DB & Server Access Control quickstart

Prev Next

Available in VPC

With NAVER Cloud Platform's DB & Server Access Control, you can easily and conveniently manage access permissions for servers and databases, log task history, and conduct audits. While you can explore the service in detail with our Getting Started and Using DB & Server Access Control guides, we recommend starting with this quickstart overview to understand the complete workflow. Here is the entire process for using DB & Server Access Control's:

1. Set user permissions
2. Subscribe to the service and set up a proxy server
3. Register access control targets
4. Set access permissions
5. Install the client and access resources
6. Monitor and audit task history
7. Unsubscribe from the service

Using the DB & Server Access Control service consists of stages of administrator environment configuration, user access, and auditing task history. For more information on the service structure, how to operate it, and terminology, see DB & Server Access Control concepts.

1. Set user permissions

Set permissions to use the DB & Server Access Control service. Permissions for the DB & Server Access Control service are defined by adding policies to the "sub-account" issued by the NAVER Cloud Platform Sub Account service. Thus, you need to first create a sub-account other than your main account through Sub Account.

Note

Sub Account is a free service with no additional charges. For more information about Sub Account and pricing, see Services > Management & Governance > Sub Account on the NAVER Cloud Platform portal.

The DB & Server Access Control service does not have a separate permission system, and console usage and resource access permissions are managed together through Sub Account. Permissions can be set using predefined system-managed (System Managed) policies and user-defined (User Created) policies, which you define by selecting the permissions yourself. To use the DB & Server Access Control service safely, it is recommended that you configure and manage the minimum number of permissions required to use the service. For detailed instructions, see:

2. Subscribe to the service and set up a proxy server

When you subscribe to the DB & Server Access Control service, a proxy server that relays access and logs task history is created in the customer's VPC. During the subscription stage, select the VPC and Subnet for deploying the proxy server, as well as the server specifications suitable for the scale of the access control targets, and set the dashboard analytics criteria (business hours, bulk query criteria).

Caution

Since the DB & Server Access Control service features access history logging as its core function, you must first subscribe to the Cloud Log Analytics service.

For detailed instructions, see:

3. Register access control targets

Register resources subject to access control and logging as server targets or DB targets. Before creating a server target, you must first set the usage range, and for each target, you can set the logging range (Request or Request + Response) and personal information masking. For detailed instructions, see:

4. Set access permissions

User-specific resource access permissions are managed through user-defined policies in Sub Account. If you define access permissions for specific server targets or DB targets as policies and link them to a sub-account or group, the proxy server checks those policies when a user logs in to allow or deny access. For detailed instructions, see:

5. Install the client and access resources

Downloads the dedicated client (Windows, macOS) from the user guide, installs it on their PC, and logs in with a sub-account. Using an access tool (terminal, DB client, etc.) after logging in allows you to connect to an authorized server or DB via the proxy server. For detailed instructions, see:

6. Monitor and audit task history

On the console dashboard, you can view analytics on anomalies, such as access blocking status, non-business hour access, and bulk query activity. Detailed logs, such as commands, queries, and results executed by users, can be viewed and audited in the Cloud Log Analytics service. If long-term retention is required, you can store data in a bucket using the Object Storage service. For detailed instructions, see:

7. Unsubscribe from the service

To stop using the service, delete any registered access control targets and then cancel your subscription. The proxy server created in the customer VPC will be automatically deleted upon canceling your subscription. Deleting the proxy server may forcibly terminate ongoing connections and task sessions. For detailed instructions, see: