Managing Cloud DB for MySQL permissions (VPC)
    • PDF

    Managing Cloud DB for MySQL permissions (VPC)

    • PDF

    Article Summary

    Available in VPC

    By using Sub Account, NAVER Cloud Platform's account management service, you can set various access permissions for Cloud DB for MySQL. Sub Account provides the system-managed and user-created policies for setting management and administration permissions.

    Note

    Sub Account is a service provided free of charge upon subscription request. For more details about Sub Account, see Services > Management & Governance > Sub Account in NAVER Cloud Platform portal, as well as the Sub Account Guide.

    System-managed policies

    System-managed policies are role-based policies defined by NAVER Cloud Platform for user convenience. Once the system-managed policies are granted to a sub account created in Sub Account, that sub account can use Cloud DB for MySQL. The following is a brief description of the system-managed policies of Cloud DB for MySQL.

    Policy namePolicy description
    NCP_ADMINISTRATORPermission to access the portal and console in NAVER Cloud Platform in the same manner as main accounts
    NCP_INFRA_MANAGERPermission to use all services in NAVER Cloud Platform and access My Page > Manage notifications in the portal
    NCP_VPC_CLOUD_DB_FOR_MYSQL_MANAGERPermission to use all the features in VPC-based Cloud DB for MySQL
    NCP_VPC_CLOUD_DB_FOR_MYSQL_VIEWERPermission to only use the view list and search features in VPC-based Cloud DB for MySQL

    User-created policies

    User-created policies are policies that users may create. Once the user-created policies are granted to a sub account created in Sub Account, that sub account can only use the user-assigned action combinations. The following is a brief description of the user-created policies of Cloud DB for MySQL.

