Role Permissions
Roles can be used for fairly coarse-grained permissions control. They grant service-level permissions based on user responsibilities. GES does not support custom roles. The following system roles are available.
Role Name |
Description |
---|---|
Tenant Guest |
Regular tenant users
|
GES Administrator |
GES administrator
|
GES Manager |
GES manager
|
GES Operator |
Regular GES users
NOTE:
|
Operation |
GES Administrator |
GES Manager |
GES Operator |
Tenant Guest |
---|---|---|---|---|
Creating graphs |
Yes |
No |
No |
No |
Deleting graphs |
Yes |
No |
No |
No |
Querying graphs |
Yes |
Yes |
Yes |
Yes |
Accessing graphs |
Yes |
Yes |
Yes |
No |
Importing data |
Yes |
Yes |
No |
No |
Creating metadata |
Yes |
Yes |
No |
No |
Viewing metadata |
Yes |
Yes |
Yes |
Yes |
Copying metadata |
Yes |
Yes |
No |
No |
Editing metadata |
Yes |
Yes |
No |
No |
Deleting metadata |
Yes |
Yes |
No |
No |
Clearing data |
Yes |
Yes |
No |
No |
Backing up graphs |
Yes |
Yes |
No |
No |
Restoring graphs from backups |
Yes |
Yes |
No |
No |
Deleting backups |
Yes |
Yes |
No |
No |
Querying backups |
Yes |
Yes |
Yes |
Yes |
Starting graphs |
Yes |
Yes |
No |
No |
Stopping graphs |
Yes |
Yes |
No |
No |
Upgrading graphs |
Yes |
Yes |
No |
No |
Exporting graphs |
Yes |
Yes |
No |
No |
Viewing results in the task center |
Yes |
Yes |
Yes |
Yes |
Resizing a graph |
√ |
No |
No |
× |
Expanding a graph |
√ |
No |
No |
× |
Restarting a graph |
√ |
Yes |
No |
× |
Configuring fine-grained permissions |
√ |
Yes |
No |
× |
Configuring user groups |
√ |
Yes |
No |
× |
Importing IAM users |
√ |
Yes |
No |
× |
Viewing user details |
√ |
Yes |
Yes |
√ |
GES Operation |
Dependent OBS Permission |
---|---|
Viewing metadata |
OBS Viewer policy or OBS Buckets Viewer role |
Creating, importing, copying, editing, and deleting metadata |
OBS Operator policy or Tenant Administrator role |
Creating, importing, and exporting graphs |
OBS Operator policy or Tenant Administrator role |
GES Operation |
Dependent IAM Permission |
---|---|
Importing IAM users |
iam:users:listUsers (custom policy), IAM ReadOnlyAccess (system policy), or Server Administrator role |
Creating or editing a user group |
iam:users:listUsers (custom policy), IAM ReadOnlyAccess (system policy), or Server Administrator role |
Feedback
Was this page helpful?
Provide feedbackThank you very much for your feedback. We will continue working to improve the documentation.