Yandex Cloud
Search
Contact UsTry it for free
  • Customer Stories
  • Documentation
  • Blog
  • All Services
  • System Status
  • Marketplace
    • Featured
    • Infrastructure & Network
    • Data Platform
    • AI for business
    • Security
    • DevOps tools
    • Serverless
    • Monitoring & Resources
  • All Solutions
    • By industry
    • By use case
    • Economics and Pricing
    • Security
    • Technical Support
    • Start testing with double trial credits
    • Cloud credits to scale your IT product
    • Gateway to Russia
    • Cloud for Startups
    • Center for Technologies and Society
    • Yandex Cloud Partner program
    • Price calculator
    • Pricing plans
  • Customer Stories
  • Documentation
  • Blog
© 2026 Direct Cursus Technology L.L.C.
Yandex Cloud Registry
  • Getting started
    • All guides
      • Creating a registry
        • Viewing roles assigned for a registry
        • Assigning a role
        • Revoking a role
    • Creating a lifecycle policy
  • Access management
  • Pricing policy
  • Terraform reference
  • Audit Trails events
  1. Step-by-step guides
  2. Managing a registry
  3. Managing registry access permissions
  4. Assigning a role

Assigning a role for a registry

Written by
Yandex Cloud
Updated at April 6, 2026

Note

We recommend assigning roles to the public group All users only for Docker registries: correct operation is not guaranteed for other formats.

Management console
CLI
API
  1. In the management console, select the folder where the registry is located.
  2. Go to Cloud Registry.
  3. Select the registry.
  4. Navigate to the Access bindings tab.
  5. Click Assign roles.
  6. In the window that opens, select a group, user, or service account.
  7. Click Add role and select the role from the list.
  8. Click Save.

If you do not have the Yandex Cloud CLI yet, install and initialize it.

The folder used by default is the one specified when creating the CLI profile. To change the default folder, use the yc config set folder-id <folder_ID> command. You can also set a different folder for any specific command using the --folder-name or --folder-id options.

Run the following command to assign a role for a registry:

  • To a user:

    yc cloud-registry registry add-access-binding <registry_name_or_ID> \
      --role <role> \
      --user-account-id <user_ID>
    
  • To a service account:

    yc cloud-registry registry add-access-binding <registry_name_or_ID> \
      --role <role> \
      --service-account-id <service_account_ID>
    
  • To all authenticated users (the All authenticated users public group):

    yc cloud-registry registry add-access-binding <registry_name_or_ID> \
      --role <role> \
      --allAuthenticatedUsers
    
  • To all users (the All users public group):

    yc cloud-registry registry add-access-binding <registry_name_or_ID> \
      --role <role> \
      --allUsers
    

    Where <role> is the role you want to assign.

To revoke all registry roles and assign new ones right away, use the yc cloud-registry registry set-access-bindings command.

Example

In the example below, we are assigning the cloud-registry.admin role for my-first-registry to a user.

yc cloud-registry registry add-access-binding my-first-registry \
  --role cloud-registry.admin \
  --user-account-id ajeugsk5ubk6********

Result:

done (4s)

Use the updateAccessBindings REST API method for the Registry resource or the RegistryService/UpdateAccessBindings gRPC API call.

For more information on role assignment, see this Yandex Identity and Access Management guide.

Was the article helpful?

Previous
Viewing roles assigned for a registry
Next
Revoking a role
© 2026 Direct Cursus Technology L.L.C.