Available in VPC
This section describes how to configure Datafence and analysis environments to create or return Datafence.
Create Datafence
To create Datafence:
- In the VPC environment on the NAVER Cloud Platform console, navigate to
> Services > Big Data & Analytics > Datafence. - Click the My Datafence menu.
- Click [Create My Datafence] in the upper section of the interface.
- Read the service notices, indicate your agreement, and click [OK].
- Follow the steps below in order:
1. Create Datafence environment
The Datafence administrator can manage the data for analysis using Datafence. Configure the Datafence server for the administrator and the storage to upload the shared data for analysis.

- Select the specifications and number of Datafence servers and click [Add].
- The only available OS is Ubuntu. The shared data storage is provided in a mounted status.
- You can create up to 4 Datafence servers.
- Enter the capacity and quantity of shared data storage and click [Add].
- The shared data storage is mounted in the Datafence server and each box's TensorFlow server, Linux server, and Hadoop cluster, making it easy to share files.
- You can create up to 4 shared data storages, each with a capacity ranging from 500 to 10,000 GB. Their capacity can be scaled up in increments of 100 GB.
- If needed, you can leave a memo.
- Enter up to 50 characters.
- Go to
> Services > Management & Governance > Sub Account > Roles on the NAVER Cloud Platform console and select the NRN of the created service role.
- For more information on how to configure roles to create Datafence, see Configure Datafence service roles.
- Enter the Datafence's Sub Account details and click [Add].
- A Sub Account is created based on your input and registered to the Sub Account service. You can view, modify, and delete the account’s detailed settings from the Sub Account menu on the console.
- You can add up to 2 Sub Accounts.
- When you have entered all the details, click [Next] in the lower part of the interface.
2. Create a Box environment for analysis
The analysis box is where the actual data analysis is performed. Create a box environment to access the shared data, the target of the analysis, and perform the analysis.

- Configure the Connect Server's specifications, storage capacity, and quantity and click [Add].
- The only available OS is Windows. You can access Cloud Hadoop or TensorFlow servers using the PuTTY of the Connect Server.
- You can create up to 4 Connect Servers.
- Configure the TensorFlow Server's type, specifications, storage capacity, and quantity and click [Add].
- The available options are CPU or GPU types. For the CPU type, you can create up to 4 servers. For the GPU type, you can create up to 2 servers.
- Configure the Hadoop cluster and click [Add].
- You can create 0 to 2 clusters. By default, 1 edge node and 2 master nodes are provided per 1 cluster. You can create a total of 2 to 8 worker nodes.
- Configure the Linux server for internal use within the box and click [Add].
- The only available OS is Ubuntu. You can create 0 to 4 servers.
- Configure the capacity and quantity of the NAS for internal use within the box and click [Add].
- It is used to import files from outside or export analysis results after external communications are blocked. Each NAS is provided mounted on Hadoop, TensorFlow server, and Linux server.
- You can create up to 4 NASs, each with a capacity ranging from 500 to 10,000 GB. Their capacity can be scaled up in increments of 100 GB.
- If needed, you can leave a memo.
- Enter up to 50 characters.
- Enter the box's Sub Account details and click [Add].
- A Sub Account is created based on your input and registered to the Sub Account service. You can view, modify, and delete the account’s detailed settings from the Sub Account menu on the console.
- As the box's Sub Account is used by analysts, it has limited access permissions compared to the Datafence's Sub Account.
- You can add up to 2 Sub Accounts.
- When you have entered all the details, click [Next] in the lower part of the interface.
3. Set Datafence access information
Enter the Datafence's name, and configure the Datafence environment and the access details of each box environment. As each server's user name is created automatically, you only need to configure their password.

- Enter the Datafence's name.
- Enter a combination of 3 to 20 characters using Roman alphabets (lower case), numbers, and hyphens (-). Its first letter must be a lowercase Roman alphabet, and its final letter cannot be a hyphen (-).
- Enter the password for the account used to access the Datafence server.
- Enter a combination of 8 to 14 characters using English alphabets (both cases), numbers, and special characters. You cannot use quotation marks, backtick, ₩, /, &, $, and space among special characters.
- Select an Object Storage bucket to be used as the interim storage space for analysis results during the export review process.
- To create a new bucket, click [Go to Create Object Storage bucket]. Go to the Object Storage menu in the console displayed in a new window. Create a bucket and click
to see it in the dropdown list.
- To create a new bucket, click [Go to Create Object Storage bucket]. Go to the Object Storage menu in the console displayed in a new window. Create a bucket and click
- Enter the password for the accounts used to access the box's various servers.
- Enter a combination of 8 to 14 characters using English alphabets (both cases), numbers, and special characters. You cannot use quotation marks, backtick, ₩, /, &, $, and space among special characters.
4. Final confirmation
Review the details and click [Complete].
- To download the size of the infrastructure you want to create, click [Download total size of the requested infrastructure].
- The data's creation may take up to a few hours. An email notification is sent upon completion.
Return Datafence.
To return Datafence that is no longer in use:
When you return Datafence, all the servers and data inside are deleted. As the deleted data cannot be recovered, proceed with caution.
- You can only return Datafence whose boxes and infrastructures are in a normal status.
- You can return Datafence only if no routing rules for SSL VPN have been set up.
- To delete: Go to [VPC] > [Route Table] to view the routes in the table of routes dedicated to Fence. > Click [Configure routes]. > Delete rules relevant to SSL VPN and save the changes.
- In the VPC environment on the NAVER Cloud Platform console, navigate to
> Services > Big Data & Analytics > Datafence. - Click the My Datafence menu.
- Find the Datafence list among the tabs of lists and click the Datafence you want to delete. Once your target is selected, click [Return Datafence].
- Click [OK] in the return popup window.
- Once the return process is completed, the target Datafence is removed from the list.
Configure Datafence service roles
To manage users of Datafence, you have to use Sub Account. To do so, relevant roles must be created in advance using the Sub Account's [Roles] feature. To create appropriate roles, follow the below steps:
- From NAVER Cloud Platform console, navigate to
> Services > Management & Governance > Sub Account. - Click the Roles menu.
- Click [Create Roles+].
- Enter the name of the role, select its Service type, and click [Create].
- After accessing the detail page of the created role, click [Policies] > [Add individual permission] at the bottom of the page.
- Search for the policy NCP_VPC_DATAFENCE_SERVICE_ROLE by its name and add it.
- Click [Role application target] > [Add] on the role's detail page.
- Select Datafence and click [Add].
- Once it is created successfully, you can select the service role when creating Datafence.