
| Service | Service | Change the service (DB) to a high availability configuration |
| Change | Change/setStandalone |
  • View/getDBServiceList
  • View/getDBServiceDetail
| Service | Service | Change the service (DB) to a standalone configuration |
| Change | Change/skipReplicationError |
  • View/getDBServiceList
  • View/getDBServiceDetail
| Service | Service | Resolve replication errors by skipping queries that caused replication errors on the slave DB. |
| Change | Change/upgradeDBEngine |
  • View/getDBServiceList
  • View/getDBServiceDetail
| Service | Service | Upgrade the MySQL engine version of the service (DB). |
| Change | Change/managePublicDomain |
  • View/getDBServiceList
  • View/getDBServiceDetail
| Service | Service | Request a public domain to allow external access to the DB server |
| Change | Change/exportBackupToObjectStorage |
  • View/getDBServiceList
  • View/getDBServiceDetail
  • View/getBucketList
  • View/getBucketDetail
  • View/getDBBackupList
  • View/getDBBackupDetail
| Service | Service | Export the selected backup file to Object Storage |
| Change | Change/exportDBServerLogsToObjectStorage |
  • View/getDBServiceList
  • View/getDBServiceDetail
  • View/getBucketList
  • View/getBucketDetail
  • View/getDBServerLogs
| Service | Service | Export the selected log files to Object Storage. |
| Change | Change/manageDBServiceSwap |
  • View/getDBServiceList
  • View/getDBServiceDetail | Service | Service | Manage swap memory of the service (DB). |
    | Change | Change/resetDBService |
    • View/getDBServiceList
    • View/getDBServiceDetail
    • Change/manageDBConfig
    | Service | Service | Initialize the service (DB) |
    | Change | Change/killDBServiceMultipleSession |
    • View/getDBServiceList
    • View/getDBServiceDetail
    | Service | Service | Force-terminate multiple sessions (IDs) of the service (DB). |
    | Change | Change/changeMultizoneConfig |
    • View/getSubnetList
    • View/getSubnetDetail
    • View/getDBServiceList
    • View/getDBServiceDetail
    | - | Service | Change the multizone configuration of the service (DB). |
    | Change | Change/managePasswordPlugin |
    • View/getDBServiceList
    • View/getDBServiceDetail
    | Service | Service | Configure password plugin options of the service (DB). |
    | Change | Change/manageAuditPlugin |
    • View/getDBServiceList
    • View/getDBServiceDetail
    | Service | Service | Configure audit plugin options of the service (DB). |
    | Change | Change/manageSystemConfig |
    • View/getDBServiceList
    • View/getDBServiceDetail
    • View/getSystemConfig
    | Service | Service | Configure system config options of the service (DB). |
    | Change | Change/changeDeleteProtectionConfig |
    • View/getDBServiceList
    • View/getDBServiceDetail
    | Service | Service | Change return protection settings of the service (DB). |
    | Change | Change/manageOperatingSystem |
    • View/getDBServiceList
    • View/getDBServiceDetail
    • View/getOperatingSystemConfig
    | Service | Service | Upgrade the operating system of the service (DB) |
    | Change | Change/importBackupFromObjectStorage |
    • View/getBucketList
    • View/getBucketDetail
    | Service | Service | Import selected backup files from a bucket. |

    Caution

    If you grant someone access to a specific action but not to the required related actions, they won't be able to complete their tasks. Sub Account automatically includes these related permissions to prevent this issue. However, if you manually uncheck these auto-selected related actions, the system assumes this was intentional and won't override your selection.