Service integrations

Prev Next

Available in VPC

This guide identifies the services that must be used in conjunction with the DB & Server Access Control service for smooth operation, and explains how to subscribe to and prepare to use them. The services requiring integration with the DB & Server Access Control service are as follows:

  • Required integration services
    • Cloud Log Analytics: Stores access history logs collected by the proxy server. You must subscribe to it before subscribing to the DB & Server Access Control service.
    • Sub Account: Required to log into the client and set target access permissions per user.
    • Object Storage: Necessary to create a bucket for preserving long-term access records as required by regulations such as the Personal Information Protection Act.
  • Optional integration services
    • Data Query: Enables you to view and analyze logs stored long-term in Object Storage using SQL.
    • Cloud Activity Tracer: Automatically records the history of management operations performed in the DB & Server Access Control console.
  • Required services for each connection environment
    • SSL VPN: Required when connecting to the proxy server via the client in an environment with internet access.
    • IPSec VPN: Required for VPC connection in a closed network environment where the internet is blocked.

Cloud Log Analytics

NAVER Cloud Platform's Cloud Log Analytics is a paid service, and can be used after subscribing to the service. The DB & Server Access Control service first checks whether Cloud Log Analytics is in use on the subscription screen, and if it is not in use, the subscription cannot be completed. Make sure to subscribe to this service first before subscribing to the DB & Server Access Control service. Learn more in the Cloud Log Analytics user guide.

Note

Logs stored in Cloud Log Analytics are automatically deleted after 30 days. To retain logs for long-term periods, configure the settings to export logs to Object Storage.

Sub Account

NAVER Cloud Platform's Sub Account service is provided free of charge and does not require a separate subscription. The DB & Server Access Control service does not have its own user permission system and uses the user-defined policies in Sub Account as access control policies. After creating a target, create a user-defined policy that includes access permissions for that target and grant it to the sub-account. Client login is also supported only with a sub-account. Learn more in the Sub Account user guide.

Object Storage

NAVER Cloud Platform's Object Storage is a paid service, and you can create buckets after subscribing to the service. Related regulations, such as the Personal Information Protection Act and the Information and Communications Network Act (ISMS-P), require that access records to personal information processing systems be preserved for at least 1 year. Create a bucket in advance to export logs from Cloud Log Analytics to Object Storage for long-term retention. Learn more in the Object Storage user guide.

SSL VPN

NAVER Cloud Platform's SSL VPN is a paid service, and can be used after subscribing to the service. When using the DB & Server Access Control client in an environment with internet access, connect to the proxy server via SSL VPN. Learn more in the SSL VPN user guide.

IPSec VPN

NAVER Cloud Platform's IPSec VPN is a paid service, and can be used after subscribing to the service. When using the DB & Server Access Control client in a closed network environment where the internet is blocked, IPSec VPN must be configured. Learn more in the IPSec VPN user guide.

Data Query

NAVER Cloud Platform's Data Query is a paid service that can be optionally integrated. It enables you to use SQL queries to view and analyze access history logs that are long-term preserved in Object Storage. It is useful when you need to search for access records of a specific period or analyze access patterns for audit purposes. Learn more in the Data Query user guide.

Cloud Activity Tracer

NAVER Cloud Platform's Cloud Activity Tracer is a service that can be optionally integrated. It automatically records the history of management operations performed on the console without separate configuration. The history of console management operations in the DB & Server Access Control service, such as target creation/deletion and access permission changes, is preserved in Cloud Activity Tracer, making it available for use in internal security audits or compliance reviews. Learn more in the Cloud Activity Tracer user guide.