In this section, you'll learn:
- What roles are required for particular actions.
- What resources you can assign roles to.
- What roles exist in the service.
About access management
All transactions in Yandex.Cloud are checked by the Identity and Access Management service. If a subject doesn't have the required permission, the service returns an error.
To grant permission to a resource, assign roles for this resource to the subject that will perform operations. Roles can be assigned to a Yandex account, service account, or system group. For more information, see How access management in Yandex.Cloud works.
Only users with the
resource-manager.clouds.owner role for a resource can assign roles for this resource.
What roles are required
To use the service, you need a role
editor or a higher role for the folder where projects are created. With the
viewer role, you can only view the list of projects and the contents of files that were downloaded.
You can always assign a role granting more permissions than the role specified. For example, assign the
admin role instead of
What resources you can assign roles to.
What roles exist in the service
The diagram shows which roles are available in the service and how they inherit each other's permissions. For example, the
editor role includes all
viewer role permissions. A description of each role is given under the diagram.
Active roles in the service:
- Service roles:
resource-manager.clouds.owner: Grants you full access to the cloud and the resources in it. You can only assign this role for a cloud.
resource-manager.clouds.member: The role needed to perform any operation in the cloud on behalf of a Yandex account. The role is assigned automatically when a user is added to the cloud. You can only assign this role for a cloud.
- Primitive roles: