Managing Cloud DB for MongoDB permissions
    • PDF

    Managing Cloud DB for MongoDB permissions

    • PDF

    Article Summary

    Available in VPC

    By using Sub Account, NAVER Cloud Platform's account management service, you can set various access permissions for Cloud DB for MongoDB. Sub Account provides system-managed policies and user-created policies for setting management and administration permissions.

    Note

    Sub Account is a service provided free of charge upon subscription request. For more details about Sub Account, refer to the Services > Management & Governance > Sub Account menu in the NAVER Cloud Platform portal, and Sub Account user guide.

    System-managed policies

    System-managed policies are role-based policies defined by NAVER Cloud Platform for user convenience. Once system-managed policies are granted to a sub account created in Sub Account, that sub account can use Cloud DB for MongoDB. The following is a brief description of the system-managed policies of Cloud DB for MongoDB.

    PolicyPolicy description
    NCP_ADMINISTRATORPermission to access the portal and console in NAVER Cloud Platform in the same manner as main accounts
    NCP_INFRA_MANAGERPermission to use all services in NAVER Cloud Platform and access My page > Manage notifications in the portal
    NCP_VPC_CLOUD_DB_FOR_MONGODB_MANAGERPermission to use all the features in VPC-based Cloud DB for MongoDB
    NCP_VPC_CLOUD_DB_FOR_MONGODB_VIEWERPermission to only use the view list and search features in VPC-based Cloud DB for MongoDB

    User-created policies

    User-created policies are policies that users may create. Once user-created policies are granted to a sub account created in Sub Account, that sub account can only use the user-assigned action combinations. The following is a brief description of the user created policies of Cloud DB for MongoDB.

    DivisionAction nameRelated action(s)Resource typeGroup by resource typeAction description
    ViewView/getDBDashboardView/getServiceList
    View/getServiceDetail
    ServiceServiceView service’s DB dashboard
    ViewView/getDBLogsView/getServiceList
    View/getServiceDetail
    ServiceServiceView service DB log
    ViewView/getOSDashboardView/getServiceList
    View/getServiceDetail
    ServiceServiceView service’s OS dashboard
    ViewView/getQueryTimelineView/getServiceList
    View/getServiceDetail
    ServiceServiceView service query timeline
    ViewView/getServiceBackupDetailView/getServiceBackupList
    View/getServiceList
    View/getServiceDetail
    ServiceServiceView service backup details
    ViewView/getServiceBackupListView/getServiceList-ServiceView service backup settings list
    ViewView/getServiceDetailView/getServiceListServiceServiceCheck service details
    ViewView/getServiceList--ServiceView service list
    ViewView/getServiceServerEventDetailView/getServiceList
    View/getServiceDetail
    View/getServiceServerEventList
    ServiceServiceView service’s server event details
    ViewView/getServiceServerEventListView/getServiceList-ServiceView service server event list
    ViewView/getSubnetDetailView/getSubnetListVPC:SubnetServiceCheck accessible subnet for service
    ViewView/getSubnetList--ServiceView subnet list required for service
    ViewView/getVPCDetailView/getVPCListVPC:VPCServiceCheck accessible VPCs for service
    ViewView/getVPCList--ServiceView VPC list required for service
    ViewView/getBucketList--ServiceView bucket list to export selected file
    ViewView/getBucketDetailView/getBucketListObjectStorage:BucketServiceSelect bucket to export the selected file
    ChangeChange/changePrimaryView/getServiceList
    View/getServiceDetail
    ServiceServiceChange primary of replica set
    ChangeChange/changeSpecView/getServiceList
    View/getServiceDetail
    ServiceServiceChange service specifications
    ChangeChange/createConnectStringView/getServiceList
    View/getServiceDetail
    ServiceServiceCreate service access string
    ChangeChange/createServiceView/getVPCList
    View/getVPCDetail
    View/getSubnetList
    View/getSubnetDetail
    View/getServiceList
    -ServiceCreate service
    ChangeChange/createServiceWithBackupFileView/getServiceList
    View/getServiceDetail
    View/getServiceBackupList
    View/getServiceBackupDetail
    ServiceServiceCreate new service using backup file
    ChangeChange/deleteServiceView/getServiceList
    View/getServiceDetail
    ServiceServiceDelete service
    ChangeChange/deleteServiceBackupView/getServiceBackupList
    View/getServiceBackupDetail
    ServiceServiceDelete service backup
    ChangeChange/manageAdminUserView/getServiceList
    View/getServiceDetail
    ServiceServiceManage service’s admin user
    ChangeChange/manageConfigServerChange/manageConfigServer
    View/getServiceDetail
    ServiceServiceManage service’s config server
    ChangeChange/manageDBUserView/getServiceList
    View/getServiceDetail
    ServiceServiceManage service DB users
    ChangeChange/manageMongosChange/manageMongos
    View/getServiceDetail
    ServiceServiceManage service’s mongos
    ChangeChange/managePublicDomainView/getServiceList
    View/getServiceDetail
    ServiceServiceManage public domain that allows external access to service
    ChangeChange/manageReplicaSetView/getServiceList
    View/getServiceDetail
    ServiceServiceManage replica set of service
    ChangeChange/manageServiceBackupTimeView/getServiceList
    View/getServiceDetail
    View/getServiceBackupList
    View/getServiceBackupDetail
    ServiceServiceManage service backup settings
    ChangeChange/manageShardView/getServiceList
    View/getServiceDetail
    ServiceServiceManage service shard
    ChangeChange/restartServiceView/getServiceList
    View/getServiceDetail
    ServiceServiceRestart service
    ChangeChange/exportBackupToObjectStorageView/getServiceList
    View/getServiceDetail
    View/getBucketList
    View/getBucketDetail
    View/getServiceBackupDetail
    View/getServiceBackupList
    ServiceServiceExport the selected backup file to Object Storage
    ChangeChange/upgradeDBVersionView/getDBServiceList
    View/getDBServiceDetail
    ServiceServiceUpgrade service’s MongoDB version (DB)
    Caution

    Even when you are granted permission for a specific action, you cannot perform jobs properly if you are not also granted permissions for the related actions that are required. To prevent such issues, Sub Account provides a feature that automatically grants permissions for related actions when granting action permissions. However, if you deselect related actions that are automatically granted, the system determines that it was done intentionally by the main account user and does not forcibly include them. Thus, be careful when setting permissions.


    Was this article helpful?

    Changing your password will log you out immediately. Use the new password to log back in.
    First name must have atleast 2 characters. Numbers and special characters are not allowed.
    Last name must have atleast 1 characters. Numbers and special characters are not allowed.
    Enter a valid email
    Enter a valid password
    Your profile has been successfully updated.