Catálogo de permissões
Todas as permissões que podem ser concedidas, agrupadas por área do produto. Use esta página para descobrir qual chave corresponde à ação que você quer liberar.
Os rótulos são os mesmos que aparecem na tela do IAM.
Como ler
Nível indica o estrago que a permissão pode causar, e é o que a tela destaca:
| Nível | Significa |
|---|---|
| Baixo | Leitura, sem efeito colateral |
| Normal | Alteração do dia a dia |
| Alto | Destrutivo ou caro de desfazer |
| Crítico | Perda de dado ou de controle de acesso |
Escopos lista onde a chave pode ser concedida: Plataforma, Tenant, Customer, VDC. Conceder fora dos escopos permitidos é recusado.
Chaves terminadas em :* concedem tudo abaixo daquele prefixo, em qualquer profundidade — inclusive permissões criadas em versões futuras.
IAM
| Permissão | O que faz | Nível | Escopos |
|---|---|---|---|
* | Super administrator | Crítico | P |
iam:* | All iam:* permissions | Alto | PTCV |
iam:audit:view | View audit log | Baixo | PTCV |
iam:grant:* | All iam:grant:* permissions | Alto | PTCV |
iam:grant:create | Create direct grant | Crítico | PTCV |
iam:grant:renew | Renew direct grant | Normal | PTCV |
iam:grant:revoke | Revoke direct grant | Alto | PTCV |
iam:group:* | All iam:group:* permissions | Alto | PTCV |
iam:group:assign | Assign/unassign group | Crítico | PTCV |
iam:group:delete | Delete group | Alto | PTCV |
iam:group:manage | Manage group | Alto | PTCV |
iam:group:set-permissions | Set group permissions | Crítico | PTCV |
iam:users:* | All iam:users:* permissions | Alto | PTCV |
iam:users:effective-permissions:view | View effective permissions | Baixo | PTCV |
iam:users:invite | Invite user | Normal | PTCV |
iam:users:remove | Remove user | Alto | PTCV |
iam:users:update | Update user | Normal | PTCV |
iam:view | View IAM | Baixo | PTCV |
Tenant
| Permissão | O que faz | Nível | Escopos |
|---|---|---|---|
tenant:* | All tenant:* permissions | Alto | PTCV |
tenant:manage | Manage organization | Alto | PT |
tenant:view | View organization | Baixo | PT |
Customer
| Permissão | O que faz | Nível | Escopos |
|---|---|---|---|
customer:* | All customer:* permissions | Alto | PTC |
customer:archive | Archive customer | Alto | PT |
customer:create | Create customer | Alto | PT |
customer:reactivate | Reactivate customer | Alto | PT |
customer:update | Update customer | Normal | PTC |
customer:view | View customer | Baixo | PTC |
Contract
| Permissão | O que faz | Nível | Escopos |
|---|---|---|---|
contract:* | All contract:* permissions | Alto | PTC |
contract:create | Create contract | Alto | PTC |
contract:link-vdc | Link VDC | Alto | PTC |
contract:update | Update contract | Normal | PTC |
contract:view | View contract | Baixo | PTC |
Billing
| Permissão | O que faz | Nível | Escopos |
|---|---|---|---|
billing:* | All billing:* permissions | Alto | PTC |
billing:manage | Manage billing | Alto | PT |
billing:view | View billing | Normal | PTC |
VDC
| Permissão | O que faz | Nível | Escopos |
|---|---|---|---|
vdc:* | All vdc:* permissions | Alto | PTCV |
vdc:create | Create VDC | Normal | PTCV |
vdc:delete | Delete VDC | Alto | PTCV |
vdc:update | Update VDC | Normal | PTCV |
vdc:view | View VDC | Baixo | PTCV |
Virtual machines
| Permissão | O que faz | Nível | Escopos |
|---|---|---|---|
vm:* | All vm:* permissions | Alto | PTCV |
vm:clone | Clone VM | Normal | PTCV |
vm:console:* | All vm:console:* permissions | Alto | PTCV |
vm:console:file-transfer | Transfer files to/from VM console | Crítico | PTCV |
vm:console:view | View VM console | Crítico | PTCV |
vm:create | Create VM | Normal | PTCV |
vm:delete | Delete VM | Alto | PTCV |
vm:disk:* | All vm:disk:* permissions | Alto | PTCV |
