Cloud DB for MongoDB permissions management
    • PDF

    Cloud DB for MongoDB permissions management

    • PDF

    Article summary

    The latest service changes have not yet been reflected in this content. We will update the content as soon as possible. Please refer to the Korean version for information on the latest updates.

    Available in VPC

    By using Sub Account, NAVER Cloud Platform's account management service, you can set various access permissions for Cloud DB for MongoDB. Sub Account provides System Managed policies and User Created policies for setting management and administration permissions.

    Note

    Sub Account is a service provided free of charge upon subscription request. For more information about Sub Account, see Services > Management & Governance > Sub Account in NAVER Cloud Platform portal, as well as the Sub Account user guide.

    System-managed policies

    System-managed policies are role-based policies defined by NAVER Cloud Platform for user convenience. Once system-managed policies are granted to a sub account created in Sub Account, that sub account can use Cloud DB for MongoDB. The following is a brief description of the system-managed policies of Cloud DB for MongoDB.

    Policy namePolicy description
    NCP_ADMINISTRATORPermission to access the portal and console in NAVER Cloud Platform in the same manner as main accounts
    NCP_INFRA_MANAGERPermission to use all services in NAVER Cloud Platform and access My Page > Manage notifications in the portal
    NCP_VPC_CLOUD_DB_FOR_MONGODB_MANAGERPermission to use all the features in VPC-based Cloud DB for MongoDB
    NCP_VPC_CLOUD_DB_FOR_MONGODB_VIEWERPermission to only use the view list and search features in VPC-based Cloud DB for MongoDB

    User-defined policies

    User-defined policies are policies that users may create. Once the user-defined policies are granted to a sub account created in Sub Account, that sub account can only use the user-assigned action combinations. The following is a brief description of the user created policies of Cloud DB for MongoDB.

    ClassificationAction nameRelated action(s)Resource typeGroup by resource typeAction description
    ViewView/getDBDashboardView/getServiceList
    View/getServiceDetail
    ServiceServiceView service’s DB Dashboard
    ViewView/getDBLogsView/getServiceList
    View/getServiceDetail
    ServiceServiceView service DB log
    ViewView/getOSDashboardView/getServiceList
    View/getServiceDetail
    ServiceServiceView service’s OS dashboard
    ViewView/getQueryTimelineView/getServiceList
    View/getServiceDetail
    ServiceServiceView service Query Timeline
    ViewView/getServiceBackupDetailView/getServiceBackupList
    View/getServiceList
    View/getServiceDetail
    ServiceServiceView service backup details
    ViewView/getServiceBackupListView/getServiceList-ServiceView service backup settings list
    ViewView/getServiceDetailView/getServiceListServiceServiceCheck service details
    ViewView/getServiceList--ServiceView service list
    ViewView/getServiceServerEventDetailView/getServiceList
    View/getServiceDetail
    View/getServiceServerEventList
    ServiceServiceView service’s server event details
    ViewView/getServiceServerEventListView/getServiceList-ServiceView service server event list
    ViewView/getSubnetDetailView/getSubnetListVPC:SubnetServiceCheck accessible subnet for service
    ViewView/getSubnetList--ServiceView subnet list required for service
    ViewView/getVPCDetailView/getVPCListVPC:VPCServiceCheck accessible VPCs for service
    ViewView/getVPCList--ServiceView VPC list required for service
    ViewView/getBucketList--ServiceView bucket list to export selected file
    ViewView/getBucketDetailView/getBucketListObjectStorage:BucketServiceSelect Bucket to export the selected file
    ViewView/getDBServerLogsView/getServiceList
    View/getServiceDetail
    ServiceServiceView the log file of the selected DB Server
    ChangeChange/changePrimaryView/getServiceList
    View/getServiceDetail
    ServiceServiceChange Primary of Replica Set
    ChangeChange/changeSpecView/getServiceList
    View/getServiceDetail
    ServiceServiceChange service specifications
    ChangeChange/createConnectStringView/getServiceList
    View/getServiceDetail
    ServiceServiceCreate service access string
    ChangeChange/createServiceView/getVPCList
    View/getVPCDetail
    View/getSubnetList
    View/getSubnetDetail
    View/getServiceList
    -ServiceCreate service
    ChangeChange/createServiceWithBackupFileView/getServiceList
    View/getServiceDetail
    View/getServiceBackupList
    View/getServiceBackupDetail
    ServiceServiceCreate new service using backup file
    ChangeChange/deleteServiceView/getServiceList
    View/getServiceDetail
    ServiceServiceDelete service
    ChangeChange/deleteServiceBackupView/getServiceBackupList
    View/getServiceBackupDetail
    ServiceServiceDelete service backup
    ChangeChange/manageAdminUserView/getServiceList
    View/getServiceDetail
    ServiceServiceManage service’s Admin User
    ChangeChange/manageConfigServerChange/manageConfigServer
    View/getServiceDetail
    ServiceServiceManage service’s Config Server
    ChangeChange/manageDBUserView/getServiceList
    View/getServiceDetail
    ServiceServiceManage service DB users
    ChangeChange/manageMongosChange/manageMongos
    View/getServiceDetail
    ServiceServiceManage service’s Mongos
    ChangeChange/managePublicDomainView/getServiceList
    View/getServiceDetail
    ServiceServiceManage public domain that allows external access to service
    ChangeChange/manageReplicaSetView/getServiceList
    View/getServiceDetail
    ServiceServiceManage replica set of service
    ChangeChange/manageServiceBackupTimeView/getServiceList
    View/getServiceDetail
    View/getServiceBackupList
    View/getServiceBackupDetail
    ServiceServiceManage service backup settings
    ChangeChange/manageShardView/getServiceList
    View/getServiceDetail
    ServiceServiceManage service shard
    ChangeChange/restartServiceView/getServiceList
    View/getServiceDetail
    ServiceServiceRestart service
    ChangeChange/exportBackupToObjectStorageView/getServiceList
    View/getServiceDetail
    View/getBucketList
    View/getBucketDetail
    View/getServiceBackupDetail
    View/getServiceBackupList
    ServiceServiceExport the selected backup file to Object Storage
    ChangeChange/upgradeDBVersionView/getDBServiceList
    View/getDBServiceDetail
    ServiceServiceUpgrade MongoDB version of Service (DB)
    ChangeChange/deleteDBServerLogView/getDBServiceList
    View/getDBServiceDetail
    View/getDBServerLogs
    ServiceServiceDelete log file for the selected DB server
    ChangeChange/exportDBServerLogsToObjectStorageView/getServiceList
    View/getServiceDetail
    View/getDBServerLogs
    View/getBucketList
    View/getBucketDetail
    ServiceServiceExport the selected log file to Object Storage
    Caution

    Even when you are granted permission for a specific action, you won't be able to perform the task properly unless you are also granted permission for the required related actions. To prevent such issues, Sub Account provides a feature that automatically grants permissions for related actions when granting action permissions. However, if you deselect related actions that are automatically granted, then the system determines that it was done intentionally by the main account user and won't forcibly include them. Use care when setting permissions.


    Was this article helpful?

    Changing your password will log you out immediately. Use the new password to log back in.
    First name must have atleast 2 characters. Numbers and special characters are not allowed.
    Last name must have atleast 1 characters. Numbers and special characters are not allowed.
    Enter a valid email
    Enter a valid password
    Your profile has been successfully updated.