IBM Cloud Docs
Roles and permissions for VMware Cloud Director

Roles and permissions for VMware Cloud Director

The following table provides information about the platform management roles and permissions for IBM Cloud® for VMware Cloud Foundation as a Service.

  • Minimum - roles with the bare minimum permissions in VMware Cloud Directorâ„¢.
  • VMware Cloud Director - roles that are provided by VMware Cloud Director. For more information, see Rights in predefined global tenant roles.
  • Custom - roles that are custom-defined by IBM®.
Roles and actions for VCF as a Service
Platform management role Actions Level of permission
Reader Read-only actions to view service-specific resources. Minimum
Writer Create and edit service-specific resources. Minimum
Manager Privileged actions as defined by the service in addition to create and edit service-specific resources. Custom
Viewer Read-only actions to view the summary and details of instances. Minimum
Operator Read-only actions. For example, list instances and view instance details. Minimum
Editor Update a specific instance. For example, add or remove VMware ESXiâ„¢ servers, clusters, and services; upgrade an instance to a higher version. Minimum
Administrator Full management access. For example, create new instances, delete instances, and grant platform access to other users. Custom
VCFaaS Full Viewer All view access to every component in VMware Cloud Director. Custom
VCFaaS vApp Author Use catalogs and create vApps in VMware Cloud Director. VMware Cloud Director
VCFaaS vApp User Use existing vApps in VMware Cloud Director. VMware Cloud Director
VCFaaS Catalog Author Create and publish catalogs in VMware Cloud Director. VMware Cloud Director
VCFaaS Network Admin Create, view, edit, delete the subnet, the static route, and troubleshoot routing in VMware Cloud Director. Custom
VCFaaS Console User View a virtual machine state, properties, and use the guest operating system in VMware Cloud Director. VMware Cloud Director
VCFaaS Backup User Manage Veeam® backup jobs in VMware Cloud Director. Custom
VCFaaS Security Admin View and edit the edge firewall and the distributed firewall in VMware Cloud Director. Custom

Recently introduced rights

Additional rights are available with recent releases. If you use pre-configured Open ID Connect (OIDC) roles or any role other than the Organization Administrator role, you must manually add these rights to your roles.

To update the roles with the new rights, complete the following steps as an IBM Cloud IAM Administrator or as an Organization Administrator.

  1. From the tenant portal, click the Menu icon at the upper left of the page and select Administration.
  2. Under the Access Control section on the left pane, select Roles.
  3. Select the role to change and click Edit. You must use the recommended OIDC roles from the following table, Table 2. Recommended OIDC roles, or use customized roles.
  4. In the Edit Role window, select the new permissions and clear the permissions to remove. You can add the new tenant permissions to the roles as defined in Table 2. Recommended OIDC roles.
  5. Click SAVE to apply the new or removed permissions. You might need to log out and log back into the tenant portal to see the changes.
  6. Repeat for each role that requires the update.

For more information, see Edit a Custom Tenant Role Using Your VMware Cloud Director Tenant Portal.

The permissions that include an asterisk (*) are introduced in VMware Cloud Director 10.6 and are available to users after the Cloud Director site where the virtual data centers are deployed is upgraded to VMware Cloud Director 10.6.0.1. For more information, see IBM Cloud Maintenance notifications for scheduled upgrade dates.

The following table provides the recently introduced rights and the recommended OIDC roles to manually update.

