Managing Data Catalog permissions
    • PDF

    Managing Data Catalog permissions

    • PDF

    Article summary

    Available in VPC

    You can set various access permissions for Data Catalog using Sub Account, NAVER CLOUD PLATFORM's account management service. Sub Account provides System Managed policies and User Created policies for setting management and administration permissions.

    Note

    Sub Account is a service provided free of charge upon subscription request. For a detailed description of Sub Account, see Services > Management & Governance > Sub Account on the NAVER Cloud Platform portal and the Sub Account user guide.

    System-managed policies

    System-managed policies are role-based policies defined by NAVER Cloud Platform for user convenience. When you grant a managed policy to a subaccount created in the Sub Account, the authorized Sub Account will access the Data Catalog. Here is a brief description of managed policies in the Data Catalog.

    Policy namePolicy description
    NCP_ADMINISTRATORPermission to access the portal and console in NAVER Cloud Platform in the same manner as main accounts
    NCP_INFRA_MANAGERPermission to use all services in NAVER Cloud Platform and access My Page > Manage notifications in the portal
    NCP_VPC_DATA_CATALOG_MANAGERFull access to all features of the VPC-based Data Catalog
    NCP_VPC_DATA_CATALOG_VIEWERPermission to use the lookup feature of the VPC-based Data Catalog only

    User-defined policies

    User-defined policies are policies that users may create. Once the user-defined policies are granted to a sub account created in Sub Account, that sub account can only use the user-assigned action combinations. A brief description of custom policies in the Data Catalog is provided below.

