Changing desktop group access permissions
Cloud Desktop leverages Yandex Identity and Access Management roles and access control lists (ACL) to manage access. Example of access control.
- In the management console
, select the folder containing the desktop group. - Navigate
to Cloud Desktop. - Select the desktop group to update access permissions for.
- In the left-hand panel, select
Access permissions. - Click Assign roles.
- In the Edit access bindings window that opens, grant or revoke permissions as needed.
- Click Save.
If you do not have the Yandex Cloud CLI yet, install and initialize it.
The folder used by default is the one specified when creating the CLI profile. To change the default folder, use the yc config set folder-id <folder_ID> command. You can also specify a different folder for any command using --folder-name or --folder-id.
If you access a resource by its name, the search will be limited to the default folder. If you access a resource by its ID, the search will be global, i.e., through all folders based on access permissions.
You can assign multiple roles using the set-access-bindings command.
Alert
The set-access-bindings command completely overwrites access permissions for the desktop group. All current group roles will be deleted.
-
Make sure the desktop group has no roles you want to keep:
yc desktops group list-access-bindings <desktop_group_name_or_ID> -
See the description of the CLI command for assigning roles to a desktop group:
yc desktops group set-access-bindings --help -
Assign roles:
yc desktops group set-access-bindings <desktop_group_name_or_ID> \ --access-binding role=<role>,<subject_type>=<subject_ID> \ --access-binding role=<role>,<subject_type>=<subject_ID>Where
--access-bindingcontains access permission settings:-
role: Role. -
subject: Subject getting the role.Indicating a subject
To indicate a subject, use the
--subjectparameter in<subject_type>:<ID>format. For some subject types, the Yandex Cloud CLI provides separate parameters instead of--subject, where you only need to specify the subject name or ID without the type. Possible subject designations and matching CLI parameters:Subject type
Subject designation
Yandex Cloud CLI parameter
userAccountuserAccount:<user_ID>--user-account-idor--user-yandex-loginserviceAccountserviceAccount:<service_account_ID>--service-account-idor--service-account-namefederatedUserfederatedUser:<user_ID>--user-account-idgroupgroup:<group_ID>--group-memberssystemsystem:allAuthenticatedUsers(
All authenticated usersgroup)--all-authenticated-userssystem:allUsers(
All usersgroup)—
system:group:organization:<organization_ID>:users(
All users in organization Xgroup)--organization-userssystem:group:federation:<federation_ID>:users(
All users in federation Ngroup)--federation-userssystem:group:userpool:<pool_ID>:users(
All users in userpool Pgroup)—
For example, assign roles to several users and a service account:
yc desktops group set-access-bindings my-desktop-group \ --access-binding role=editor,userAccount=gfei8n54hmfh******** \ --access-binding role=viewer,userAccount=helj89sfj80a******** \ --access-binding role=editor,serviceAccount=ajel6l0jcb9s********To assign a role to a subject without rewriting its other roles, use the
yc desktops group add-access-bindingscommand. For example, to assign a role to a service account:yc desktops group add-access-bindings \ --name <desktop_group_name> \ --role <role> \ --service-account-name <service_account_name> -
Use the updateAccessBindings REST API method for the DesktopGroup resource or the DesktopGroupService/UpdateAccessBindings gRPC API call. In the request body, specify the subject type and ID under subject.
Subject designations
To indicate a subject, use a combination of its type and unique ID in the subject.type and subject.id fields of the request. Here are possible combinations:
|
subject.type |
subject.id |
|
|
|
|
|
|
|
|
|
|
|
|
|
|
( |
|
( |
|
|
( |
|
|
( |
|
|
( |