Yandex Cloud
Search
Contact UsGet started
  • Blog
  • Pricing
  • Documentation
  • All Services
  • System Status
    • Featured
    • Infrastructure & Network
    • Data Platform
    • Containers
    • Developer tools
    • Serverless
    • Security
    • Monitoring & Resources
    • AI Studio
    • Business tools
  • All Solutions
    • By industry
    • By use case
    • Economics and Pricing
    • Security
    • Technical Support
    • Customer Stories
    • Gateway to Russia
    • Cloud for Startups
    • Education and Science
  • Blog
  • Pricing
  • Documentation
Yandex project
© 2025 Yandex.Cloud LLC
All solutions
    • All solutions for Object Storage
    • Resolving the Bucket not empty error when deleting a bucket from Object Storage
    • Resolving errors of access to a bucket with an assigned security policy
    • Resolving error 429
    • Resolving the "409 BucketAlreadyExists" error
    • Resolving the error of access to S3 buckets from a DataProc 1.4 cluster
    • Resolving error 403 (header is not provided when using the OPTION method)
    • Resolving certificate error
    • Resolving GATEWAY_REQUEST_ERROR
    • Resolving issues with incorrect MIME-types of objects when uploading them to Object Storage
    • Moving data from an Object Storage bucket to an ice storage
    • Restricting access to an Object Storage bucket using an IP range from Cloud CDN
    • Moving bucket contents to another bucket in the same the folder
    • Accessing Object Storage API directly, bypassing the SDK
    • Viewing and deleting incomplete uploads
    • How to determine the speed of data upload and download
    • How to configure cache-control headers for objects in a bucket during HTTP requests
    • How to restrict access to a bucket for a user
    • How to connect your own domain to a bucket
    • How to change the storage class

In this article:

  • Scenario description
  • Solution
  1. Object Storage
  2. How to restrict access to a bucket for a user

How to restrict access to a bucket for a user

Written by
Yandex Cloud
Updated at November 27, 2023
  • Scenario description
  • Solution

Scenario descriptionScenario description

You need to restrict access to the bucket for another user or a service account.

SolutionSolution

Users with service roles such as storage.viewer, storage.configViewer, storage.configurer, storage.editor, or storage.admin have different privileges and access rights for buckets:

  • The storage.viewer, storage.editor, and storage.admin roles grant access to view or edit files in buckets.
  • The storage.configViewer role only allows viewing the security settings of buckets and objects in them (without access to objects).
  • The storage.configurer role allows modifying these settings.

For more details about service roles in Object Storage, see the documentation.

You can configure access to the bucket through ACL, removing the service roles from the required users, or configure access policies for each bucket: for more details, see here.

Was the article helpful?

Previous
How to configure cache-control headers for objects in a bucket during HTTP requests
Next
How to connect your own domain to a bucket
Yandex project
© 2025 Yandex.Cloud LLC