Access management in Cloud Backup
In this section, you will learn:
About access management
In Yandex Cloud, all transactions are checked in Yandex Identity and Access Management. If a subject does not have the required permission, the service returns an error.
To grant permission for a resource, assign roles for this resource to the subject that will perform operations. Roles can be assigned to a Yandex account, a service account, federated users, a user group, or a system group. For more information, see How access management works in Yandex Cloud.
Only users with the admin
, resource-manager.clouds.owner
, or organization-manager.organizations.owner
role for a resource can assign roles for this resource.
Which resources you can assign a role for
Using the Yandex Cloud console or the YC CLI, you can assign a role to a cloud or folder. These assigned roles will also apply to nested resources.
Which roles exist in the service
Service roles
backup.viewer
The backup.viewer
role allows you to view information on virtual machines connected to Cloud Backup, on backup policies and backups, as well as on the relevant cloud, folder, and quotas.
Users with this role can:
- View info on the connected backup providers.
- View info on access bindings for backup policies.
- View info on backup policies and virtual machines linked to them.
- View info on the virtual machines connected to the service.
- View info on backups.
- View info on Cloud Backup quotas.
- View information on the relevant cloud.
- View info on the relevant folder and its statistics.
To assign the backup.viewer
role, you need either the admin
role for the cloud or the backup.admin
one for the folder.
backup.editor
The backup.editor
role allows you to manage the connection of virtual machines to Cloud Backup, manage backup policies, make backups, and restore VMs from existing backups.
Users with this role can:
- View info on connected backup providers, as well as connect providers available in Cloud Backup.
- Create, modify, and delete backup policies, as well as link, unlink, and run them on virtual machines.
- View info on access bindings for backup policies.
- View info on backup policies and virtual machines linked to them.
- View info on virtual machines connected to Cloud Backup, as well as connect and disconnect VMs to and from the service.
- View info on backups, as well as delete them and use them to restore VMs.
- View info on Cloud Backup quotas.
- View information on the relevant cloud.
- View info on the relevant folder and its statistics.
This role also includes the backup.viewer
permissions.
To assign the backup.editor
role, you need either the admin
role for the cloud or the backup.admin
one for the folder.
backup.admin
The backup.admin
role allows you to manage backup policies and access to them, manage the connection of virtual machines to Cloud Backup, make backups, and restore VMs from existing backups.
Users with this role can:
- View info on access bindings for backup policies and modify such bindings.
- View info on connected backup providers, as well as connect providers available in Cloud Backup.
- Create, modify, and delete backup policies, as well as link, unlink, and run them on virtual machines.
- View info on backup policies and virtual machines linked to them.
- View info on virtual machines connected to Cloud Backup, as well as connect and disconnect VMs to and from the service.
- View info on backups, as well as delete them and use them to restore VMs.
- View info on Cloud Backup quotas.
- View information on the relevant cloud.
- View info on the relevant folder and its statistics.
This role also includes the backup.editor
permissions.
To assign the backup.admin
role, you need the admin
role for the cloud.
Primitive roles
auditor
Grants permission to view service configuration and metadata without access to data.
viewer
Enables you to view information about resources.
editor
Allows managing (creating, editing, and deleting) resources.
admin
Allows you to manage your resources and access to them.
For more information about primitive roles, see the Yandex Cloud role reference.