- Print
- PDF
Managing Data Forest permissions
- Print
- PDF
You can use Sub Account, the account management service of NAVER Cloud Platform, to set various access permissions for Data Forest. Sub Account provides System Managed policies and User Created policies for setting management and administration permissions.
Sub Account is a service provided free of charge upon subscription. For more details about Sub Account, see the Services > Management & Governance > Sub Account menu in the NAVER Cloud Platform portal, as well as the Sub Account user guide.
System managed policies
System managed policies are role-based policies defined by NAVER Cloud Platform for user convenience. Once System Managed policies are granted to a sub account created in Sub Account, that sub account can use Data Forest. The following is a brief description about system managed policies of Data Forest.
Policy name | Policy description |
---|---|
NCP_ADMINISTRATOR | Permission to access the portal and console in NAVER Cloud Platform in the same manner as main accounts |
NCP_INFRA_MANAGER | Permission to use all services in NAVER Cloud Platform and access My Page > Manage notifications in the portal |
NCP_DATA_FOREST_MANAGER | Permission to use all the features in the Data Forest service |
NCP_DATA_FOREST_VIEWER | Permission to only use the view list and view features in Data Forest |
User created policies
User created policies are policies that users can create. Once user created policies are granted to a sub account created in Sub Account, that sub account can only use the user-assigned action combinations. The following is a brief description about system user created policies of Data Forest.
Classification | Action name | Related action(s) | Resource type | Group by resource type | Action description |
---|---|---|---|---|---|
View | View/getAccountList | - | - | Account | View account list |
View | View/getAccountDetail | View/getAccountList | Account | Account | View account details |
View | View/downloadAccountKerberosKeytab | View/getAccountList View/getAccountDetail | Account | Account | Download the account's Kerberos keytab |
View | View/getNotebookList | View/getAccountList View/getAccountDetail | - | Notebooks | View notebook list |
View | View/getNotebookDetail | View/getAccountList View/getAccountDetail View/getNotebookList | Notebook | Notebooks | View notebook details |
View | View/getVPCList | - | - | Notebooks | View VPC list |
View | View/getVPCDetail | View/getVPCList | VPC:VPC | Notebooks | View VPC details |
View | View/getSubnetList | View/getVPCList View/getVPCDetail | - | Notebooks | View subnet list |
View | View/getSubnetDetail | View/getVPCList View/getVPCDetail View/getSubnetList | VPC:Subnet | Notebooks | View subnet details |
View | View/getAppList | View/getAccountList View/getAccountDetail | - | Data Forest | View app list |
View | View/getAppDetail | View/getAccountList View/getAccountDetail View/getAppList | App | Data Forest | View app details |
View | View/getAIAppList | View/getAccountList View/getAccountDetail | - | AI Forest | View AI app list |
View | View/getAIAppDetail | View/getAccountList View/getAccountDetail View/getAIAppList | AIApp | AI Forest | View AI app details |
View | View/getAIAppLog | View/getAccountList View/getAccountDetail View/getAIAppList View/getAIAppDetail | AI App | AI Forest | View AI app log |
View | View/getAIWorkspaceList | View/getAccountList View/getAccountDetail | - | AI Forest | View AI workspace list |
View | View/getAIWorkspaceDetail | View/getAccountList View/getAccountDetail View/getAIWorkspaceList | AI Workspace | AI Forest | View AI workspace details |
View | View/getAIWorkspaceConfigurationList | View/getAccountList View/getAccountDetail View/getAIWorkspaceList | AI Workspace | AI Forest | View AI workspace settings |
View | View/getAIWorkspaceObjectList | View/getAccountList View/getAccountDetail View/getAIWorkspaceList | AI Workspace | AI Workspace | View AI workspace file and folder list |
View | View/getAIWorkspaceObjectContent | View/getAccountList View/getAccountDetail View/getAIWorkspaceList View/getAIWorkspaceObjectList | AI Workspace | AI Forest | Read AI workspace file content |
View | View/getMonitoring | View/getAccountList View/getAccountDetail View/getAppList View/getAIAppList | - | - | View monitoring |
View | View/getBucketList | - | - | - | View the bucket list. |
View | View/getObjectList | View/getBucketList | Object Storage:Bucket | Notebooks | View the object details of the bucket. |
View | View/getLoginKeyList | - | - | Notebooks | View the list of authentication keys. |
View | View/getNotebookAcgRuleList | View/getAccountList View/getAccountDetail View/getNotebookList View/getNotebookDetail | Notebook | Notebooks | View the list of ACG rule for notebook |
Change | Change/createAccount | View/getAccountList | - | Account | Create account |
Change | Change/deleteAccount | View/getAccountList View/getAccountDetail | Account | Account | Delete account |
Change | Change/setAccountQuota | View/getAccountList View/getAccountDetail | Account | Account | Change account's quota |
Change | Change/resetAccountKerberosKeytab | View/getAccountList View/getAccountDetail | Account | Account | Reset the account's Kerberos keytab |
