RDS System Permissions

By default, new IAM users do not have permissions assigned. You need to add a user to one or more groups, and attach permissions policies or roles to these groups. Users inherit permissions from the groups to which they are added and can perform specified operations on cloud services based on the permissions. For details about RDS system permissions, see Table 1.

Table 1 RDS system policies and permissions

Policy Name/System Role

Scope

Permission Description

Permission Type

Dependency

RDS FullAccess

Region-specific projects

Full permissions for RDS

Policy

None

RDS ReadOnlyAccess

Read-only permissions for RDS

None

RDS ManageAccess

Database administrator permissions for all operations except deleting RDS resources

None

RDS Administrator

Full permissions for RDS

Role

This role must be used together with the Tenant Guest and Server Administrator roles in the same project.