Managing Data Catalog permissions
    • PDF

    Managing Data Catalog permissions

    • PDF

    Article Summary

    Available in VPC

    By using Sub Account, NAVER Cloud Platform's account management service, you can set various access permissions for Data Catalog. Sub Account provides System Managed policies and User Created policies for setting management and administration permissions.

    Note

    Sub Account is a service provided free of charge upon subscription request. For more details about Sub Account, see the Service > Management & Governance > Sub Account menu in the NAVER Cloud Platform portal, as well as the Sub Account guide.

    System Managed policies

    System Managed policies are role-based policies defined by NAVER Cloud Platform for user convenience. Once system managed policies are granted to a sub account created in Sub Account, that sub account can use Data Catalog. The following is a brief description about System Managed policies of Data Catalog.

    Policy namePolicy description
    NCP_ADMINISTRATORPermission to access the portal and console in NAVER Cloud Platform in the same manner as main accounts
    NCP_INFRA_MANAGERPermission to use all services in NAVER Cloud Platform and access My Page > Manage notifications in the portal
    NCP_VPC_DATA_CATALOG_MANAGERPermission to use all features within VPC-based Data Catalog
    NCP_VPC_DATA_CATALOG_VIEWERPermission to use only the view feature in VPC-based Data Catalog

    User Created policies

    User Created policies are policies that users may create. Once User Created policies are granted to a sub account created in Sub Account, that sub account can only use the user-assigned action combinations. The following is a brief description about User Created policies of Data Catalog.

