Managing access with Yandex Identity and Access Management
Object Storage incorporates multiple mechanisms for managing access to resources. To learn how these mechanisms interact, see Access management methods in Object Storage: Overview.
In this section, you will learn:
About access management
In Yandex Cloud, all transactions are checked in Yandex Identity and Access Management. If a subject does not have the required permission, the service returns an error.
To grant permission for a resource, assign roles for this resource to the subject that will perform operations. Roles can be assigned to a Yandex account, a service account, federated users, a user group, or a system group. For more information, see How access management works in Yandex Cloud.
Only users with the admin
, resource-manager.clouds.owner
, or organization-manager.organizations.owner
role for a resource can assign roles for this resource.
Which resources you can assign a role for
Using the Yandex Cloud console or the YC CLI, you can assign a role for a cloud, a folder, or an individual bucket. These assigned roles will also apply to nested resources.
For information about managing access to buckets and objects, see Access control lists (ACLs).
Which roles exist in the service
The chart below shows which roles are available in the service and how they inherit each other's permissions. For example, the editor
role includes all the permissions of viewer
. You can find the description of each role under the chart.
Service roles
storage.viewer
The storage.viewer
role gives you read access to the list of buckets, settings, and data.
storage.configViewer
The storage.configViewer
role enables you to view the security settings of buckets and their objects. It does not grant access to data stored in buckets.
storage.configurer
The storage.configurer
role enables you to manage the settings of object lifecycles, static website hosting, access policy, and CORS.
It does not permit the user to manage access control list (ACL) or public access settings. It does not grant access to bucket data.
storage.uploader
The storage.uploader
role enables you to upload objects to a bucket and overwrite previously uploaded ones. Since the storage.uploader
role inherits the permissions of the storage.viewer
role, it also grants permission to list bucket objects and download them.
This role does not allow you to delete objects or configure buckets.
storage.editor
The storage.editor
role enables you to perform any operation with buckets and objects in the folder: create (including a publicly accessible bucket), delete, and edit them.
This role does not allow you to manage access control list (ACL) settings.
storage.admin
The storage.admin
role is intended for managing Object Storage. Users with this role can:
- Create buckets.
- Delete buckets.
- Assign an access control list (ACL).
- Manage any bucket object.
- Manage any bucket website.
- Configure other bucket parameters and objects in the bucket.
This role enables the user to grant other users access to a bucket or a specific object in it.
This role can be assigned by the administrator of the cloud (the admin
role).
Primitive roles
auditor
Grants permission to view service configuration and metadata without access to data.
viewer
Enables you to view information about resources.
editor
Allows managing (creating, editing, and deleting) resources.
admin
Allows you to manage your resources and access to them.
For more information about primitive roles, see the Yandex Cloud role reference.