Recommended OIDC roles
Permission Manager Administrator Director Full Viewer Director Network Admin Director Security Admin
IP Spaces: Allocate Available Available Available Available
Organization vDC Gateway: Configure Firewall Available Available Available
Organization vDC Gateway: Configure NAT Available
Organization vDC Gateway: View Available
Organization vDC Network: Manage Manual IP Reservation* Available Available Available Available
Private IP Spaces: Manage Available Available Available Available
Private IP Spaces: View Available Available Available Available Available
Provider Gateway: Simple View Available Available Available Available
Provider Gateway BGP: Simple Manage Available Available Available Available Available
Provider Gateway BGP: Simple View Available Available Available Available Available
Provider Gateway Firewall: Manage Available Available Available Available
Provider Gateway Firewall: View Available Available Available Available Available
Provider Gateway IP Sec VPN: Manage* Available Available Available Available
Provider Gateway IP Sec VPN: View* Available Available Available Available Available
Provider Gateway NAT: Manage Available Available Available Available
Provider Gateway NAT: View Available Available Available Available Available
Provider Gateway Routing: Simple View* Available Available Available Available Available
Provider Network: View Available

Custom-defined roles and permissions

The following table provides information about roles that are custom-defined by IBM.

Custom-defined roles and permissions for VCF as a Service
Permission Manager Administrator Director Full Viewer Director Network Admin Director Security Admin Director Backup User
Access Control List: Manage Available Available Available
Access Control List: View Available Available Available Available Available
Access All Organization VDCs Available Available Available Available Available Available
Alternate Admin Entity: View Available Available Available Available
API Explorer: View Available Available Available Available
API Tokens: Manage Available Available
API Tokens: Manage All Available Available
Catalog: Add vApp from My Cloud Available Available
Catalog: Change Owner Available Available
Catalog: CLSP Publish Subscribe Available Available
Catalog: Create / Delete a Catalog Available Available
Catalog: Edit Properties Available Available
Catalog: Publish Available Available
Catalog: Shadow VM View Available Available Available Available
Catalog: Sharing Available Available
Catalog: VCSP Publish Subscribe Available Available
Catalog: VCSP Publish Subscribe Caching Available Available
Catalog: View ACL Available Available Available
Catalog: View Private and Shared Catalogs Available Available Available Available Available
Catalog: View Published Catalogs Available Available Available Available
Certificate Library: Manage Available Available
Certificate Library: View Available Available Available Available
Custom entity: View all custom entity instances in org Available Available Available Available
Custom entity: View custom entity instance Available Available Available Available
Extension Service API Definition: Manage Available Available
Extension Service API Definition: View Available Available Available
Extension Services: View Available Available Available
Extensions: View Available Available Available
External Service: Manage Available Available
External Service: View Available Available Available
General: Administrator Control Available Available Available
General: Administrator View Available Available Available Available Available Available
General: Send Notification Available Available
General: View Error Details Available Available Available Available Available
Group / User: Manage Available Available
Group / User: View Available Available Available Available Available
Hybrid Cloud Operations: Acquire control ticket Available Available
Hybrid Cloud Operations: Acquire from-the-cloud tunnel ticket Available Available
Hybrid Cloud Operations: Acquire to-the-cloud tunnel ticket Available Available
Hybrid Cloud Operations: Create from-the-cloud tunnel Available Available
Hybrid Cloud Operations: Create to-the-cloud tunnel Available Available
Hybrid Cloud Operations: Delete from-the-cloud tunnel Available Available
Hybrid Cloud Operations: Delete to-the-cloud tunnel Available Available
Hybrid Cloud Operations: Update from-the-cloud tunnel endpoint tag Available Available
IP Spaces: Allocate Available Available Available Available
Localization Resources: Manage Available Available
Metadata File Entry: Create/Modify Available Available
Network Pool: View Available Available Available Available Available
Object Extensions: Manage Available Available
Object Extensions: View Available Available Available
Organization Network: Create or Delete Available Available Available
Organization Network: Edit Properties Available Available Available
Organization Network: View Available Available Available Available Available
