RBAC Scopes: Cloud Accounts
This Pulumi Cloud feature is available in the Enterprise and Business Critical editions.
This document defines all the available scopes in Pulumi Cloud assignable to specific cloud accounts or sets of cloud accounts.
Note that creating, listing, or restoring cloud accounts are organization-level operations, and these scopes can be found in the organization settings scopes.
Cloud accounts
| Value | Description |
|---|---|
insights_account_access:read | View what users and roles can access a cloud account. Granted by default permission set: Account Read |
insights_account_access:update | Manage what users and roles can access a cloud account. Granted by default permission set: Account Admin |
insights_account:delete | Remove an existing cloud account. This permanently deletes the account and its associated data. Granted by default permission set: Account Admin |
insights_account:read | View cloud account configurations and data. This includes access to monitoring settings and analysis results. Granted by default permission set: Account Read |
insights_account:update | Modify cloud account settings and configurations. This allows updating monitoring parameters and analysis rules. Granted by default permission set: Account Write |
Cloud account scans
| Value | Description |
|---|---|
insights_account:scan | Initiate a new scan of a cloud account. This triggers analysis of infrastructure configurations and compliance. Granted by default permission set: Account Write |
insights_account_scan:cancel | Stop an ongoing cloud account scan. This halts the current analysis process. Granted by default permission set: Account Write |
insights_account_scan:pause | Temporarily suspend a cloud account scan. This pauses the analysis process without losing progress. Granted by default permission set: Account Write |
insights_account_scan:read | View cloud account scan results and status. This includes access to analysis findings and progress. Granted by default permission set: Account Read |
insights_account_scan:resume | Resume a paused cloud account scan. This continues the analysis process from where it paused. Granted by default permission set: Account Write |
insights_account_scan:update | Modify cloud account scan settings. This allows updating scan parameters and analysis configurations. Granted by default permission set: Account Write |