Role
The user can create a role with separate permissions and switch from their own account to another role to access the Account.
Creating a role
To create a role, follow the following procedure.
- All services > Management > IAM menu is clicked. It moves to the Service Home page of Identity and Access Management(IAM).
- Service Home page, click the role menu. It moves to the role list page.
- Role List page, click the Create Role button. It moves to the Create Role page.
- Role Creation page where you enter information for role creation, click the Complete button.
- Basic Information Input를 입력하세요.
Classification NecessityDetailed Description Role Name Required Enter the name of the role - Use English letters, numbers, and special characters (
+=-_@,.) to enter within 64 characters
Description Selection Enter a description of the role within 1,000 characters Maximum session persistence time Required Enter the session time allowed for the user when switching roles in the console - Time selection: 1 hour, 2 hours, 4 hours, 8 hours, 12 hours
- Job input: Input possible in seconds from 3,200 seconds (1 hour) to 43,200 seconds (12 hours)
Table. Basic Information Items for Role Creation - Use English letters, numbers, and special characters (
- Execution Entity를 연결하세요.
Classification MandatoryDetailed Description Classification Essential Select the performing entity - Current Account, Different Account, User SRN, Credential Provider, Service
Value Required Enter the Value value for the performing entity - Current Account: Display the current Account ID
- Different Account: Enter the Account ID to use this role
- User SRN: Enter the SRN of the user registered in the Console
- Credential Provider: Select the credential provider name
- Service: Select Virtual Server or Cloud Functions
Add Select A button to add the performing entity - Up to 20 additional connections are possible
Table. Role Creation Performing Subject Connection Items - Policy을 연결하세요 -> * Connect the policy.
Classification MandatoryDetailed Description Policy Required Select a policy to link to the role - If you select the check box, the selected policy name will be displayed at the top of the list
- You can cancel the policy by clicking the X button for the added policy name at the top of the list or by unchecking the check box in the policy list
- If there is no policy to link, you can click the Create Policy item at the bottom of the policy list to register a new policy first
- After policy creation is complete, you can refresh the policy list and select the created policy
- For more information on policy creation, see Create Policy
Table. Role Creation Policy Link Items - Additional information를 입력하세요.
Classification MandatoryDetailed Description Tag Selection Tags to add to the role - Up to 50 tags can be added per resource
Table. Role Creation Additional Information Items
- When the popup window notifying role creation opens, click the Confirm button.
Check detailed role information
Role List page where you can check and modify the detailed information of the selected role.
To check the detailed information of the role, follow the next procedure.
- All services > Management > IAM menu, click. It moves to the Service Home page of Identity and Access Management(IAM).
- Service Home page, click the role menu. It moves to the role list page.
- Role List page, click the identity provider to verify. It moves to the Identity Provider Details page.
- Role Details page displays basic information, and consists of Basic Information, Performing Entity, Policy, Tag tabs.
Basic Information
You can check and modify the basic information of the role.
| Classification | Detailed Description |
|---|---|
| Service | Service Name |
| Resource Type | Resource Type |
| SRN | Unique resource ID in Samsung Cloud Platform |
| Resource Name | Resource Name
|
| Resource ID | Unique Resource ID |
| Creator | The user who created the service |
| Creation Time | The time when the service was created |
| Modifier | User who modified the service information |
| Revision Time | The time when service information was revised |
| Role Name | Role’s Name |
| Description | Description of the role proof provider
|
| Maximum session duration | The role session duration allowed for an IAM user switching roles in the Console
|
Performing Entity
You can confirm and manage the subject of role performance.
| Classification | Detailed Description |
|---|---|
| Division | Name of the executing entity |
| Value | Value of the performing entity |
| Modify Executor | Modify the executor button
|
Policy
| Classification | Detailed Description |
|---|---|
| Disconnect | Disconnects the selected policy from the role
|
| Policy Connection | Connect a new policy to the role
|
| Policy Name | Policy’s Name
|
| Type | Type of Policy |
| Description | Description of the policy |
| Modification Time | The time when the policy was last modified |
Tag
You can check, add, change, or delete the tag information of the credential provider.
| Classification | Detailed Description |
|---|---|
| Tag List | Tag list
|
Managing Roles
You can change the basic information of the role, or modify or delete the performing entity, connected policies, or tag information of the role.
Modify basic information
You can modify the maximum session persistence time and description in the role details. To modify the basic information, follow the following procedure.
- All services > Management > IAM menu is clicked. It moves to the Service Home page of Identity and Access Management(IAM).
- Service Home page, click the role menu. It moves to the role list page.
- Role List page, click the user role name to modify the basic information. It moves to the Role Details page.
- Role Details page, check the basic information to be modified, and then click the Modify button.
- Maximum session duration: You can set the role session duration allowed for an IAM user switching roles in the Console. When you click the Edit button, the Edit maximum session duration popup window opens.
- Description: You can modify the description of the role. When the Modify button is clicked, the Description Modification popup window opens.
- In the popup window, modify it to the content to be changed, then click the confirm button.
Managing the Performing Entity
You can add, modify, or delete the subject of the role’s performance.
To manage the performing subject of a role, follow the following procedure.
- All services > Management > IAM menu, click. It moves to the Service Home page of Identity and Access Management(IAM).
- Service Home page, click the role menu. It moves to the role list page.
- Role List page, click the user name to modify the performing subject. It moves to the Role Details page.