Organization vDC Compute Policy: View Available Available Available Available Available Available
Organization vDC Disk: View IOPS Available Available Available Available
Organization vDC Distributed Firewall: Configure Rules Available Available Available
Organization vDC Distributed Firewall: View Rules Available Available Available Available
Organization vDC Gateway: Configure BGP Routing Available Available Available
Organization vDC Gateway: Configure DHCP Available Available Available
Organization vDC Gateway: Configure DNS Available Available Available
Organization vDC Gateway: Configure ECMP Routing Available Available Available
Organization vDC Gateway: Configure Firewall Available Available Available Available
Organization vDC Gateway: Configure IPSec VPN Available Available Available
Organization vDC Gateway: Configure L2 VPN Available Available Available
Organization vDC Gateway: Configure Load Balancer Available Available Available
Organization vDC Gateway: Configure NAT Available Available Available Available
Organization vDC Gateway: Configure OSPF Routing Available Available Available
Organization vDC Gateway: Configure Remote Access Available Available Available
Organization vDC Gateway: Configure Route Advertisement Available Available Available
Organization vDC Gateway: Configure SLAAC Profile Available Available Available
Organization vDC Gateway: Configure SSL VPN Available Available Available
Organization vDC Gateway: Configure Static Routing Available Available Available
Organization vDC Gateway: Configure Syslog Available Available Available
Organization vDC Gateway: Convert to Advanced Networking Available Available Available
Organization vDC Gateway: Distributed Routing Available Available Available
Organization vDC Gateway: View Available Available Available Available Available
Organization vDC Gateway: View BGP Routing Available Available Available Available
Organization vDC Gateway: View DHCP Available Available Available Available Available
Organization vDC Gateway: View DNS Available Available Available Available Available
Organization vDC Gateway: View Firewall Available Available Available Available Available
Organization vDC Gateway: View IPSec VPN Available Available Available Available
Organization vDC Gateway: View L2 VPN Available Available Available Available Available
Organization vDC Gateway: View Load Balancer Available Available Available Available Available
Organization vDC Gateway: View NAT Available Available Available Available Available
Organization vDC Gateway: View OSPF Routing Available Available Available Available Available
Organization vDC Gateway: View Remote Access Available Available Available Available
Organization vDC Gateway: View Route Advertisement Available Available Available Available Available
Organization vDC Gateway: View SLAAC Profile Available Available Available Available Available
Organization vDC Gateway: View SSL VPN Available Available Available Available Available
Organization vDC Gateway: View Static Routing Available Available Available Available Available
Organization vDC Named Disk: Change Owner Available Available
Organization vDC Named Disk: Create Available Available
Organization vDC Named Disk: Delete Available Available
Organization vDC Named Disk: Edit Properties Available Available
Organization vDC Named Disk: Move Available Available
Organization vDC Named Disk: View Encryption Status Available Available Available Available Available
Organization vDC Named Disk: View Properties Available Available Available Available Available
Organization vDC Network: Edit Properties Available Available Available
Organization vDC Network: Manage Manual IP Reservation* Available Available Available Available
Organization vDC Network: View Available Available
Organization vDC Network: View Properties Available Available Available Available Available
Organization vDC Storage Policy: View Capabilities Available Available
Organization vDC Storage Profile: Set Default Available Available
Organization vDC: Edit Available Available
Organization vDC: Edit ACL Available Available Available
Organization vDC: Manage Firewall Available Available
Organization vDC: Simple Edit Available Available
Organization vDC: User View Available Available
Organization vDC: View Available Available Available Available Available
Organization vDC: View ACL Available Available Available Available Available
Organization vDC: View CPU and Memory Reservation Available Available Available Available Available
Organization VDC: view metrics Available Available Available Available Available
Organization vDC: VM-VM Affinity Edit Available Available
Organization vDC Shared Named Disk: Create Available Available
Organization: Edit Association Settings Available Available
Organization: Edit Federation Settings Available Available
Organization: Edit Leases Policy Available Available
Organization: Edit OAuth Settings Available Available
Organization: Edit Password Policy Available Available
Organization: Edit Properties Available Available
