Yandex Cloud security tutorials
Written by
Updated at March 31, 2025
Authentication and access management
- Access control for user groups with different roles in Yandex Cloud Organization
- Using a service account with an OS Login profile for VM management via Ansible
- Managing identity federations
Network security
- Setting up virtual hosting
- Automatically copying objects from one Yandex Object Storage bucket to another
- Loading data from Yandex Direct to a Yandex Managed Service for ClickHouse® data mart using Yandex Cloud Functions, Yandex Object Storage, and Yandex Data Transfer
- Creating a load balancer with DDoS protection
- Secure user access to cloud resources based on WireGuard VPN
- Providing secure access to content in Yandex Cloud CDN
Secure virtual environment configuration
- Hosting a static Gatsby website in Yandex Object Storage
- Storing Apache Airflow™ connections and variables in Yandex Lockbox
- Deploying a fault-tolerant architecture with preemptible VMs
- Migrating services from an NLB to an L7 ALB for DDoS protection using Yandex Smart Web Security
- Migrating services from an NLB load balancer with VMs as targets to an ALB L7 load balancer
- Migrating services from a NLB load balancer with an instance group as a target to an L7 ALB load balancer
- Migrating services from an external NLB load balancer to an L7 ALB load balancer with an internal NLB load balancer as a target
Data encryption and key management
- Data encryption
- Managing Yandex Key Management Service keys with Hashicorp Terraform
- Encrypting secrets in Hashicorp Terraform
- Auto Unseal in Hashicorp Vault
- Secure password transmission to an initialization script
- Terminating TLS connections
- Secure storage of GitLab CI passwords as Yandex Lockbox secrets
- Using a Yandex Lockbox secret to store a static access key
- Getting Yandex Lockbox secret value on the GitHub side
- Getting the Yandex Lockbox secret value on the GitLab side
Collecting, monitoring, and analyzing audit logs
- Searching for Yandex Cloud events in Yandex Query
- Searching for Yandex Cloud events in Yandex Object Storage
- Searching for Yandex Cloud events in Yandex Cloud Logging
- Alert settings in Yandex Monitoring
- Configuring responses in Yandex Cloud Logging and Yandex Cloud Functions
- Processing Yandex Audit Trails events
- Exporting audit logs to SIEM systems
- Transferring logs from a VM to Yandex Cloud Logging
- Writing load balancer logs to PostgreSQL
- Transferring logs from Container Optimized Image to Yandex Cloud Logging
Application security
- Installing an NGINX Ingress controller with a Yandex Certificate Manager certificate
- Building a CI/CD pipeline in GitLab with serverless products
- Creating an interactive serverless application using WebSocket
- Creating an Yandex Application Load Balancer L7 load balancer with a Yandex Smart Web Security security profile
- Yandex API Gateway protection with Yandex Smart Web Security
- Adding an HTML page to work with Yandex SmartCaptcha
- Yandex SmartCaptcha in Android apps
- Invisible Yandex SmartCaptcha in Android apps
- Yandex SmartCaptcha in an Android app on Flutter
- Yandex SmartCaptcha in iOS apps
Kubernetes security
- Encrypting secrets in Yandex Managed Service for Kubernetes
- Signing and verifying Yandex Container Registry Docker images in Yandex Managed Service for Kubernetes
- Syncing with Yandex Managed Service for Kubernetes secrets
- Getting the Yandex Lockbox secret value on the Kubernetes side
- Creating an L7 load balancer with a Yandex Smart Web Security security profile through an Yandex Application Load Balancer Ingress controller
- Migrating services from a NLB load balancer with a Yandex Managed Service for Kubernetes cluster as a target to an L7 ALB load balancer
- Transferring Yandex Managed Service for Kubernetes cluster logs to Yandex Cloud Logging