Permissions Reference On this page This page lists all IAM permissions available in Excloud and the service area they belong to. Wildcards such as * indicate all actions within a service or subgroup.
For how permissions are evaluated inside policies, see Policies .
Legend:
Enforced today: whether the backend currently checks this action in handlers. Wildcards like service:* match all actions within that service. Billing# Permission Enforced today Notes billing:caYes Cost Explorer
Compute# Permission Enforced today Notes compute:*Yes Wildcard for all compute actions compute:instance:*Yes Wildcard for all instance actions compute:instance:connectYes Ephemeral terminal access compute:instance:createYes compute:instance:listYes compute:instance:restartYes compute:instance:startYes compute:instance:stopYes compute:instance:terminateYes compute:securitygroup:*Yes Includes bindings and rules compute:securitygroup:binding:createYes compute:securitygroup:binding:deleteYes compute:securitygroup:binding:listYes compute:securitygroup:createYes compute:securitygroup:deleteYes compute:securitygroup:listYes compute:securitygroup:rule:createYes compute:securitygroup:rule:deleteYes compute:securitygroup:rule:listYes compute:snapshot:createYes compute:snapshot:deleteYes compute:snapshot:listYes compute:sshpubkey:*Yes Wildcard for all SSH key actions compute:sshpubkey:createYes compute:sshpubkey:deleteYes compute:sshpubkey:listYes compute:subnet:*Yes Matches list (no create today) compute:subnet:listYes compute:volume:createYes compute:volume:deleteYes compute:volume:listYes compute:volume:resizeYes
DNS# Permission Enforced today Notes dns:*Yes Wildcard for all DNS actions dns:record:*Yes Wildcard for all record actions dns:record:createYes dns:record:deleteYes dns:record:listYes dns:record:updateYes dns:zone:*Yes Wildcard for all zone actions dns:zone:createYes dns:zone:deleteYes dns:zone:listYes
Database# Permission Enforced today Notes database:*Yes Wildcard for all database actions database:cluster:*Yes Wildcard for all cluster actions database:cluster:createYes database:cluster:listYes database:cluster:resetpasswordYes database:cluster:restartYes database:cluster:terminateYes database:node:addYes database:node:restartYes database:node:terminateYes
IAM# Permission Enforced today Notes iam:*Yes Wildcard for all IAM actions iam:account:*Yes Wildcard for account actions iam:account:inviteYes iam:account:listYes iam:billing:getYes iam:billing:updateYes iam:org:renameYes iam:policy:*Yes Wildcard for all policy actions iam:policy:binding:createYes iam:policy:binding:deleteYes iam:policy:binding:listYes iam:policy:createYes iam:policy:deleteYes iam:policy:listYes iam:policy:updateYes iam:serviceaccount:*Yes Wildcard for all service account actions iam:serviceaccount:createYes iam:serviceaccount:deleteYes iam:serviceaccount:listYes iam:serviceaccount:updateYes