Managing identity and access management (IAM) for IBM® Power® Virtual Servers
IBM Power Virtual Server located in IBM data centers: Off-premises
IBM Power Virtual Server Private Cloud: On-premises
IAM enables you to securely authenticate users, control access to Power® Virtual Server resources with resource groups, and allow access to specific resources for a set of users with access groups. IAM is your one-stop shop for all user and resource management in the IBM Cloud.
On-premises To display the Infrastructure capacity navigation menu for the IBM Power Virtual Server (On-premises) when you use a custom role with the power-iaas.pod-capacity.view
IAM action, ensure that you have a Viewer
role that is assigned in the IAM Access Management service.
For more information about IAM, review the following information:
Platform access roles
You can use platform access roles to enable users to complete tasks on IBM Cloud resources, such as creating users or adding services.
The following table displays the IAM platform access roles and the corresponding type of control that is allowed by the Power Virtual Server:
Platform access role | Type of access allowed |
---|---|
Viewer | View instances and list instances. |
Operator | View instances and manage aliases, bindings (IBM Power Virtual Server (On-premises) only), and credentials. |
Editor | View instances, list instances, create instances, and delete instances. |
Administrator | View instances, list instances, create instances, delete instances, and assign policies to other users. |
Service access roles
You can use the service access roles to define the actions that the users can perform on Power Virtual Server resources. The following table displays the IAM service access roles and the corresponding actions that a user can complete by using the Power Virtual Server:
Service access role | Description of actions |
---|---|
Reader | View all resources (such as SSH keys, storage volumes, and network settings). You cannot make changes to the resources. |
Manager |
Configure all resources. You can perform the following actions:
|
To see the complete list of actions for each specific role, see the IAM roles and actions page in IBM Cloud documentation.
Resources supported for Power Virtual Server IAM access policies
When you assign access to the Power Virtual Server service, you can scope access to any of the following resources:
- All resources
- Specific resources, which support the following selections:
- Resource group
- Service instance
Although you can select a Resource type from the Attribute type drop-down, it is not supported. Any roles and actions that are assigned to the Resource type are ignored.
Access role requirements for Power Virtual Server
Power Virtual Server requires extra access for features such as Direct Link, Transit Gateway service, and Virtual Private Cloud. You might require these extra access based on your resource requirements. For example, to create a Cloud connection,
you need access
to the Direct Link service.
The following table displays the additional access roles that are required for the corresponding type of services that are allowed by Power Virtual Server:
Additional access role | Resources Attributes |
---|---|
Editor, Manager, Operator, Reader, Viewer | Power Virtual Server service |
Editor, Manager, Operator, Reader, Viewer, VPN Client | VPC Infrastructure Services service |
Editor, Operator, Viewer | Transit Gateway service |
Reader, Viewer | All resources in account (Including future IAM enabled services) |
Editor, Operator, Viewer | Direct Link service |
Viewer | All resource group |
Viewer | Satellite service On-premises |
User access scenarios
For more information about managing and assigning access by using IAM policies, see Managing access to resources.