Permissions
The actions that govern storage accounts, buckets, access keys and temporary credentials, and the roles that hold them.
These actions govern what people and service accounts may do with storage accounts on the platform — in the portal and through the platform's API. They do not limit S3 requests: any valid temporary credential has full access to its account's buckets and objects, and any valid access key to those of every storage account in its boundary — see What a key can do.
Actions
| Action | Allows |
|---|---|
s3storageaccounts/read |
See storage accounts, their configuration and usage |
s3storageaccounts/write |
Create storage accounts and change their settings. Includes s3storageaccounts/delete |
s3storageaccounts/delete |
Delete storage accounts |
s3storageaccounts/admin |
Not checked by anything today; the Advanced settings are saved with s3storageaccounts/write |
s3buckets/read |
See buckets |
s3buckets/write |
Create buckets. Includes s3buckets/delete |
s3buckets/delete |
Delete buckets |
s3accesskeys/read |
See access keys, never their secrets |
s3accesskeys/write |
Issue access keys and disable them. Includes s3accesskeys/delete |
s3accesskeys/delete |
Delete access keys |
s3sts/issue |
Get temporary credentials; needed to browse buckets in the portal |
s3/audit/read |
Read the account's audit log |
s3objects/read, s3objects/write, s3objects/delete |
Not applied today: S3 requests are not checked against them |
Roles
| Role | See | Create, change, delete accounts | Buckets | Access keys | Browse buckets | Audit log |
|---|---|---|---|---|---|---|
| Reader | Yes | No | See | See | No | No |
| Storage Reader | Yes | No | See | See | No | No |
| Storage Operator | Yes | Yes | Create, delete | Issue, disable, delete | Yes | No |
| Contributor, Owner | Yes | Yes | Create, delete | Issue, disable, delete | Yes | Yes |
Assign a role on a boundary or a resource group — see
Role assignments. The storage account list under
S3 Storage needs s3storageaccounts/read on the boundary itself; with a role held only in a
resource group, that list does not load.
Warning
Role assignments on a single storage account, made on its Access Control tab, are not applied: the platform's API checks storage account, bucket, access key and temporary-credential requests against the resource group or the boundary, so a role held only on the account grants nothing there. Assignments on a single bucket are not applied either — see Bucket permissions.