Configure IAM
Access to FPT Database Engine is granted through IAM in two steps: a role bundles a set of permissions, and a user group ties users to roles. Define the roles first, then the groups that carry them, since granting access by group rather than user by user cuts the administrative work and keeps permissions consistent.
Roles and user groups behave the same way across every FPT Cloud service, so the screens and fields are documented once in the IAM section. This page covers only what is specific to FPT Database Engine: the service types to choose from, the permissions available, and the one permission that behaves in reverse.
Where the IAM mechanics are documented
| To do this | See |
|---|---|
| Understand how users, groups, roles, and permission templates fit together | IAM overview |
| Create, edit, or delete a role, field by field | Managing roles |
| Create or delete a user group and assign roles to it | Managing user groups |
| Save a permission set for reuse across several roles | Managing permission templates |
| Look up any field or column on an IAM screen | IAM field and column reference |
Give a role only what its work requires. Someone who reads database logs does not also need permission to change cluster configuration or delete a database.
Service types for FPT Database Engine
When you add a permission to a role, Service Type selects which family of operations that permission covers. FPT Database Engine uses two:
| Service type | What it covers |
|---|---|
| ManageDatabase | Standard database management: viewing information, provisioning, operating databases, and managing add-on services. |
| FDE | Sensitive database operations, such as viewing or managing the password of the database administrator account. |
Choosing a service type populates the Action list with the operations available for it, and updates the permission name to match. Actions you leave unselected are blocked.
The permission that works in reverse
Every permission in the list below grants what you select against it. One does the opposite.
FDE:hide_admin_password inverts the resource selectionScope this permission to Specific, and the databases you select are the ones where viewing the administrator password is blocked. Any database you do not select still allows it.
Permission reference
Every operation on FPT Database Engine is gated by a permission. If a role does not carry the permission for an action, that action is unavailable to everyone holding the role, so build roles from this list rather than granting broadly and trimming later.
| Permission | Group | Action type | What it allows |
|---|---|---|---|
manageDatabase:ProvisionBackend | Service | Create | Activate FPT Database Engine in a VPC. |
manageDatabase:DeactiveBackend | Service | Delete | Deactivate FPT Database Engine in a VPC. |
manageDatabase:List | Database | View | View the database list. |
manageDatabase:Create | Database | Create | Create a database. |
manageDatabase:View | Database | View | View the details of a database cluster. |
manageDatabase:Management | Database | Edit | Start, stop, and restart a database. |
manageDatabase:UpdateResource | Database | Edit | Update cluster resources such as CPU, RAM, and storage. |
manageDatabase:Configuration | Database | Edit | Change database configuration, including parameters and scaling settings. |
FDE:hide_admin_password | Database | View | Block viewing of the cluster's administrator password. |
manageDatabase:Delete | Database | Delete | Delete a database. |
manageDatabase:ListBackup | Backup & Restore | View | View backup information for a database. |
manageDatabase:EnableBackup | Backup & Restore | Create | Enable the backup service on a cluster. |
manageDatabase:DeleteBackup | Backup & Restore | Edit | Disable the backup service on a cluster. |
manageDatabase:CreateJobBackup | Backup & Restore | Create | Create a backup job for a cluster. |
manageDatabase:ViewJobBackup | Backup & Restore | View | View the details of a backup job. |
manageDatabase:RunNowJobBackup | Backup & Restore | Create | Take a manual backup snapshot of a cluster. |
manageDatabase:EditJobBackup | Backup & Restore | Edit | Edit a backup job. |
manageDatabase:DeleteJobBackup | Backup & Restore | Delete | Delete a backup job. |
manageDatabase:ListRestore | Backup & Restore | View | View the backups available to restore from. |
manageDatabase:Restore | Backup & Restore | Create | Restore a database from a backup or to a point in time. |
manageDatabase:ListProxy | DB Proxy | View | View the DB Proxy list for a database. |
manageDatabase:CreateProxy | DB Proxy | Create | Create a DB Proxy for a cluster. |
manageDatabase:DeleteProxy | DB Proxy | Delete | Delete a DB Proxy from a cluster. |
manageDatabase:ListNotification | Notification | View | View the notification settings of a cluster. |
manageDatabase:CreateNotification | Notification | Create | Enable system notifications for a cluster. |
manageDatabase:DeleteNotification | Notification | Delete | Disable system notifications for a cluster. |
manageDatabase:Monitor | Monitoring | View | Monitor database performance and status. |
manageDatabase:ReportConfig | Reporting | Edit | Configure the schedule for database activity reports. |
FDE:hide_admin_password is the one entry that restricts rather than grants. See The permission that works in reverse for how its Specific resource selection inverts.
Before you delete a role or user group
Deleting a role or a group revokes its permissions immediately from everyone holding it, which can interrupt database management and operations in progress. Before deleting anything that carries FPT Database Engine permissions, confirm that:
- It is no longer used for database operational or administrative tasks.
- Its users have been moved to another group, or granted an alternative role, if they still need access.
- No database operational processes, automations, or workflows depend on its permissions.
Next steps
- Activate FPT Database Engine service, which needs a high-privilege role of its own
- Create your first database once your team has the access it needs