- Role Details page, click the Performing Entity tab. It moves to the Performing Entity tab.
- Execution Entity tab, click the Modify Execution Entity button. It moves to the Modify Execution Entity page.
- Modify the performing entity page, modify the performing entity, and then click the Complete button. A pop-up window announcing the modification of the performing entity will open.
| Classification | Mandatory | Detailed Description |
|---|---|---|
| Classification | Essential | Select the performing entity
|
| Value | Required | Enter the Value value for the performing entity
|
| Add | Select | Button to add the performing entity
|
- Click the Confirm button in the pop-up window notifying the modification of the performing entity. You can check the modified performing entity in the list of the Performing Entity tab.
Managing Policies
You can link policies to roles or unlink linked policies.
Connect Policy
You can link policies to a role.
To link a policy to a role, follow these procedures.
All services > Management > IAM menu, click. It moves to the Service Home page of Identity and Access Management(IAM).
Service Home page, click the role menu. It moves to the role list page.
Role List page, click the role name to link the policy. It moves to the User Detail page.
Role Details page, click the Policy tab. It moves to the Policy tab.
Policy tab, click the Policy Link button. It moves to the Policy Link page.
After selecting the policy to be linked to the role, click the Complete button. A popup window announcing the policy connection will open.
Classification Detailed Description Connected Policy Displays the policy connected to the role Policy Select a policy to be linked to the role from the list of policies registered in the Account - When you select a check box, the selected policy name is displayed at the top of the list
- The selected policy can be canceled by clicking the X button at the top of the list or by unchecking the check box in the policy list
- If there are no policies to link, click the Create Policy item at the bottom of the policy list to register a new policy first
- After policy creation is complete, you can refresh the policy list and select the created policy
- For more information on policy creation, see Create Policy
Table. Policy Link DetailsClick the Confirm button in the pop-up window notifying policy connection. You can check the connected policy in the list of the Policy tab.
Policy Disconnecting
You can release the policies connected to the user.
To release the policy linked to the user, follow the following procedure.
- All services > Management > IAM menu, click. It moves to the Service Home page of Identity and Access Management(IAM).
- Service Home page, click the role menu. It moves to the role list page.
- Role List page, click the role name to disconnect the policy link. It moves to the Role Details page.
- Role Details page, click the Policy tab. It moves to the Policy tab.
- Policy list, select the policy to disconnect, then click the Disconnect button. A pop-up window notifying disconnection will open.
- After checking the policy information to be disconnected, click the Confirm button. The policy will be disconnected.
Managing tags
You can add, modify, or delete the role’s tag.
To manage the role’s tags, follow the following procedure.
- All services > Management > IAM menu, click. It moves to the Service Home page of Identity and Access Management(IAM).
- Service Home page, click the Role menu. It moves to the Role List page.
- Role List page, click the role name to modify the tag information. It moves to the Role Details page.
- Role Details page, click the Tags tab. It moves to the Tags tab.
- Tag tab, click the Edit Tag button.
- After adding or modifying the tag, click the Save button. A popup window announcing the tag modification will open.
- You can modify the Key, Value of the previously registered tag.
- Add tag button to click and add a new tag.
- Clicking the X button in front of the added tag will delete the tag.
- Confirm button, you can check the modified tag information in the list.
Switching roles
To switch roles in the Samsung Cloud Platform Console, follow the following procedure.
Click the profile-shaped button at the top right of the Console. My menu popup window will open.
My menu popup window, click the role switch button. Role switch popup window opens.
Role Switching In the role switching popup window, enter the role switching information and click the Confirm button.
Classification MandatoryDetailed Description Account ID required Enter the Account ID that the user wants to enter with role switching Role Name Mandatory Enter the role name that the user wants to enter through role switching Alias Select Name to be used when the user enters with role switching Color Required Select a color to use as the background of the Account when entering the role - Not selected: Apply the existing Account background color
Table. Role Transition Information ItemsWhen the popup window notifying role switching opens, click the Confirm button.
Check the role
Console you can check the role information switched by clicking the profile-shaped button at the top right of the console.
| Provided Function | Description |
|---|---|
| Account ID | Account ID logged in to Samsung Cloud Platform Console |
| Role Name | Alias set when switching roles
|
| Time Zone | Time zone set by the user
|
| Account | Account information
|
| Cost Management | You can check the usage and billing details, payment history, and cost analysis, and manage Credits, budgets, Accounts, and payment methods
|
| Login user information | Role switched IAM user name and user’s Account ID |
| Switch to my account | Switch to the IAM user account and move to the Console Home page
|
| Role Switching | Can be switched to another role
|
| Log out | Log out from Samsung Cloud Platform Console |
Delete role
To delete a role, follow the following procedure.
- All services > Management > IAM menu is clicked. It moves to the Service Home page of Identity and Access Management(IAM).
- Service Home page, click the role menu. It moves to the role list page.
- Role List page, click the role name to be deleted. It moves to the Role Details page.
- Role Details page, click the Delete Role button.
- The role is deleted, and it moves to the role list page.
To delete multiple roles at the same time, follow the procedure below.
- All services > Management > IAM menu, click. It moves to the Service Home page of Identity and Access Management(IAM).
- Service Home page, click the role menu. It moves to the role list page.
- Check the role to be deleted from the role list.
- Confirm the selected role, and click the role deletion button.
- The selected role is deleted and the role list page is newly retrieved.