最新のコンテンツが反映されていません。早急にアップデート内容をご提供できるよう努めております。最新のコンテンツ内容は韓国語ページをご参照ください。
VPC環境で利用できます。
NAVERクラウドプラットフォームのアカウント管理サービスである Sub Accountを使用すると、DB & Server Access Controlサービスのアクセス権限を様々な方法で設定できます。Sub Accountサービスでは、管理および運用権限の設定のためにマネージド(System Managed)ポリシーとユーザー定義(User Created)ポリシーを提供します。
Sub Accountは、ご利用の申し込みの際に別途料金が発生しない無料サービスです。Sub Accountに関する詳細は、NAVERクラウドプラットフォームポータルの サービス > Management & Governance > Sub Account メニューと Sub Account ご利用ガイド をご参照ください。
マネージドポリシー
マネージドポリシーは、ユーザーの便宜を図るために、NAVERクラウドプラットフォームが独自に定義したロールベースのポリシーです。Sub Accountサービスで作成したサブアカウントにマネージドポリシーを付与すると、権限を付与されたサブアカウントは DB & Server Access Controlサービスを利用できるようになります。DB & Server Access Controlサービスのマネージドポリシーについての説明は、次の通りです。
| ポリシー名 | ポリシーの説明 |
|---|---|
| NCP_ADMINISTRATOR | メインアカウントと同等の権限で、すべてのサービスにアクセスできる権限 |
| NCP_INFRA_MANAGER | すべてのサービスにアクセスできるものの、コンソールの My Account > 課金情報と費用管理 > 請求と決済管理メニューのみアクセスが制限された権限 |
| NCP_FINANCE_MANAGER | Cost Explorerサービスとコンソールの My Account > 課金情報と費用管理 > 請求と決済管理メニューのみにアクセスできる権限 |
| NCP_VPC_DB_&_SERVER_ACCESS_CONTROL_MANAGER | VPCベースの DB & Server Access Controlサービス内のすべての機能が利用できる権限 |
| NCP_VPC_DB_&_SERVER_ACCESS_CONTROL_VIEWER | VPCベースの DB & Server Access Controlサービス内の照会機能のみ利用できる権限 |
ユーザー定義ポリシー
ユーザー定義ポリシーは、ユーザーが直接作成できるポリシーです。Sub Accountサービスで作成したサブアカウントにユーザー定義ポリシーを付与すると、権限を付与されたサブアカウントはユーザーが割り当てたアクションの組み合わせでのみ利用できるようになります。DB & Server Access Controlサービスのユーザー定義ポリシーについての簡単な説明は、次の通りです。
| 区分 | アクション名 | 関連アクション | リソースタイプ | リソースタイプ別のグループ | アクションの説明 |
|---|---|---|---|---|---|
| View | View/getVPCList | - | - | VPC | DB & Server Access Controlのプロキシを構成するための VPCを照会 |
| View | View/getVPCDetail | View/getVPCList | VPC : VPC | VPC | DB & Server Access Controlのプロキシを構成するための VPCの詳細情報を照会 |
| View | View/getSubnetList | - | - | Subnet | DB & Server Access Controlのプロキシを構成するための Subnetを照会 |
| View | View/getSubnetDetail | View/getSubnetList | VPC : Subnet | Subnet | DB & Server Access Controlのプロキシを構成するための Subnetの詳細情報を照会 |
| View | View/getDSACProxySpec | - | - | DB & Server Access Control | DB & Server Access Controlのプロキシスペックを照会 |
| View | View/getDSACProxyDetail | - | - | DB & Server Access Control | DB & Server Access Controlのプロキシの詳細情報を照会 |
| View | View/getServerList | Server:ServiceInstance | Server | DB & Server Access Controlのターゲットサーバリストを照会 | |
| View | View/getServerDetail | View/getServerList | Server:ServiceInstance | Server | DB & Server Access Controlのターゲットサーバリストを選択 |
| View | View/getCDBList | - | Cloud DB for Redis:service Cloud DB PostgreSQL:service Cloud DB for MySQL:service Cloud DB for MSSQL:service Cloud DB for MongoDB:service |
DB & Server Access Control | DB & Server Access Controlのターゲット CDBリストを照会 |
| View | View/getCDBDetail | View/getCDBList | Cloud DB for Redis:service Cloud DB PostgreSQL:service Cloud DB for MySQL:service Cloud DB for MSSQL:service Cloud DB for MongoDB:service |
DB & Server Access Control | DB & Server Access Controlのターゲット CDBリストを選択 |
| View | View/getAccessTargetDetail | View/getAccessTargetList | AccessTarget | DB & Server Access Control | DB & Server Access Controlのターゲットの詳細情報を照会 |
| View | View/getAccessTargetMaskingDetail | View/getAccessTargetMaskingList | - | DB & Server Access Control | DB & Server Access Controlのターゲットマスキングルールの詳細情報を照会 |
