Skip to Main Content
Status Delivered
Workspace * IBM Cloud Ideas
Created by Guest
Created on Feb 27, 2020

More granular access permissions for cloud object storage

It would be helpful to be able to give someone permissions to upload/PUT new objects in object storage, but not modify/delete them. The Writer service access has 52 more granular permissions listed, but Writer allows objects and even buckets to be deleted. It would be helpful to set more granular permissions beneath that, for example allowing "cloud-object-storage.object.put" but not "cloud-object-storage.object.delete". Retention policies help in some scenarios, but aren't granular enough and can't be overridden by another user/service.

Idea priority High
  • Guest
    Apr 16, 2020

    IAM has custom policy support now so you can make your own policy with the actions you want to include

    https://cloud.ibm.com/docs/iam?topic=iam-custom-roles