Yandex.Cloud
  • Services
  • Why Yandex.Cloud
  • Pricing
  • Documentation
  • Contact us
Get started
Yandex Data Transfer
  • Getting started
  • Step-by-step instructions
    • All instructions
    • Managing a source endpoint
      • Creating a source endpoint
      • Updating a source endpoint
      • Deleting a source endpoint
    • Managing a target endpoint
      • Creating a target endpoint
      • Updating a target endpoint
      • Deleting a target endpoint
    • Managing the transfer process
      • Creating a transfer
      • Updating a transfer
      • Deleting a transfer
  • Concepts
    • Relationship between service resources
    • What tasks is the service used for?
    • Service specifics
      • Overview
      • MySQL specifics
      • PostgreSQL specifics
    • Monitoring transfers
    • Quotas and limits
  • Access management
  • Pricing policy
  • Questions and answers
  1. Access management

Access management

  • About access management
  • What roles are required
  • What resources you can assign roles to
  • What roles exist in the service

To use the service, log in to the management console with your Yandex account or federated account.

In this section, you'll learn:

  • What roles are required for particular actions.
  • What resources you can assign roles to.
  • What roles exist in the service.

About access management

All transactions in Yandex.Cloud are checked by the Identity and Access Management service. If a subject doesn't have the required permission, the service returns an error.

To grant permission to a resource, assign roles for this resource to the subject that will perform operations. Roles can be assigned to a Yandex account, service account, or system group. For more information, see How access management works in Yandex.Cloud.

Only users with the admin or resource-manager.clouds.owner role for a resource can assign roles for this resource.

What roles are required

To use the service, you need a role editor or a higher role for the folder where projects are created. With the viewer role, you can only view the list of projects and the contents of files that were downloaded.

You can always assign a role granting more permissions than the role specified. For example, assign the admin role instead of editor.

What resources you can assign roles to

You can assign roles for a cloud and folder. Cloud roles also apply to nested folders.

What roles exist in the service

  • Service roles:
    • data-transfer.viewer: Lets you view information only about Data Transfer resources.
    • resource-manager.clouds.owner: Grants you full access to the cloud and the resources in it. You can only assign this role for a cloud.

    • resource-manager.clouds.member: The role needed to perform any operation in the cloud on behalf of a Yandex account. The role is assigned automatically when a user is added to the cloud. You can only assign this role for a cloud.

  • Primitive roles:
    • viewer: Only lets you view information about the resources.

    • editor: Lets you manage resources (create, edit, and delete).

    • admin: Lets you manage resources and access them.

What's next

  • How to assign a role.
  • How to revoke a role.
  • Learn more about access management in Yandex.Cloud.
  • More about role inheritance.
In this article:
  • About access management
  • What roles are required
  • What resources you can assign roles to
  • What roles exist in the service
Language
Careers
Privacy policy
Terms of use
© 2021 Yandex.Cloud LLC