Organization: Edit Quotas Policy Available Available
Organization: Edit SMTP Settings Available Available
Organization: Import User/Group from IdP while Editing VDC ACL Available Available
Organization: Perform Administrator Queries Available Available Available Available
Organization: View Available Available Available Available Available
Organization: view metrics Available Available Available Available
Private IP Spaces: Manage Available Available Available Available
Private IP Spaces: View Available Available Available Available Available
Provider Gateway: Simple View Available Available Available Available
Provider Gateway BGP: Simple View Available Available Available Available Available
Provider Gateway Firewall: Manage Available Available Available Available
Provider Gateway Firewall: View Available Available Available Available Available
Provider Gateway IP Sec VPN: Manage* Available Available Available Available
Provider Gateway IP Sec VPN: View* Available Available Available Available Available
Provider Gateway NAT: Manage Available Available Available Available
Provider Gateway NAT: View Available Available Available Available Available
Provider Gateway Routing: Simple View* Available Available Available Available Available
Provider Network: View Available Available Available Available Available
Resource Pool: View Available Available Available Available
Quota Policy Capabilities: View Available Available Available Available Available Available
Resource Class Action: Manage Available Available
Resource Class Action: View Available Available Available
Role: Create, Edit, Delete, or Copy Available Available
Security Tag Edit Available Available
Selector Extensions: Manage Available Available
Selector Extensions: View Available Available Available
Service Authorization: Manage Available Available
Service Configuration: Manage Available Available
Service Configuration: View Available Available Available
Service Link: Manage Available Available
Service Link: View Available Available Available
Service Resource Type: Manage Available Available
Service Resource Type: View Available Available Available
Service Resource: Manage Available Available
Service Resource: View Available Available Available
Service Library: View service libraries Available Available Available Available Available
SSL: Test Connection Available Available Available Available Available Available
Truststore: Manage Available Available Available
Truststore: View Available Available Available Available Available Available
UI Plugins: Define Upload Modify Delete Associate or Disassociate Available Available
UI Plugins: View Available Available Available Available Available
UI Plugins: View Available Available Available
vApp Template / Media: Copy Available Available
vApp Template / Media: Create / Upload Available Available
vApp Template / Media: Edit Available Available
vApp Template / Media: View Available Available Available Available Available
vApp Template: Add to My Cloud Available Available
vApp Template: Change Owner Available Available
vApp Template: Checkout Available Available
vApp Template: Download Available Available
vApp: Allow All Extra Config Available Available
vApp: Allow Matching Extra Config Available Available
vApp: Change Owner Available Available
vApp: Copy Available Available
vApp: Create / Reconfigure Available Available
vApp: Delete Available Available
vApp: Download Available Available
vApp: Edit Properties Available Available Available
vApp: Edit VM Compute Policy Available Available
vApp: Edit VM CPU Available Available
vApp: Edit VM Hard Disk Available Available
vApp: Edit VM Memory Available Available
vApp: Edit VM Network Available Available Available
vApp: Edit VM Properties Available Available Available
vApp: Manage VM Password Settings Available Available
vApp: Power Operations Available Available
vApp: Shadow VM View Available Available Available Available Available
vApp: Sharing Available Available
vApp: Snapshot Operations Available Available
vApp: Upload Available Available
vApp: Use Console Available Available Available
vApp: View ACL Available Available Available Available Available Available
vApp: View VM and VM's Disks Encryption Status Available Available Available Available Available Available
vApp: View VM metrics Available Available Available Available Available Available
vApp: VM Boot Options Available Available
vApp: VM Metadata to vCenter Available Available
vApp: VM Migrate, Force Undeploy, Relocate, Consolidate Available Available Available
VAPP_VM_METADATA_TO_VCENTER Available Available
VCD Extension: Register, Unregister, Refresh, Associate or Disassociate Available Available
VCD Extension: View Available Available Available
VDC Group: Configure Available Available
VDC Group: Configure Logging Available Available
VDC Group: View Available Available Available Available Available
VDC Template: Instantiate Available Available
VDC Template: View Available Available Available Available
vGPU Profile Consumption: View Available Available Available