Available in VPC
You can set different access permissions for Cloud DB for Cache using NAVER Cloud Platform's Sub Account service. Sub Account offers both system-managed (System Managed) and user-defined (User Created) policies to help you configure management and operation permissions.
Sub Account is a free service with no additional charges. For more information about Sub Account, see All Service > Management & Governance > Sub Account on the NAVER Cloud Platform portal and the Sub Account user guide.
System-managed policies
System-managed policies are pre-built, role-based policies that NAVER Cloud Platform provides for your convenience. When you assign one of these policies to a sub account, that account gets access to Cloud DB for Cache. Here are the available system-managed policies for Cloud DB for Cache:
| Policy name | Policy description |
|---|---|
| NCP_ADMINISTRATOR | Full access to all services, same as the main account. |
| NCP_INFRA_MANAGER | Access to all services, except My Account > Manage billing information and expense > Manage billing and payment menu on the console. |
| NCP_FINANCE_MANAGER | Access to only Cost Explorer service and My Account > Manage billing information and expense > Manage billing and payment menu on the console. |
| NCP_VPC_CLOUD_DB_FOR_CACHE_MANAGER | Full access to all Cloud DB for Cache features on the VPC platform |
| NCP_VPC_CLOUD_DB_FOR_CACHE_VIEWER | View-only access to all Cloud DB for Cache features and lists on the VPC platform |
User-defined policies
User-defined policies let you create custom permissions. When you assign a user-defined policy to a sub account, that account can only perform the specific actions you've allowed. Here are the available user-defined policies for Cloud DB for Cache:
| Type | Action | Related action | Resource type | Group by resource type | Action description |
|---|---|---|---|---|---|
| View | View/getServiceBackupDetail |
|
Service | Service | View detailed information about a service backup. |
| View | View/getServiceBackupList |
|
- | Service | View the list of service backup configurations. |
| View | View/getServiceDetail | View/getServiceList | Service | Service | View detailed service information. |
| View | View/getServiceList | - | - | Service | View the list of services. |
| View | View/getServiceListOfConfigGroup |
|
ConfigGroup | Service | View the list of services to which a config group is applied. |
| View | View/getServiceServerEventDetail |
|
Service | Service | View detailed server event information for a service. |
| View | View/getServiceServerEventList | View/getServiceList | - | Service | View the list of server events for a service. |
| View | View/getConfigGroupDetail | View/getConfigGroupList | ConfigGroup | ConfigGroup | View detailed information about a config group. |
| View | View/getConfigGroupList | - | - | ConfigGroup | View the list of config groups. |
| View | View/getOSDashboard |
|
Service | Service | View the OS dashboard for nodes that make up the service. |
| View | View/getCacheDashboard |
|
Service | Service | View the Cache dashboard for nodes that make up the service. |
| View | View/getSubnetDetail | View/getSubnetList | VPC:Subnet | Service | Check the subnets accessible for the service. |
| View | View/getSubnetList | - | - | Service | View the list of subnets required for the service. |
| View | View/getVPCDetail | View/getVPCList | VPC:VPC | Service | Check the VPCs accessible for the service. |
| View | View/getVPCList | - | - | Service | View the list of VPCs required for the service. |
| View | View/getBucketList | - | - | Service | View the list of buckets to which the selected file can be exported. |
| View | View/getBucketDetail | View/getBucketList | ObjectStorage:Bucket | Service | Select a bucket to which the selected file can be exported. |
| View | View/getServiceBackupManualList |
|
- | Service | View the list of manual backup configurations for a service. |
| View | View/getServiceBackupManualDetail |
|
Service | Service | View detailed information about a service manual backup. |
| View | View/exportDBServiceList | View/getServiceList | Service | Service | Download the service (DB) list. |
| View | View/getOperatingSystemConfig |
|
Service | Service | View the settings required for upgrading the operating system of the service (DB). |
| Change | Change/createService |
|
- | Service | Create a service. |
| Change | Change/createServiceWithBackupFile |
|
Service | Service | Create a new service using a backup file. |
| Change | Change/createConfigGroup | View/getConfigGroupList | - | ConfigGroup | Create a config group. |
| Change | Change/deleteService |
|
Service | Service | Delete a service. |
| Change | Change/deleteConfigGroup |
|
ConfigGroup | ConfigGroup | Delete a config group. |
| Change | Change/manageServiceBackup |
|
Service | Service | Configure service backups. |
| Change | Change/manageServiceConfigGroup |
|
Service | Service | Manage the config group for a service. |
| Change | Change/manageServiceNode |
|
Service | Service | Manage service nodes. |
| Change | Change/changeServiceSpec |
|
Service | Service | Change the service specifications. |
| Change | Change/manageConfigGroup |
|
ConfigGroup | ConfigGroup | Modify a config group. |
| Change | Change/restartService |
|
Service | Service | Restart the service. |
| Change | Change/changeFlushAll |
|
Service | Service | Delete all data on the DB server. |
| Change | Change/exportBackupToObjectStorage |
|
Service | Service | Export selected backup files to Object Storage. |
| Change | Change/createManualBackup |
|
Service | Service | Perform a manual backup for the service. |
| Change | Change/deleteManualBackupFile |
|
Service | Service | Delete a manual backup file for the service. |
| Change | Change/manageDBServerName |
|
Service | Service | Change the DB server name. |
| Change | Change/upgradeDBVersion |
|
Service | Service | Upgrade the service (DB) version. |
| Change | Change/manageOperatingSystem |
|
Service | Service | Upgrade the operating system of the service (DB). |
| Change | Change/setStandalone |
|
Service | Service | Change the service (DB) to a standalone configuration. |
| Change | Change/setHa |
|
Service | Service | Change the service (DB) to a high availability configuration. |
| Change | Change/exportDBServerLogsToObjectStorage |
|
Service | Service | Export selected log files to Object Storage. |
If you grant someone access to a specific action but not to the required related actions, they won't be able to complete their tasks.
- To prevent this issue, Sub Accounts automatically receive related action permissions when an action permission is granted.
- If a related action that was granted automatically is deselected, the system interprets it as the user's intention and does not force it to be included. Please be careful when configuring permissions.