Assigning a role for a registry
Note
We recommend assigning roles to the public group All users only for Docker registries: correct operation is not guaranteed for other formats.
- In the management console
, select the folder where the registry is located. - Go to Cloud Registry.
- Select the registry.
- Navigate to the Access bindings tab.
- Click Assign roles.
- In the window that opens, select a group, user, or service account.
- Click
Add role and select the role from the list. - Click Save.
If you do not have the Yandex Cloud CLI yet, install and initialize it.
The folder used by default is the one specified when creating the CLI profile. To change the default folder, use the yc config set folder-id <folder_ID> command. You can also set a different folder for any specific command using the --folder-name or --folder-id options.
Run the following command to assign a role for a registry:
-
To a user:
yc cloud-registry registry add-access-binding <registry_name_or_ID> \ --role <role> \ --user-account-id <user_ID> -
To a service account:
yc cloud-registry registry add-access-binding <registry_name_or_ID> \ --role <role> \ --service-account-id <service_account_ID> -
To all authenticated users (the
All authenticated userspublic group):yc cloud-registry registry add-access-binding <registry_name_or_ID> \ --role <role> \ --allAuthenticatedUsers -
To all users (the
All userspublic group):yc cloud-registry registry add-access-binding <registry_name_or_ID> \ --role <role> \ --allUsersWhere
<role>is the role you want to assign.
To revoke all registry roles and assign new ones right away, use the yc cloud-registry registry set-access-bindings command.
Example
In the example below, we are assigning the cloud-registry.admin role for my-first-registry to a user.
yc cloud-registry registry add-access-binding my-first-registry \
--role cloud-registry.admin \
--user-account-id ajeugsk5ubk6********
Result:
done (4s)
Use the updateAccessBindings REST API method for the Registry resource or the RegistryService/UpdateAccessBindings gRPC API call.
For more information on role assignment, see this Yandex Identity and Access Management guide.