IBM Cloud Docs
Managing identity and access management (IAM) for IBM® Power® Virtual Servers

Managing identity and access management (IAM) for IBM® Power® Virtual Servers


IBM Power Virtual Server located in IBM data centers: Off-premises

IBM Power Virtual Server Private Cloud: On-premises


IAM enables you to securely authenticate users, control access to Power® Virtual Server resources with resource groups, and allow access to specific resources for a set of users with access groups. IAM is your one-stop shop for all user and resource management in the IBM Cloud.

On-premises To display the Infrastructure capacity navigation menu for the IBM Power Virtual Server (On-premises) when you use a custom role with the power-iaas.pod-capacity.view IAM action, ensure that you have a Viewer role that is assigned in the IAM Access Management service.

For more information about IAM, review the following information:

Platform access roles

You can use platform access roles to enable users to complete tasks on IBM Cloud resources, such as creating users or adding services.

The following table displays the IAM platform access roles and the corresponding type of control that is allowed by the Power Virtual Server:

IAM platform access roles
Platform access role Type of access allowed
Viewer View instances and list instances.
Operator View instances and manage aliases, bindings (IBM Power Virtual Server (On-premises) only), and credentials.
Editor View instances, list instances, create instances, and delete instances.
Administrator View instances, list instances, create instances, delete instances, and assign policies to other users.

Service access roles

You can use the service access roles to define the actions that the users can perform on Power Virtual Server resources. The following table displays the IAM service access roles and the corresponding actions that a user can complete by using the Power Virtual Server:

IAM service access roles
Service access role Description of actions
Reader View all resources (such as SSH keys, storage volumes, and network settings). You cannot make changes to the resources.
Manager

Configure all resources. You can perform the following actions:

  • Create instances
  • Increase storage volume sizes
  • Create SSH keys
  • Modify network settings
  • Create boot images
  • Delete storage volumes

To see the complete list of actions for each specific role, see the IAM roles and actions page in IBM Cloud documentation.

Resources supported for Power Virtual Server IAM access policies

When you assign access to the Power Virtual Server service, you can scope access to any of the following resources:

  • All resources
  • Specific resources, which support the following selections:
    • Resource group
    • Service instance

Although you can select a Resource type from the Attribute type drop-down, it is not supported. Any roles and actions that are assigned to the Resource type are ignored.

Access role requirements for Power Virtual Server

Power Virtual Server requires extra access for features such as Direct Link, Transit Gateway service, and Virtual Private Cloud. You might require these extra access based on your resource requirements. For example, to create a Cloud connection, you need accessto the Direct Link service.

The following table displays the additional access roles that are required for the corresponding type of services that are allowed by Power Virtual Server:

Additional access roles
Additional access role Resources Attributes
Editor, Manager, Operator, Reader, Viewer Power Virtual Server service
Editor, Manager, Operator, Reader, Viewer, VPN Client VPC Infrastructure Services service
Editor, Operator, Viewer Transit Gateway service
Reader, Viewer All resources in account (Including future IAM enabled services)
Editor, Operator, Viewer Direct Link service
Viewer All resource group
Viewer Satellite service On-premises

User access scenarios

For more information about managing and assigning access by using IAM policies, see Managing access to resources.