DB & Server Access Control permissions management

Prev Next

Available in VPC

You can set different access permissions for DB & Server Access Control using NAVER Cloud Platform's Sub Account service. Sub Account offers both system-managed (System Managed) and user-defined (User Created) policies to help you configure management and operation permissions.

Note

Sub Account is a free service with no additional charges. For more information about Sub Account, see the Services > Management & Governance > Sub Account menu and the Sub Account user guide in the NAVER Cloud Platform portal.

System-managed policies

System-managed policies are pre-built, role-based policies that NAVER Cloud Platform provides for your convenience. When you assign one of these policies to a sub account, that account gets access to DB & Server Access Control. Here are the available system-managed policies for DB & Server Access Control:

Policy name Policy description
NCP_ADMINISTRATOR Full access to all services, same as the main account.
NCP_INFRA_MANAGER Access to all NAVER Cloud Platform services, except the My Account > Manage billing information and expense > Manage billing and payment menu in the console.
NCP_FINANCE_MANAGER Access only to Cost Explorer and the My Account > Manage billing information and expense > Manage billing and payment menu in the console.
NCP_VPC_DB_&_SERVER_ACCESS_CONTROL_MANAGER Full access to all DB & Server Access Control features on the VPC platform.
NCP_VPC_DB_&_SERVER_ACCESS_CONTROL_VIEWER View-only access to all DB & Server Access Control features on the VPC platform.

User-defined policies

User-defined policies let you create custom permissions. When you assign a user-defined policy to a sub account, that account can only perform the specific actions you've allowed. Here are the available user-defined policies for DB & Server Access Control:

Type Action Related action Resource type Group by resource type Action description
View View/getVPCList - - VPC View VPC for DB & Server Access Control proxy configuration.
View View/getVPCDetail View/getVPCList VPC: VPC VPC View VPC details for DB & Server Access Control proxy configuration.
View View/getSubnetList - - Subnet View subnet for DB & Server Access Control proxy configuration.
View View/getSubnetDetail View/getSubnetList VPC: Subnet Subnet View subnet details for DB & Server Access Control proxy configuration.
View View/getDSACProxySpec - - DB & Server Access Control View DB & Server Access Control proxy specifications.
View View/getDSACProxyDetail - - DB & Server Access Control View DB & Server Access Control proxy details.
View View/getServerList Server:ServiceInstance Server View DB & Server Access Control target server list.
View View/getServerDetail View/getServerList Server:ServiceInstance Server Select DB & Server Access Control target server list.
View View/getCDBList - Cloud DB for Redis:service
Cloud DB PostgreSQL:service
Cloud DB for MySQL:service
Cloud DB for MSSQL:service
Cloud DB for MongoDB:service
DB & Server Access Control View DB & Server Access Control target CDB list.
View View/getCDBDetail View/getCDBList Cloud DB for Redis:service
Cloud DB PostgreSQL:service
Cloud DB for MySQL:service
Cloud DB for MSSQL:service
Cloud DB for MongoDB:service
DB & Server Access Control Select DB & Server Access Control target CDB list.
View View/getAccessTargetDetail View/getAccessTargetList AccessTarget DB & Server Access Control View DB & Server Access Control target details.
View View/getAccessTargetMaskingDetail View/getAccessTargetMaskingList - DB & Server Access Control View DB & Server Access Control target masking rule details.
View View/getDashboard - - DB & Server Access Control View DB & Server Access Control Dashboard screen.
View View/getAccessTargetList - - DB & Server Access Control View DB & Server Access Control target list (server, DB).
View View/getAccessTargetMaskingList - - DB & Server Access Control View DB & Server Access Control target masking rule list.
Change Change/subscribeService - - DB & Server Access Control Manage subscription to the DB & Server Access Control service.
Change Change/createDSACProxy - - DB & Server Access Control Create DB & Server Access Control proxy server.
Change Change/rebootDSACProxy View/getDSACProxyDetail - DB & Server Access Control Restart DB & Server Access Control proxy server.
Change Change/updateDSACProxy View/getDSACProxyList
View/getDSACProxyDetail
- DB & Server Access Control Change DB & Server Access Control proxy specifications.
Change Change/createAccessTargetServer View/getServerList
View/getServerDetail
View/getAccessTargetList
- DB & Server Access Control Create DB & Server Access Control target server.
Change Change/createTargetDB View/getServerList
View/getCDBList
View/getServerDetail
View/getCDBDetail
View/getAccessTargetList
- DB & Server Access Control Create DB & Server Access Control target DB (DB, DBMS Server).
Change Change/createAccessTargetMasking - - DB & Server Access Control Create DB & Server Access Control target masking rule.
Change Change/updateAccessTargetDetail View/getAccessTargetList
View/getAccessTargetDetail
AccessTarget DB & Server Access Control Change DB & Server Access Control target details.
Change Change/deleteAccessTarget View/getAccessTargetList
View/getAccessTargetDetail
AccessTarget DB & Server Access Control Delete DB & Server Access Control target list.
Change Change/deleteAccessTargetMasking View/getAccessTargetMaskingList
View/getAccessTargetMaskingDetail
UserCustomMaskingPolicy DB & Server Access Control Delete DB & Server Access Control target masking rule.
Change Change/updateAccessTargetMasking View/getAccessTargetMaskingList
View/getAccessTargetMaskingDetail
UserCustomMaskingPolicy DB & Server Access Control Edit DB & Server Access Control target masking rule.
Change Change/updateTargetServerRange - - DB & Server Access Control Edit DB & Server Access Control target server usage range value.
Change Change/createDashboardPolicy - - DB & Server Access Control Configure DB & Server Access Control Dashboard view screen.
Change Change/permitAccessTarget - AccessTarget DB & Server Access Control Designate targets to which users are allowed access.
Caution

If you grant someone access to a specific action but not to the required related actions, they won't be able to complete their tasks. Sub Account automatically includes these related permissions to prevent this issue. However, if you manually uncheck these auto-selected related actions, the system assumes this was intentional and won't override your selection.

Precautions for setup

Take note of the following when using Sub Account to set sub-account access permissions for the DB & Server Access Control service:

  • Prohibition on main account usage: We do not recommend using your main account to access the DB & Server Access Control service. If you use an account with NAVER Cloud Platform's admin permissions, all the permissions for the account can be captured and abused when an intrusion occurs.
  • Creation of sub-accounts for each role: To distinguish users of DB & Server Access Control, you can create sub-accounts for each role and grant the necessary permissions.