| View | View/getDashboard | - | - | DB & Server Access Control | DB & Server Access Controlのダッシュボード画面を照会 |
| View | View/getAccessTargetList | - | - | DB & Server Access Control | DB & Server Access Controlのターゲットリストを照会(サーバ、DB) |
| View | View/getAccessTargetMaskingList | - | - | DB & Server Access Control | DB & Server Access Controlのターゲットマスキングルールのリストを照会 |
| Change | Change/subscribeService | - | - | DB & Server Access Control | DB & Server Access Controlサービスのご利用の申し込みと解約 |
| Change | Change/createDSACProxy | - | - | DB & Server Access Control | DB & Server Access Controlのプロキシサーバを作成 |
| Change | Change/rebootDSACProxy | View/getDSACProxyDetail | - | DB & Server Access Control | DB & Server Access Controlのプロキシサーバを再起動 |
| Change | Change/updateDSACProxy | View/getDSACProxyList View/getDSACProxyDetail |
- | DB & Server Access Control | DB & Server Access Controlのプロキシスペックを変更 |
| Change | Change/createAccessTargetServer | View/getServerList View/getServerDetail View/getAccessTargetList |
- | DB & Server Access Control | DB & Server Access Controlのターゲットサーバを作成 |
| Change | Change/createTargetDB | View/getServerList View/getCDBList View/getServerDetail View/getCDBDetail View/getAccessTargetList |
- | DB & Server Access Control | DB & Server Access Controlのターゲット DBを作成(DB、DBMS Server) |
| Change | Change/createAccessTargetMasking | - | - | DB & Server Access Control | DB & Server Access Controlのターゲットマスキングルールを作成 |
| Change | Change/updateAccessTargetDetail | View/getAccessTargetList View/getAccessTargetDetail |
AccessTarget | DB & Server Access Control | DB & Server Access Controlのターゲットの詳細情報を変更 |
| Change | Change/deleteAccessTarget | View/getAccessTargetList View/getAccessTargetDetail |
AccessTarget | DB & Server Access Control | DB & Server Access Controlのターゲットリストを削除 |
| Change | Change/deleteAccessTargetMasking | View/getAccessTargetMaskingList View/getAccessTargetMaskingDetail |
UserCustomMaskingPolicy | DB & Server Access Control | DB & Server Access Controlのターゲットマスキングルールを削除 |
| Change | Change/updateAccessTargetMasking | View/getAccessTargetMaskingList View/getAccessTargetMaskingDetail |
UserCustomMaskingPolicy | DB & Server Access Control | DB & Server Access Controlのターゲットマスキングルールを変更 |
| Change | Change/updateTargetServerRange | - | - | DB & Server Access Control | DB & Server Access Controlのターゲットサーバの利用区間数を変更 |
| Change | Change/createDashboardPolicy | - | - | DB & Server Access Control | DB & Server Access Controlのダッシュボード照会画面を設定 |
| Change | Change/permitAccessTarget | - | AccessTarget | DB & Server Access Control | ユーザーアクセス許可ターゲットの指定 |
特定のアクションに対する権限が付与されたとしても、関連する必須アクションに対する権限が一緒に付与されていない場合、タスクは正常に行えません。このような問題を防ぐため、Sub Accountサービスではアクション権限の付与時に、関連アクションに対する権限も自動で一緒に付与する機能を提供します。ただし、自動的に一緒に付与された関連アクションの選択を解除すると、メインアカウントユーザーの意図とみなし、システムで強制的に含めないようにするため、権限設定の際はご注意ください。
設定時の注意事項
Sub Accountを使用してサブアカウントに対する DB & Server Access Controlサービスのアクセス権限を設定する際には、以下の点にご注意ください。
- メインアカウント使用の禁止: DB & Server Access Controlサービスを利用する際は、メインアカウントの使用を避けることを推奨します。NAVERクラウドプラットフォームの管理者権限を持つアカウントを使用する場合、侵害事故が発生するとアカウントのすべての権限が奪取または悪用される可能性があります。
- ロール別サブアカウントの作成: DB & Server Access Controlサービスを利用するユーザーを区分するために、ロール別のサブアカウントを作成し、必要な権限を付与できます。