Available in VPC
You can set different access permissions for Datafence using NAVER Cloud Platform's Sub Account service. Sub Account offers both system-managed (System Managed) and user-defined (User Created) policies to help you configure management and operation permissions.
Sub Account is a free service with no additional charges. For more information about Sub Account, see Services > Management & Governance > Sub Account on the NAVER Cloud Platform portal and the Sub Account user guide.
System-managed policies
System-managed policies are pre-built, role-based policies that NAVER Cloud Platform provides for your convenience. When you assign one of these policies to a sub account, that account gets access to Datafence. Here are the available system-managed policies for Datafence:
| Policy name | Policy description |
|---|---|
| NCP_ADMINISTRATOR | Full access to all services, same as the main account |
| NCP_INFRA_MANAGER | Access to all services, except My Account > Manage billing information and expense > Manage billing and payment on the console |
| NCP_FINANCE_MANAGER | Access limited to the Cost Explorer services and My Account > Manage billing information and expense > Manage billing and payment on the console |
| NCP_VPC_DATAFENCE_MANAGER | Full access to all features of the VPC-based Datafence |
| NCP_VPC_DATAFENCE_VIEWER | View-only access to all Datafence features on the VPC platform |
| NCP_DATA_FENCE_SERVICE_ROLE | Access for the Datafence service role |
User-defined policies
User-defined policies let you create custom permissions. When you assign a user-defined policy to a sub account, that account can only perform the specific actions you've allowed. Here are the available user-defined policies for Datafence:
| Type | Action | Related action | Resource type | Group by resource type | Action description |
|---|---|---|---|---|---|
| View | View/downloadDataFenceUsage |
|
Datafence | Datafence | Download current Datafence usage. |
| View | View/getApprovalDetail |
|
Box | Box | View details about export review requests. |
| View | View/getApprovalList |
|
Box | Box | View list of export review requests. |
| View | View/getBoxAcgRuleList |
|
Box | Box | View ACG of box servers. |
| View | View/getBoxDetail |
|
Box | Box | View box details. |
| View | View/getBoxList |
|
Datafence | Datafence | View box list. |
| View | View/getBoxServerImage |
|
Datafence | Datafence | View box server image created in Datafence. |
| View | View/getBucketList | - | ObjectStorage:Bucket | ObjectStorage:Bucket | View buckets used for import and export requests and export review. |
| View | View/getDataExportDetail |
|
Box | Box | View export request details. |
| View | View/getDataExportList |
|
Box | Box | View list of export requests. |
| View | View/getDataFence | - | - | Datafence | View Datafence. |
| View | View/getDataFenceDetail | View/getDataFence | Datafence | Datafence | View Datafence details. |
| View | View/getDataGroupAccessList |
|
Box | Box | View the box's share data view status. |
| View | View/getDataGroupDetail |
|
DataGroup | DataGroup | View data group details. |
| View | View/getDataGroupList | - | - | DataGroup | View data group list. |
| View | View/getDataImportDetail |
|
Box | Box | View import request details. |
| View | View/getDataImportList |
|
Box | Box | View list of import requests. |
| View | View/getFenceAcgRuleList |
|
Datafence | Datafence | View ACG of Datafence server within Datafence. |
| View | View/getFenceBoxAcgRuleList |
|
Datafence | Datafence | View ACG between Datafence server and box server within Datafence. |
| View | View/getFenceInfraList |
|
Datafence | Datafence | View infrastructure list within Datafence. |
| View | View/getFenceServerImage |
|
Datafence | Datafence | View Datafence server image created in Datafence. |
| View | View/getObjectList | View/getBucketList | ObjectStorage:Bucket | ObjectStorage:Bucket | View files in buckets. |
| View | View/getSslVpnList |
|
Datafence | Datafence | View integrated SSL VPN list. |
| Change | Change/cancelDataExport |
|
Box | Box | Cancel export request. |
| Change | Change/createBox |
|
Datafence | Datafence | Create box within Datafence. |
| Change | Change/createBoxServerImage |
|
Box | Box | Create box server image. |
| Change | Change/createDataExport |
|
Box | Box | Request to export data in the box. |
| Change | Change/createDataFence |
|
Datafence | Datafence | Create Datafence |
| Change | Change/createDataGroup |
|
DataGroup | DataGroup | Create data group. |
| Change | Change/createDataImport |
|
Box | Box | Request to import data in the box. |
| Change | Change/createFenceServerImage |
|
Datafence | Datafence | Create Datafence server image in Datafence. |
| Change | Change/deleteDataGroup | View/getDataGroupList | DataGroup | DataGroup | Return data group. |
| Change | Change/editBoxMemo |
|
Box | Box | Edit box memo. |
| Change | Change/editDataExportMemo |
|
Box | Box | Edit export request memo. |
| Change | Change/editDataFenceMemo |
|
Datafence | Datafence | Edit Datafence memo. |
| Change | Change/editDataGroupMemo |
|
DataGroup | DataGroup | Edit data group memo. |
| Change | Change/editDataImportMemo |
|
Box | Box | Edit import request memo. |
| Change | Change/manageApproval |
|
Box | Box | Approve or reject export requests. |
| Change | Change/manageBoxServer |
|
Box | Box | Adjust box server. |
| Change | Change/manageFenceServer |
|
Datafence | Datafence | Adjust Datafence server. |
| Change | Change/modifyBox |
|
Box | Box | Edit infrastructure in the box. |
| Change | Change/modifyBoxAcgRule |
|
Box | Box | Edit box's ACG. |
| Change | Change/modifyBoxInternetAccess |
|
Box | Box | Edit box's external network block status. |
| Change | Change/modifyBoxNAS |
|
Box | Box | Edit box's NAS. |
| Change | Change/modifyDataGroupAccess |
|
Box | Box | Change viewing permission of shared data by box. |
| Change | Change/modifyFenceAcgRule |
|
Datafence | Datafence | Edit Datafence server's ACG. |
| Change | Change/modifyFenceBoxAcgRule |
|
Datafence | Datafence | Edit ACG between Datafence server and box server. |
| Change | Change/modifyFenceInfra |
|
Datafence | Datafence | Edit infrastructure of Datafence component. |
| Change | Change/modifyFenceNAS |
|
Datafence | Datafence | Edit NAS of the Datafence component. |
| Change | Change/resetBoxServerPassword |
|
Box | Box | Edit box server's access password. |
| Change | Change/resetFenceServerPassword |
|
Datafence | Datafence | Edit Datafence server's access password. |
| Change | Change/returnBox |
|
Box | Box | Return box in Datafence. |
| Change | Change/returnDataFence | View/getDataFence | Datafence | Datafence | Return Datafence. |
| Change | Change/setSslVpn |
|
Datafence | Datafence | Specify SSL VPN in Datafence. |
| Change | Change/modifyNotificationRecipient |
|
Datafence | Datafence | Add or remove notification recipients when the Datafence configuration is changed. |
| View | View/downloadBoxLoginKey |
|
Box | Box | Download a box server authentication key within Datafence. |
| View | View/downloadFenceLoginKey |
|
Datafence | Datafence | Download a Datafence server authentication key. |
| Change | Change/editDataFenceExportBucket |
|
Datafence | Datafence | Specify an Object Storage bucket for Datafence export review. |
If you grant permission for a specific action without granting the required related action permissions, the task may not be performed properly.
- When you grant action permissions, Sub Account automatically grants the related action permissions as well.
- If you deselect automatically granted related actions, the system considers this intentional and does not forcibly include them. Use caution when configuring permissions.