    ClassificationAction nameRelated action(s)Resource typeGroup by resource typeAction description
    ViewView/getBucketListView/getClassifierListObjectStorage
    :Bucket
    ObjectStorage
    :Bucket
    Get the list of buckets in use in Object Storage.
    ViewView/getClassifierDetailView/getClassifierListClassifierClassifierView detailed information of classifier
    ViewView/getClassifierList--ClassifierView lists of classifier
    ViewView/getConnectionDetailView/getConnectionListConnectionConnectionView detailed information of connection
    ViewView/getConnectionList--ConnectionView lists of connection
    ViewView/getDatabaseDetailView/getDatabaseList
    View/getTableDetail
    View/getTableList
    View/getTagTemplateDetail
    View/getTagTemplateList
    DatabaseDatabaseView details of Data Catalog’s database
    ViewView/getDatabaseList--DatabaseView lists of Data Catalog’s database
    ViewView/getDBServiceDetailView/getDBServiceListVPCCloudDBforMySQL
    :Service
    VPCCloudDBforMySQL
    :Service
    View detailed information of CDB for MySQL's Service(DB)
    ViewView/getDBServiceListView/getDBServiceList-VPCCloudDBforMySQL
    :Service
    View Lists of CDB for MySQL's Service(DB)
    ViewView/getObjectListView/getBucketListObjectStorage
    :Bucket
    ObjectStorage
    :Bucket
    Read of Object Storage's Object
    ViewView/getScannerDetailView/getScannerListScannerScannerView detailed information of scanner
    ViewView/getScannerList--ScannerView lists of scanner
    ViewView/getTableDetailView/getTableListTableTableView details of Data Catalog’s table
    ViewView/getTableList--TableView lists of Data Catalog’s table
    ViewView/getTagTemplateDetailView/getTagTemplateListTagTemplateTagTemplateView tag template details
    ViewView/getTagTemplateList--TagTemplateView tag template lists
    ChangeChange/createClassifier--ClassifierCreate classifier
    ChangeChange/createConnectionView/getDBServiceList
    View/getDBServiceDetail
    View/getBucketList
    View/getObjectList
    -ConnectionCreate connection
    ChangeChange/createDatabaseView/getTagTemplateDetail
    View/getTagTemplateList
    View/getBucketList
    View/getObjectList
    -DatabaseCreate Data Catalog’s database
    ChangeChange/createScannerView/getClassifierDetail
    View/getClassifierList
    View/getConnectionDetail
    View/getConnectionList
    View/getDatabaseDetail
    View/getDatabaseList
    Change/createConnection
    Change/createClassifier
    -ScannerCreate scanner
    ChangeChange/createTableView/getDatabaseDetail
    View/getDatabaseList
    View/getTagTemplateDetail
    View/getTagTemplateList
    -TableCreate Data Catalog’s table
    ChangeChange/createTagTemplate--TagTemplateCreate tag template
    ChangeChange/deleteClassifierView/getClassifierDetail
    View/getClassifierList
    ClassifierClassifierDelete classifier
    ChangeChange/deleteConnectionView/getConnectionDetail
    View/getConnectionList
    ConnectionConnectionDelete connection
    ChangeChange/deleteDatabaseView/getDatabaseDetail
    View/getDatabaseList
    View/getTagTemplateDetail
    View/getTagTemplateList
    DatabaseDatabaseDelete Data Catalog’s database
    ChangeChange/deleteScannerView/getClassifierDetail
    View/getClassifierList
    View/getConnectionDetail
    View/getConnectionList
    View/getDatabaseDetail
    View/getDatabaseList
    View/getScannerDetail
    View/getScannerList
    ScannerScannerDelete scanner
    ChangeChange/deleteTableView/getTableDetail
    View/getTableList
    TableTableDelete Data Catalog’s table
    ChangeChange/deleteTagTemplateView/getTagTemplateDetail
    View/getTagTemplateList
    TagTemplateTagTemplateDelete tag template
    ChangeChange/pauseScannerScheduleView/getClassifierDetail
    View/getClassifierList
    View/getConnectionDetail
    View/getConnectionList
    View/getDatabaseDetail
    View/getDatabaseList
    View/getScannerDetail
    View/getScannerList
    View/getTableDetail
    View/getTableList
    View/getTagTemplateDetail
    View/getTagTemplateList
    --Pause scanner running cycle
    ChangeChange/reloadDataCatalog-CatalogCatalogReload setting information of Data Catalog
    ChangeChange/resumeScannerScheduleView/getClassifierDetail
    View/getClassifierList
    View/getConnectionDetail
    View/getConnectionList
    View/getDatabaseDetail
    View/getDatabaseList
    View/getScannerDetail
    View/getScannerList
    ScannerScannerRestart scanner running cycle
    ChangeChange/runScannerView/getClassifierDetail
    View/getClassifierList
    View/getConnectionDetail
    View/getConnectionList
    View/getDatabaseDetail
    View/getDatabaseList
    View/getScannerDetail
    View/getScannerList
    ScannerScannerRun scanner
    ChangeChange/stopScannerView/getClassifierDetail
    View/getClassifierList
    View/getConnectionDetail
    View/getConnectionList
    View/getDatabaseDetail
    View/getDatabaseList
    View/getScannerDetail
    View/getScannerList
    ScannerScannerStop running scanner
    ChangeChange/subscribeProduct-CatalogCatalogRequest subscription or cancellation to Data Catalog
    ChangeChange/updateClassifierView/getClassifierDetail
    View/getClassifierList
    ClassifierClassifierEdit classifier
    ChangeChange/updateConnectionView/getScannerDetail
    View/getScannerList
    ConnectionConnectionEdit connection
    ChangeChange/updateDatabaseView/getDatabaseDetail
    View/getDatabaseList
    View/getTagTemplateDetail
    View/getTagTemplateList
    View/getBucketList
    View/getObjectList
    DatabaseDatabaseEdit Data Catalog’s database
    ChangeChange/updateScannerView/getConnectionDetail
    View/getConnectionList
    View/getDatabaseDetail
    View/getDatabaseList
    View/getScannerDetail
    View/getScannerList
    View/getClassifierDetail
    View/getClassifierList
    ScannerScannerEdit scanner
    ChangeChange/updateTableView/getDatabaseDetail
    View/getDatabaseList
    View/getTagTemplateDetail
    View/getTagTemplateList
    TableTableEdit Data Catalog’s table
    ChangeChange/updateTagTemplateView/getTagTemplateDetail
    View/getTagTemplateList
    TagTemplateTagTemplateEdit tag template
    Caution

    Even when you are granted permission for a specific action, if you are not also granted permissions for the related actions that are required, then you won't be able to perform jobs properly. To prevent such issues, Sub Account provides a feature that automatically grants permissions for related actions when granting action permissions. However, if you deselect related actions that are automatically granted, then the system determines that it was done intentionally by the main account user and does not forcibly include them. Thus, be careful when setting permissions.


    Was this article helpful?

    Changing your password will log you out immediately. Use the new password to log back in.
    First name must have atleast 2 characters. Numbers and special characters are not allowed.
    Last name must have atleast 1 characters. Numbers and special characters are not allowed.
    Enter a valid email
    Enter a valid password
    Your profile has been successfully updated.