Skip to main content

Configure IAM

Access to FPT Database Engine is granted through IAM in two steps: a role bundles a set of permissions, and a user group ties users to roles. Define the roles first, then the groups that carry them, since granting access by group rather than user by user cuts the administrative work and keeps permissions consistent.

Roles and user groups behave the same way across every FPT Cloud service, so the screens and fields are documented once in the IAM section. This page covers only what is specific to FPT Database Engine: the service types to choose from, the permissions available, and the one permission that behaves in reverse.

Where the IAM mechanics are documented​

To do thisSee
Understand how users, groups, roles, and permission templates fit togetherIAM overview
Create, edit, or delete a role, field by fieldManaging roles
Create or delete a user group and assign roles to itManaging user groups
Save a permission set for reuse across several rolesManaging permission templates
Look up any field or column on an IAM screenIAM field and column reference
Grant the least privilege that works

Give a role only what its work requires. Someone who reads database logs does not also need permission to change cluster configuration or delete a database.

Service types for FPT Database Engine​

When you add a permission to a role, Service Type selects which family of operations that permission covers. FPT Database Engine uses two:

Service typeWhat it covers
ManageDatabaseStandard database management: viewing information, provisioning, operating databases, and managing add-on services.
FDESensitive database operations, such as viewing or managing the password of the database administrator account.

Choosing a service type populates the Action list with the operations available for it, and updates the permission name to match. Actions you leave unselected are blocked.

The permission that works in reverse​

Every permission in the list below grants what you select against it. One does the opposite.

warning
FDE:hide_admin_password inverts the resource selection

Scope this permission to Specific, and the databases you select are the ones where viewing the administrator password is blocked. Any database you do not select still allows it.

Permission reference​

Every operation on FPT Database Engine is gated by a permission. If a role does not carry the permission for an action, that action is unavailable to everyone holding the role, so build roles from this list rather than granting broadly and trimming later.

PermissionGroupAction typeWhat it allows
manageDatabase:ProvisionBackendServiceCreateActivate FPT Database Engine in a VPC.
manageDatabase:DeactiveBackendServiceDeleteDeactivate FPT Database Engine in a VPC.
manageDatabase:ListDatabaseViewView the database list.
manageDatabase:CreateDatabaseCreateCreate a database.
manageDatabase:ViewDatabaseViewView the details of a database cluster.
manageDatabase:ManagementDatabaseEditStart, stop, and restart a database.
manageDatabase:UpdateResourceDatabaseEditUpdate cluster resources such as CPU, RAM, and storage.
manageDatabase:ConfigurationDatabaseEditChange database configuration, including parameters and scaling settings.
FDE:hide_admin_passwordDatabaseViewBlock viewing of the cluster's administrator password.
manageDatabase:DeleteDatabaseDeleteDelete a database.
manageDatabase:ListBackupBackup & RestoreViewView backup information for a database.
manageDatabase:EnableBackupBackup & RestoreCreateEnable the backup service on a cluster.
manageDatabase:DeleteBackupBackup & RestoreEditDisable the backup service on a cluster.
manageDatabase:CreateJobBackupBackup & RestoreCreateCreate a backup job for a cluster.
manageDatabase:ViewJobBackupBackup & RestoreViewView the details of a backup job.
manageDatabase:RunNowJobBackupBackup & RestoreCreateTake a manual backup snapshot of a cluster.
manageDatabase:EditJobBackupBackup & RestoreEditEdit a backup job.
manageDatabase:DeleteJobBackupBackup & RestoreDeleteDelete a backup job.
manageDatabase:ListRestoreBackup & RestoreViewView the backups available to restore from.
manageDatabase:RestoreBackup & RestoreCreateRestore a database from a backup or to a point in time.
manageDatabase:ListProxyDB ProxyViewView the DB Proxy list for a database.
manageDatabase:CreateProxyDB ProxyCreateCreate a DB Proxy for a cluster.
manageDatabase:DeleteProxyDB ProxyDeleteDelete a DB Proxy from a cluster.
manageDatabase:ListNotificationNotificationViewView the notification settings of a cluster.
manageDatabase:CreateNotificationNotificationCreateEnable system notifications for a cluster.
manageDatabase:DeleteNotificationNotificationDeleteDisable system notifications for a cluster.
manageDatabase:MonitorMonitoringViewMonitor database performance and status.
manageDatabase:ReportConfigReportingEditConfigure the schedule for database activity reports.
note

FDE:hide_admin_password is the one entry that restricts rather than grants. See The permission that works in reverse for how its Specific resource selection inverts.

Before you delete a role or user group​

Deleting a role or a group revokes its permissions immediately from everyone holding it, which can interrupt database management and operations in progress. Before deleting anything that carries FPT Database Engine permissions, confirm that:

  • It is no longer used for database operational or administrative tasks.
  • Its users have been moved to another group, or granted an alternative role, if they still need access.
  • No database operational processes, automations, or workflows depend on its permissions.

Next steps​