- Print
- PDF
Managing Effective Log Search & Analytics permissions
- Print
- PDF
Available in Classic and VPC
By using Sub Account, which is NAVER Cloud Platform's account management service, you can set various access permissions for Effective Log Search & Analytics. Sub Account provides System Managed policies and User Created policies for setting management and administration permissions.
The Sub Account service is provided free of charge upon subscription request. For more information on Sub Account, refer to the Service > Management & Governance > Sub Account menu in the NAVER Cloud Platform portal, as well as the Sub Account Guide.
System Managed policies
System Managed policies are role-based policies defined by NAVER Cloud Platform for user convenience. Once System Managed policies are granted to a sub account created in Sub Account, that sub account can use Effective Log Search & Analytics. The following is a brief description about System Managed policies of Effective Log Search & Analytics.
Policy Name | Description |
---|---|
NCP_ADMINISTRATOR | Permission to access the portal and console in NAVER Cloud Platform in the same manner as main accounts |
NCP_INFRA_MANAGER | Permission to use all services in NAVER Cloud Platform and access My Page > Manage notifications in the portal |
NCP_ELSA_MANAGER | Permission to use all features of Effective Log Search & Analytics |
NCP_ELSA_VIEWER | Permission to only use the View list and Search features of Effective Log Search & Analytics |
User-defined policy
User-defined policies are policies that users can create. Once User-defined policies are granted to a sub account created in Sub Account, that sub account can only use the user-assigned action combinations. The following is a brief description about User-defined policies of Effective Log Search & Analytics.
Type | Action Name | Related action(s) | Resource type | Group by resource type | Action Description |
---|---|---|---|---|---|
View | View/getBucketList | - | - | - | View bucket list of object storage |
View | View/getExportHistory | View/getProjectList | Project | Project | View export history |
View | View/getProjectList | - | - | Project | View project list |
Change | Change/changeProjectDescription | View/getProjectList Change/writeObject View/getBucketList | Project | Project | Modifies project description |
Change | Change/createProject | Change/writeObject View/getBucketList | - | Project | Create new project |
Change | Change/deleteProject | View/getProjectList | Project | Project | Delete project |
Change | Change/deleteSymbolicationFile | View/getProjectList | Project | Project | Delete project symbol file |
Change | Change/setExportLog | View/getProjectList | Project | Project | Set log export |
Change | Change/subscribeProduct | - | - | - | Request or cancel subscription to Effective Log Search & Analytics |
Change | Change/uploadSymbolicationFile | View/getProjectList | Project | Project | Upload symbol file to project |
Change | Change/writeObject | View/getBucketList | ObjectStorage:Bucket | Project | Use Object Storage bucket |
Even when you are granted permission for a specific action, if you are not also granted permissions for the related actions that are required, then you won't be able to perform jobs properly. To prevent such issues, Sub Account provides a feature that automatically grants permissions for related actions when granting action permissions. However, if you deselect related actions that are automatically granted, then the system determines that it was done intentionally by the main account user and won't forcibly include them. So, be careful when setting permissions.