    TypeAction nameRelated actionResource typeGroup by resource typeAction description
    ViewView/getDBBackupDetailView/getDBBackupList
    View/getDBServiceList
    View/getDBServiceDetail
    ServiceServiceView service (DB) backup information
    ViewView/getDBBackupListView/getDBServiceList-ServiceView service (DB) backup information
    ViewView/getDBDashboardView/getDBServiceList
    View/getDBServiceDetail
    ServiceServiceView DB dashboard of service (DB)
    ViewView/getDBLogsView/getDBServiceList
    View/getDBServiceDetail
    ServiceServiceView DB log of service (DB)
    ViewView/getDBServerEventDetailView/getDBServerEventListServiceServiceView server (DB) event details
    ViewView/getDBServerEventList--ServiceView server (DB) event list
    ViewView/getDBServiceDetailView/getDBServiceListServiceServiceView service (DB) details
    ViewView/getDBServiceList--ServiceView service (DB) list
    ViewView/getExecutingBinaryView/getDBServiceDetail
    View/getDBServiceList
    ServiceServiceCheck running binary log of selected DB server
    ViewView/getOSDashboardView/getDBServiceList
    View/getDBServiceDetail
    ServiceServiceView OS dashboard of service (DB)
    ViewView/getQueryTimelineView/getDBServiceList
    View/getDBServiceDetail
    ServiceServiceView query timeline of service (DB)
    ViewView/exportQueryTimelineView/getQueryTimeline
    View/getDBServiceList
    View/getDBServiceDetail
    ServiceServiceDownload searched service (DB) query timeline results
    ViewView/getSubnetDetailView/getSubnetListVPC:SubnetServiceCheck accessible subnet for service (DB)
    ViewView/getSubnetList--ServiceView subnet list required for service (DB)
    ViewView/getVPCDetailView/getVPCListVPC:VPCServiceCheck accessible VPC for service (DB)
    ViewView/getVPCList--ServiceView VPC list required for service (DB)
    ViewView/getDBServerLogsView/getDBServiceList
    View/getDBServiceDetail
    ServiceServiceView log file for the selected DB server
    ViewView/getBucketList--ServiceView bucket list to export selected file
    ViewView/getBucketDetailView/getBucketListObjectStorage:BucketServiceSelect bucket to export selected file
    ViewView/exportDBServiceListView/getDBServiceList-ServiceDownload service (DB) list
    ViewView/getSystemConfigView/getDBServiceList
    View/getDBServiceDetail
    ServiceServiceView the System Config option of service (DB)
    ChangeChange/addSlaveView/getDBServiceList
    View/getDBServiceDetail
    View/getSubnetList
    View/getSubnetDetail
    ServiceServiceAdd service (DB) slave DB
    ChangeChange/changeDBServerLogConfigView/getDBServiceList
    View/getDBServiceDetail
    ServiceServiceChange DB server log settings for service (DB)
    ChangeChange/changeDBSpecView/getDBServiceList
    View/getDBServiceDetail
    ServiceServiceChange service (DB) specifications
    ChangeChange/changeMasterDBView/getDBServiceList
    View/getDBServiceDetail
    ServiceServiceExecute service (DB) master DB failover
    ChangeChange/createDBServiceView/getVPCList
    View/getVPCDetail
    View/getSubnetList
    View/getSubnetDetail
    View/getDBServiceList
    -ServiceCreate service (DB)
    ChangeChange/createDBServiceWithRecoveryServerView/getDBServiceList
    View/getDBServiceDetail
    View/getVPCList
    View/getSubnetList
    ServiceServiceCreate new service with recovery server
    ChangeChange/deleteDBServiceView/getDBServiceList
    View/getDBServiceDetail
    ServiceServiceDelete service (DB) (Master, Stand Alone)
    ChangeChange/deleteDBServerView/getDBServiceList
    View/getDBServiceDetail
    ServiceServiceDelete slave and recovery servers of service (DB)
    ChangeChange/deleteDBServerLogView/getDBServerLogs
    View/getDBServiceList
    View/getDBServiceDetail
    ServiceServiceDelete log file for the selected DB server
    ChangeChange/killDBServiceSessionView/getDBServiceList
    View/getDBServiceDetail
    ServiceServiceForce end service (DB) session (ID)
    ChangeChange/manageBackupView/getDBServiceList
    View/getDBServiceDetail
    ServiceServiceManage service (DB) backup settings
    ChangeChange/manageDatabaseView/getDBServiceList
    View/getDBServiceDetail
    ServiceServiceManage database
    ChangeChange/manageDBConfigView/getDBServiceList
    View/getDBServiceDetail
    ServiceServiceManage service (DB) config
    ChangeChange/manageDBServiceNameView/getDBServiceList
    View/getDBServiceDetail
    ServiceServiceChange DB service name
    ChangeChange/manageDBServerNameView/getDBServiceList
    View/getDBServiceDetail
    ServiceServiceChange DB server name
    ChangeChange/manageDBUserView/getDBServiceList
    View/getDBServiceDetail
    ServiceServiceManage service (DB) users
    ChangeChange/recoveryToTimeView/getDBServiceList
    View/getDBBackupList
    View/getDBBackupDetail
    View/getDBServiceDetail
    View/getSubnetList
    View/getSubnetDetail
    ServiceServiceRestore service (DB) to specific point in time
    ChangeChange/recoveryWithBackupFileView/getDBServiceList
    View/getDBBackupList
    View/getDBBackupDetail
    View/getDBServiceDetail
    View/getSubnetList
    View/getSubnetDetail
    ServiceServiceRestore service (DB) with backup file
    ChangeChange/reinstallSlaveDBView/getDBServiceList
    View/getDBServiceDetail
    ServiceServiceReinstall slave DB
    ChangeChange/reinstallStandbyMasterDBView/getDBServiceList
    View/getDBServiceDetail
    ServiceServiceReinstall standby master DB
    ChangeChange/restartDBServiceView/getDBServiceList
    View/getDBServiceDetail
    ServiceServiceRestart service (DB)
    ChangeChange/setHAView/getDBServiceList
    View/getDBServiceDetail
    ServiceServiceChange service (DB) to high availability configuration
    ChangeChange/setStandaloneView/getDBServiceList
    View/getDBServiceDetail
    ServiceServiceChange service (DB) to the standalone configuration
    ChangeChange/skipReplicationErrorView/getDBServiceList
    View/getDBServiceDetail
    ServiceServiceCorrect an error by skipping query with a slave DB replication error
    ChangeChange/upgradeDBEngineView/getDBServiceList
    View/getDBServiceDetail
    ServiceServiceUpgrade MySQL engine version of service (DB)
    ChangeChange/managePublicDomainView/getDBServiceList
    View/getDBServiceDetail
    ServiceServiceRequest public domain for external access to DB server
    ChangeChange/exportBackupToObjectStorageView/getDBServiceList
    View/getDBServiceDetail
    View/getBucketList
    View/getBucketDetail
    View/getDBBackupList
    View/getDBBackupDetail
    ServiceServiceExport the selected backup file to object storage
    ChangeChange/exportDBServerLogsToObjectStorageView/getDBServiceList
    View/getDBServiceDetail
    View/getBucketList
    View/getBucketDetail
    View/getDBServerLogs
    ServiceServiceExport the selected log file to Object Storage
    ChangeChange/manageDBServiceSwapView/getDBServiceList
    View/getDBServiceDetail
    ServiceServiceManage swap memory of service (DB)
    ChangeChange/resetDBServiceView/getDBServiceList
    View/getDBServiceDetail
    Change/manageDBConfig
    ServiceServiceReset service (DB)
    ChangeChange/killDBServiceMultipleSessionView/getDBServiceList
    View/getDBServiceDetail
    ServiceServiceForce end multiple service (DB) session (ID)
    ChangeChange/changeMultizoneConfigView/getSubnetList
    View/getSubnetDetail
    View/getDBServiceList
    View/getDBServiceDetail
    -ServiceChange service (DB) multizone configuration
    ChangeChange/managePasswordPluginView/getDBServiceList
    View/getDBServiceDetail
    ServiceServiceSetting options for service (DB) password plugin
    ChangeChange/manageAuditPluginView/getDBServiceList
    View/getDBServiceDetail
    ServiceServiceSetting options for service (DB) audit plugin
    ChangeChange/manageSystemConfigView/getDBServiceList
    View/getDBServiceDetail
    View/getSystemConfig
    ServiceServiceSet the System Config option of service (DB)
    Caution

    Even when you are granted a permission for a specific action, you won't be able to perform the task properly unless you are also granted a permission for the related actions that are required. To prevent such issues, Sub Account provides a feature that automatically grants permissions for related actions when granting action permissions. However, if you deselect related actions that are automatically granted, then the system will not forcibly include them since it regards such de-selection done intentionally by the main account user. Thus, caution is advised when setting permissions.


    Was this article helpful?

    Changing your password will log you out immediately. Use the new password to log back in.
    First name must have atleast 2 characters. Numbers and special characters are not allowed.
    Last name must have atleast 1 characters. Numbers and special characters are not allowed.
    Enter a valid email
    Enter a valid password
    Your profile has been successfully updated.