vm:disk:destroy | Destroy VM disk | Alto | PTCV |
vm:disk:manage | Manage VM disks | Normal | PTCV |
vm:nic:* | All vm:nic:* permissions | Alto | PTCV |
vm:nic:manage | Manage VM NICs | Normal | PTCV |
vm:nic:manage-public-ip | Attach/detach public IP | Alto | PTCV |
vm:power | Power VM | Normal | PTCV |
vm:rename | Rename VM | Normal | PTCV |
vm:resize | Resize VM (memory & vCPU) | Normal | PTCV |
vm:snapshot:* | All vm:snapshot:* permissions | Alto | PTCV |
vm:snapshot:manage | Manage VM snapshots | Normal | PTCV |
vm:snapshot:rollback | Rollback VM snapshot | Alto | PTCV |
vm:view | View VM | Baixo | PTCV |
Storage
| Permissão | O que faz | Nível | Escopos |
|---|---|---|---|
storage:* | All storage:* permissions | Alto | PTCV |
storage:attach | Attach orphan disk | Normal | PTCV |
storage:boot_disks:view | View boot disks | Baixo | PTCV |
storage:delete | Delete orphan disk | Alto | PTCV |
storage:disk_migration:* | All storage:disk_migration:* permissions | Alto | PTCV |
storage:disk_migration:delete | Delete disk migration | Alto | PTCV |
storage:disk_migration:manage | Manage disk migration | Alto | PTCV |
storage:disk_migration:view | View disk migration | Baixo | PTCV |
storage:object_storage:* | All storage:object_storage:* permissions | Alto | PTCV |
storage:object_storage:bucket:create | Create bucket | Normal | PTCV |
storage:object_storage:bucket:delete | Delete bucket | Alto | PTCV |
storage:object_storage:buckets:view | View buckets | Baixo | PTCV |
storage:object_storage:credential:delete | Delete storage credential | Alto | PTCV |
storage:object_storage:credential:manage | Manage storage credentials | Alto | PTCV |
storage:object_storage:credentials:view | View object storage credentials | Baixo | PTCV |
storage:object_storage:lock | Lock object/directory | Normal | PTCV |
storage:object_storage:object:delete | Delete object | Alto | PTCV |
storage:object_storage:object:upload | Upload object | Normal | PTCV |
storage:object_storage:path:create | Create path | Normal | PTCV |
storage:object_storage:path:delete | Delete path | Alto | PTCV |
storage:object_storage:view | View storage | Baixo | PTCV |
storage:rename | Rename orphan disk | Normal | PTCV |
storage:view | View orphan disks | Baixo | PTCV |
storage:volume_disks:view | View volume disks | Baixo | PTCV |
Object storage
| Permissão | O que faz | Nível | Escopos |
|---|---|---|---|
object-storage:* | All object-storage:* permissions | Alto | PT |
object-storage:create | Create object storage provider | Normal | PT |
object-storage:delete | Delete object storage provider | Alto | PT |
object-storage:update | Update object storage provider | Normal | PT |
object-storage:view | View object storage providers | Baixo | PT |
Network
| Permissão | O que faz | Nível | Escopos |
|---|---|---|---|
network:* | All network:* permissions | Alto | PTCV |
network:customer_gateway:* | All network:customer_gateway:* permissions | Alto | PTCV |
network:customer_gateway:manage | Manage customer gateway | Alto | PTCV |
network:customer_gateway:view | View customer gateway | Baixo | PTCV |
network:dns:manage | Manage DNS records | Normal | PTCV |
network:public-ip:* | All network:public-ip:* permissions | Alto | PTCV |
network:public-ip:allocate | Attach public IP | Normal | PTCV |
network:public-ip:release | Detach public IP | Normal | PTCV |
network:public_ips:view | View public IPs | Baixo | PTCV |
network:subnet:* | All network:subnet:* permissions | Alto | PTCV |
network:subnet:delete | Delete subnet | Alto | PTCV |
network:subnet:manage | Manage subnet | Normal | PTCV |
network:view | View network | Baixo | PTCV |
network:vnet:* | All network:vnet:* permissions | Alto | PTCV |
network:vnet:create | Create VNet | Normal | PTCV |