Change | Change/resetAccountPassword | View/getAccountList View/getAccountDetail | Account | Account | Reset account password |
Change | Change/createNotebook | View/getAccountList View/getAccountDetail View/getVPCList View/getVPCDetail View/getSubnetList View/getSubnetDetail View/getLoginKeyList View/getBucketList View/getObjectList View/getNotebookList View/getNotebookDetail | - | Notebooks | Create notebook |
Change | Change/deleteNotebook | View/getAccountList View/getAccountDetail View/getNotebookList View/getNotebookDetail | Notebook | Notebooks | Delete notebook |
Change | Change/restartNotebook | View/getAccountList View/getAccountDetail View/getNotebookList View/getNotebookDetail | Notebook | Notebooks | Restart notebook |
Change | Change/setNotebookUserConfigurationList | View/getAccountList View/getAccountDetail View/getNotebookList View/getNotebookDetail | Notebook | Notebooks | Change notebook user settings |
Change | Change/createLoginKey | - | - | Notebooks | Create authentication key for notebook |
Change | Change/createApp | View/getAccountList View/getAccountDetail View/getAppList View/getAppDetail | Account | Data Forest | Create app |
Change | Change/deleteApp | View/getAccountList View/getAccountDetail View/getAppList View/getAppDetail | App | Data Forest | Delete app |
Change | Change/setAppLifetime | View/getAccountList View/getAccountDetail View/getAppList View/getAppDetail | App | Data Forest | Change app's lifetime |
Change | Change/setAppContainerCount | View/getAccountList View/getAccountDetail View/getAppList View/getAppDetail | App | Data Forest | Change the number of app's Component Containers |
Change | Change/startApp | View/getAccountList View/getAccountDetail View/getAppList View/getAppDetail | App | Data Forest | Start app |
Change | Change/stopApp | View/getAccountList View/getAccountDetail View/getAppList View/getAppDetail | App | Data Forest | Stop app |
Change | Change/killApplicationMaster | View/getAccountList View/getAccountDetail View/getAppList View/getAppDetail | App | Data Forest | Restart app's Application Master |
Change | Change/killAppContainer | View/getAccountList View/getAccountDetail View/getAppList View/getAppDetail | App | Data Forest | Restart app's Component Container |
Change | Change/submitAIApp | View/getAccountList View/getAccountDetail View/getAIWorkspaceList View/getAIWorkspaceDetail | AI Workspace | AI Forest | Run AI app |
Change | Change/killAIApp | View/getAccountList View/getAccountDetail View/getAIAppList View/getAIAppDetail | AI App | AI Forest | Stop AI app |
Change | Change/createAIWorkspace | View/getAccountList View/getAccountDetail | Account | AI Forest | Create AI workspace |
Change | Change/deleteAIWorkspace | View/getAccountList View/getAccountDetail View/getAIWorkspaceList View/getAIWorkspaceDetail | AI Workspace | AI Forest | Delete AI workspace |
Change | Change/copyAIWorkspace | View/getAccountList View/getAccountDetail View/getAIWorkspaceList View/getAIWorkspaceDetail | AI Workspace | AI Forest | Replicate AI workspace |
Change | Change/setAIWorkspaceConfiguration | View/getAccountList View/getAccountDetail View/getAIWorkspaceList View/getAIWorkspaceDetail View/getAIWorkspaceConfigurationList | AI Workspace | AI Forest | Change AI workspace settings |
Change | Change/setAIWorkspaceDescription | View/getAccountList View/getAccountDetail View/getAIWorkspaceList View/getAIWorkspaceDetail | AI Workspace | AI Forest | Change AI workspace details |
Change | Change/createAIWorkspaceObject | View/getAccountList View/getAccountDetail View/getAIWorkspaceList View/getAIWorkspaceObjectList | AI Workspace | AI Forest | Add new folder or file to AI workspace |
Change | Change/deleteAIWorkspaceObject | View/getAccountList View/getAccountDetail View/getAIWorkspaceList View/getAIWorkspaceObjectList | AI Workspace | AI Forest | Delete folder or file in AI workspace |
Change | Change/uploadAIWorkspaceObject | View/getAccountList View/getAccountDetail View/getAIWorkspaceList View/getAIWorkspaceObjectList | AI Workspace | AI Forest | Upload file to AI workspace |
Change | Change/renameAIWorkspaceObject | View/getAccountList View/getAccountDetail View/getAIWorkspaceList View/getAIWorkspaceObjectList | AI Workspace | AI Forest | Change name of folder or file in AI workspace |
Change | Change/saveAIWorkspaceObjectContent | View/getAccountList View/getAccountDetail View/getAIWorkspaceList View/getAIWorkspaceObjectList | AI Workspace | AI Forest | Save file content of AI workspace |
Change | Change/setObjectStorageBucket | View/getAccountList View/getAccountDetail View/getNotebookList View/getNotebookDetail View/getBucketList View/getObjectList | Notebook | Notebooks | Edit the notebook integration bucket. |
Even when you are granted permission for a specific action, if you are not also granted permissions for the related actions that are required, then you won't be able to perform jobs properly. To prevent such issues, Sub Account provides a feature that automatically grants permissions for related actions when granting action permissions. However, if you deselect related actions that are automatically granted, then the system determines that it was done intentionally by the main account user and does not forcibly include them. Thus, take caution when setting permissions.