Role Permissions
Roles can be used for fairly coarse-grained permissions control. They grant service-level permissions based on user responsibilities. GES does not support custom roles. The following system roles are available.
|
Role Name |
Description |
|---|---|
|
Tenant Guest |
Regular tenant users
|
|
GES Administrator |
GES administrator
|
|
GES Manager |
GES manager
|
|
GES Operator |
Regular GES users
NOTE:
|
|
Operation |
GES Administrator |
GES Manager |
GES Operator |
Tenant Guest |
|---|---|---|---|---|
|
Creating graphs |
Yes |
No |
No |
No |
|
Deleting graphs |
Yes |
No |
No |
No |
|
Querying graphs |
Yes |
Yes |
Yes |
Yes |
|
Accessing graphs |
Yes |
Yes |
Yes |
No |
|
Importing data |
Yes |
Yes |
No |
No |
|
Creating metadata |
Yes |
Yes |
No |
No |
|
Viewing metadata |
Yes |
Yes |
Yes |
Yes |
|
Copying metadata |
Yes |
Yes |
No |
No |
|
Editing metadata |
Yes |
Yes |
No |
No |
|
Deleting metadata |
Yes |
Yes |
No |
No |
|
Clearing data |
Yes |
Yes |
No |
No |
|
Backing up graphs |
Yes |
Yes |
No |
No |
|
Restoring graphs from backups |
Yes |
Yes |
No |
No |
|
Deleting backups |
Yes |
Yes |
No |
No |
|
Querying backups |
Yes |
Yes |
Yes |
Yes |
|
Starting graphs |
Yes |
Yes |
No |
No |
|
Stopping graphs |
Yes |
Yes |
No |
No |
|
Upgrading graphs |
Yes |
Yes |
No |
No |
|
Exporting graphs |
Yes |
Yes |
No |
No |
|
Viewing results in the task center |
Yes |
Yes |
Yes |
Yes |
|
Resizing a graph |
√ |
No |
No |
× |
|
Expanding a graph |
√ |
No |
No |
× |
|
Restarting a graph |
√ |
Yes |
No |
× |
|
Configuring fine-grained permissions |
√ |
Yes |
No |
× |
|
Configuring user groups |
√ |
Yes |
No |
× |
|
Importing IAM users |
√ |
Yes |
No |
× |
|
Viewing user details |
√ |
Yes |
Yes |
√ |
|
GES Operation |
Dependent OBS Permission |
|---|---|
|
Viewing metadata |
OBS Viewer policy or OBS Buckets Viewer role |
|
Creating, importing, copying, editing, and deleting metadata |
OBS Operator policy or Tenant Administrator role |
|
Creating, importing, and exporting graphs |
OBS Operator policy or Tenant Administrator role |
|
GES Operation |
Dependent IAM Permission |
|---|---|
|
Importing IAM users |
iam:users:listUsers (custom policy), IAM ReadOnlyAccess (system policy), or Server Administrator role |
|
Creating or editing a user group |
iam:users:listUsers (custom policy), IAM ReadOnlyAccess (system policy), or Server Administrator role |
Feedback
Was this page helpful?
Provide feedbackThank you very much for your feedback. We will continue working to improve the documentation.