network:vnet:delete | Delete VNet | Alto | PTCV |
network:vnet:update | Update VNet | Normal | PTCV |
network:vnet:view | View VNet | Baixo | PTCV |
Security
| Permissão | O que faz | Nível | Escopos |
|---|---|---|---|
security:* | All security:* permissions | Alto | PTCV |
security:firewall:* | All security:firewall:* permissions | Alto | PTCV |
security:firewall:delete | Delete firewall rule | Alto | PTCV |
security:firewall:manage | Manage firewall rules | Alto | PTCV |
security:firewall:view | View firewall | Baixo | PTCV |
security:perimeter:* | All security:perimeter:* permissions | Alto | PTCV |
security:perimeter:delete | Delete perimeter policy | Alto | PTCV |
security:perimeter:manage | Manage perimeter policies | Alto | PTCV |
security:perimeter:view | View perimeter policy | Baixo | PTCV |
security:view | View security section | Baixo | PTCV |
Customer Connect
| Permissão | O que faz | Nível | Escopos |
|---|---|---|---|
customer-connect:* | All customer-connect:* permissions | Alto | PTCV |
customer-connect:direct_connect:* | All customer-connect:direct_connect:* permissions | Alto | PTCV |
customer-connect:direct_connect:delete | Delete Direct Connect | Alto | PTCV |
customer-connect:direct_connect:manage | Manage Direct Connect | Alto | PTCV |
customer-connect:direct_connect:view | View Direct Connect | Baixo | PTCV |
customer-connect:ipsec:* | All customer-connect:ipsec:* permissions | Alto | PTCV |
customer-connect:ipsec:connect | Connect/disconnect IPSec VPN | Normal | PTCV |
customer-connect:ipsec:create | Create IPSec VPN | Alto | PTCV |
customer-connect:ipsec:delete | Delete IPSec VPN | Alto | PTCV |
customer-connect:ipsec:view | View IPsec | Baixo | PTCV |
customer-connect:openvpn:view | View OpenVPN server | Baixo | PTCV |
customer-connect:view | View customer connect section | Baixo | PTCV |
customer-connect:vpn:* | All customer-connect:vpn:* permissions | Alto | PTCV |
customer-connect:vpn:create | Create OpenVPN server | Alto | PTCV |
customer-connect:vpn:delete | Delete OpenVPN server | Alto | PTCV |
customer-connect:vpn:power | Power OpenVPN server | Normal | PTCV |
customer-connect:vpn:route:add | Add VPN route | Normal | PTCV |
customer-connect:vpn:route:remove | Remove VPN route | Normal | PTCV |
customer-connect:vpn:update | Update OpenVPN server | Alto | PTCV |
customer-connect:vpn:user:create | Create VPN user | Normal | PTCV |
customer-connect:vpn:user:delete | Delete VPN user | Normal | PTCV |
customer-connect:vpn:user:disconnect | Disconnect VPN user | Normal | PTCV |
customer-connect:vpn:user:update | Update VPN user | Normal | PTCV |
Backup
| Permissão | O que faz | Nível | Escopos |
|---|---|---|---|
backup:* | All backup:* permissions | Alto | PTCV |
backup:backup_jobs:view | View backup jobs | Baixo | PTCV |
backup:backups:view | View backups | Baixo | PTCV |
backup:create | Create backup | Normal | PTCV |
backup:delete | Delete backup | Crítico | PTCV |
backup:job:* | All backup:job:* permissions | Alto | PTCV |
backup:job:delete | Delete backup job | Alto | PTCV |
backup:job:manage | Manage backup job | Normal | PTCV |
backup:restore | Restore backup | Alto | PTCV |
backup:view | View backup | Baixo | PTCV |
Virtual router
| Permissão | O que faz | Nível | Escopos |
|---|---|---|---|
vrouter:* | All vrouter:* permissions | Alto | PT |
vrouter:resolve | Resolve VRouter executions | Alto | PT |
vrouter:update | Update VRouters | Normal | PT |
vrouter:view | View VRouter releases | Baixo | PT |
Support
| Permissão | O que faz | Nível | Escopos |
|---|---|---|---|
support:* | All support:* permissions | Alto | P |
support:act-as-user | Impersonate user | Crítico | P |
support:view-all-vdcs | View all VDCs as NOC | Alto | P |