    ClassificationAction nameRelated action(s)Resource typeGroup by resource typeAction description
    ViewView/getBucketListView/getObjectListObjectStorage
    :Bucket
    ObjectStorage
    :Bucket
    View details about a classifier
    ViewView/getClassifierDetailView/getClassifierListClassifierClassifierView details about a classifier
    ViewView/getClassifierList--ClassifierView a list of classifiers
    ViewView/getConnectionDetailView/getConnectionListConnectionConnectionView details about a connection
    ViewView/getConnectionList--ConnectionView a list of connections
    ViewView/getDatabaseDetailView/getDatabaseList
    View/getTableDetail
    View/getTableList
    View/getTagTemplateDetail
    View/getTagTemplateList
    DatabaseDatabaseView detailed information about a database in the Data Catalog
    ViewView/getDatabaseList--DatabaseView a list of databases in the Data Catalog
    ViewView/getMongoDBServiceDetailView/getMongoDBServiceListVPCCloudDBforMongoDB
    :Service
    VPCCloudDBforMongoDB
    :Service
    View CDB for MongoDB Service (DB) details
    ViewView/getMongoDBServiceList--VPCCloudDBMongoDB
    :Service
    View CDB for MongoDB Service (DB) list
    ViewView/getMssqlDBServiceDetailView/getMssqlDBServiceListVPCCloudDBforMssqlDB
    :Service
    VPCCloudDBforMssqlDB
    :Service
    View CDB for MssqlDB Service (DB) details
    ViewView/getMssqlDBServiceList--VPCCloudDBforMssqlDB
    :Service
    View CDB for MssqlDB Service (DB) list
    ViewView/getMysqlDBServiceDetailView/getMysqlDBServiceListVPCCloudDBforMysqlDB
    :Service
    VPCCloudDBforMysqlDB
    :Service
    View CDB for MysqlDB Service (DB) details
    ViewView/getMysqlDBServiceList--VPCCloudDBforMySQL
    :Service
    View CDB for MysqlDB Service (DB) List
    ViewView/getPostgreSQLDBServiceDetailView/getPostgreSQLDBServiceListVPCCloudDBforPostgreSQLDB
    :Service
    VPCCloudDBforPostgreSQLDB
    :Service
    View CDB for PostgreSQLDB Service (DB) Details
    ViewView/getPostgreSQLDBServiceList--VPCCloudDBforPostgreSQLDB
    :Service
    View CDB for PostgreSQLDB Service (DB) list
    ViewView/getObjectListView/getBucketListObjectStorage
    :Bucket
    ObjectStorage
    :Bucket
    Perform a read operation on an object in Object Storage
    ViewView/getScannerDetailView/getScannerListScannerScannerView scanner details
    ViewView/getScannerList--ScannerView a list of scanners
    ViewView/getTableDetailView/getTableListTableTableView table details for a table in the Data Catalog
    ViewView/getTableList--TableView a list of tables in the Data Catalog
    ViewView/getTagTemplateDetailView/getTagTemplateListTagTemplateTagTemplateView details about a tag template
    ViewView/getTagTemplateList--TagTemplateView a list of tag templates
    ChangeChange/createClassifier--ClassifierCreate a classifier
    ChangeChange/createConnectionView/getMongoDBServiceDetail
    View/getMongoDBServiceList
    View/getMssqlDBServiceDetail
    View/getMssqlDBServiceList
    View/getMysqlDBServiceDetail
    View/getMysqlDBServiceList
    View/getPostgreSQLDBServiceDetail
    View/getPostgreSQLDBServiceList
    -ConnectionCreate a connection
    ChangeChange/createDatabaseView/getTagTemplateDetail
    View/getTagTemplateList
    View/getBucketList
    View/getObjectList
    -DatabaseCreate a database for the Data Catalog
    ChangeChange/createScannerView/getClassifierDetail
    View/getClassifierList
    View/getConnectionDetail
    View/getConnectionList
    View/getDatabaseDetail
    View/getDatabaseList
    Change/createConnection
    Change/createClassifier
    View/getBucketList
    View/getObjectList
    -ScannerCreate a scanner
    ChangeChange/createTableView/getDatabaseDetail
    View/getDatabaseList
    View/getTagTemplateDetail
    View/getTagTemplateList
    -TableCreating tables in the Data Catalog
    ChangeChange/createTagTemplate--TagTemplateCreate a tag template
    ChangeChange/deleteClassifierView/getClassifierDetail
    View/getClassifierList
    ClassifierClassifierDelete a classifier
    ChangeChange/deleteConnectionView/getConnectionDetail
    View/getConnectionList
    ConnectionConnectionDelete a connection
    ChangeChange/deleteDatabaseView/getDatabaseDetail
    View/getDatabaseList
    View/getTagTemplateDetail
    View/getTagTemplateList
    DatabaseDatabaseDeleting databases in the Data Catalog
    ChangeChange/deleteScannerView/getClassifierDetail
    View/getClassifierList
    View/getConnectionDetail
    View/getConnectionList
    View/getDatabaseDetail
    View/getDatabaseList
    View/getScannerDetail
    View/getScannerList
    ScannerScannerDelete a scanner
    ChangeChange/deleteTableView/getTableDetail
    View/getTableList
    TableTableDeleting tables in the Data Catalog
    ChangeChange/deleteTagTemplateView/getTagTemplateDetail
    View/getTagTemplateList
    TagTemplateTagTemplateDelete a tag template
    ChangeChange/pauseScannerScheduleView/getClassifierDetail
    View/getClassifierList
    View/getConnectionDetail
    View/getConnectionList
    View/getDatabaseDetail
    View/getDatabaseList
    View/getScannerDetail
    View/getScannerList
    ScannerScannerPause the scanner's run cycle
    ChangeChange/reloadDataCatalog-CatalogCatalogReload Data Catalog settings information
    ChangeChange/resumeScannerScheduleView/getClassifierDetail
    View/getClassifierList
    View/getConnectionDetail
    View/getConnectionList
    View/getDatabaseDetail
    View/getDatabaseList
    View/getScannerDetail
    View/getScannerList
    ScannerScannerRestart the scanner's run cycle
    ChangeChange/runScannerView/getClassifierDetail
    View/getClassifierList
    View/getConnectionDetail
    View/getConnectionList
    View/getDatabaseDetail
    View/getDatabaseList
    View/getScannerDetail
    View/getScannerList
    ScannerScannerRun the scanner
    ChangeChange/stopScannerView/getClassifierDetail
    View/getClassifierList
    View/getConnectionDetail
    View/getConnectionList
    View/getDatabaseDetail
    View/getDatabaseList
    View/getScannerDetail
    View/getScannerList
    ScannerScannerStop scanner from running
    ChangeChange/subscribeProduct-CatalogCatalogUsing or terminating the Data Catalog service
    ChangeChange/updateClassifierView/getClassifierDetail
    View/getClassifierList
    ClassifierClassifierModifying classifiers
    ChangeChange/updateConnectionView/getScannerDetail
    View/getScannerList
    ConnectionConnectionModifying connections
    ChangeChange/updateDatabaseView/getDatabaseDetail
    View/getDatabaseList
    View/getTagTemplateDetail
    View/getTagTemplateList
    View/getBucketList
    View/getObjectList
    DatabaseDatabaseModifying databases in the Data Catalog
    ChangeChange/updateScannerView/getConnectionDetail
    View/getConnectionList
    View/getDatabaseDetail
    View/getDatabaseList
    View/getScannerDetail
    View/getScannerList
    View/getClassifierDetail
    View/getClassifierList
    ScannerScannerEdit the scanner
    ChangeChange/updateTableView/getDatabaseDetail
    View/getDatabaseList
    View/getTagTemplateDetail
    View/getTagTemplateList
    TableTableModifying tables in the Data Catalog
    ChangeChange/updateTagTemplateView/getTagTemplateDetail
    View/getTagTemplateList
    TagTemplateTagTemplateModifying tag templates
    Caution

    Even when you are granted permission for a specific action, you won't be able to perform the task properly unless you are also granted permission for the required related actions. To prevent such issues, Sub Account provides a feature that automatically grants permissions for related actions when granting action permissions. However, if you deselect related actions that are automatically granted, then the system determines that it was done intentionally by the main account user and won't forcibly include them. Use care when setting permissions.


    Was this article helpful?

    Changing your password will log you out immediately. Use the new password to log back in.
    First name must have atleast 2 characters. Numbers and special characters are not allowed.
    Last name must have atleast 1 characters. Numbers and special characters are not allowed.
    Enter a valid email
    Enter a valid password
    Your profile has been successfully updated.