Configuring VM placement group access permissions
To grant a user, group, or service account access to a VM placement group, assign a role for it.
Assigning a role
- In the management console
, select the folder hosting your placement group. - Navigate
to Compute Cloud. - In the left-hand panel, select
Placement groups. - On the Virtual machine placement groups tab, click the name of the group.
- Navigate to the Access bindings tab.
- Click Assign roles.
- In the window that opens, select the group, user, or service account you want to grant access to the placement group.
- Click
Add role and select the required role. - Click Save.
If you do not have the Yandex Cloud CLI yet, install and initialize it.
The folder used by default is the one specified when creating the CLI profile. To change the default folder, use the yc config set folder-id <folder_ID> command. You can also specify a different folder for any command using --folder-name or --folder-id.
If you access a resource by its name, the search will be limited to the default folder. If you access a resource by its ID, the search will be global, i.e., through all folders based on access permissions.
-
See the description of the CLI command for assigning a role for a VM placement group:
yc compute placement-group add-access-binding --help -
Get a list of VM placement groups in the default folder:
yc compute placement-group list -
View the roles already assigned for the resource:
yc compute placement-group list-access-bindings <placement_group_ID> -
Assign a role using this command:
yc compute placement-group add-access-binding <placement_group_ID> \ --role <role> \ --subject <subject_type>:<subject_ID>Where:
-
--role: Role. -
--subject: Subject getting the role.Subject designations
To indicate a subject, use the
--subjectparameter in<subject_type>:<ID>format. For some subject types, the Yandex Cloud CLI provides separate parameters instead of--subject, where you only need to specify the subject name or ID without the type. Possible subject designations and matching CLI parameters:Subject type
Subject designation
Yandex Cloud CLI parameter
userAccountuserAccount:<user_ID>--user-account-idor--user-yandex-loginserviceAccountserviceAccount:<service_account_ID>--service-account-idor--service-account-namefederatedUserfederatedUser:<user_ID>--user-account-idgroupgroup:<group_ID>--group-memberssystemsystem:allAuthenticatedUsers(
All authenticated usersgroup)--all-authenticated-userssystem:allUsers(
All usersgroup)—
system:group:organization:<organization_ID>:users(
All users in organization Xgroup)--organization-userssystem:group:federation:<federation_ID>:users(
All users in federation Ngroup)--federation-userssystem:group:userpool:<pool_ID>:users(
All users in userpool Pgroup)—
-
With Terraform
Terraform is distributed under the Business Source License
For more information about the provider resources, see the guides on the Terraform
If you do not have Terraform yet, install it and configure the Yandex Cloud provider.
To manage infrastructure using Terraform under a service account or user accounts (a Yandex account, a federated account, or a local user), authenticate using the appropriate method.
To assign a role for access to a VM placement group using Terraform:
-
In the Terraform configuration file, describe the resources you want to create:
resource "yandex_compute_placement_group_iam_binding" "sa-access" { placement_group_id = "<placement_group_ID>" role = "<role>" members = ["<subject_type>:<subject_ID>"] }Where:
-
placement_group_id: VM placement group ID. -
role: Role. -
members: List of designations of subjects the role is assigned to.Subject designations
To indicate a subject, use a combination of its type and unique ID, i.e.,
<subject_type>:<ID>. Here is how you can designate a subject:Subject type
Subject designation
userAccountuserAccount:<user_ID>serviceAccountserviceAccount:<service_account_ID>federatedUserfederatedUser:<user_ID>groupgroup:<group_ID>systemsystem:allAuthenticatedUsers(
All authenticated usersgroup)system:allUsers(
All usersgroup)system:group:organization:<organization_ID>:users(
All users in organization Xgroup)system:group:federation:<federation_ID>:users(
All users in federation Ngroup)system:group:userpool:<pool_ID>:users(
All users in userpool Pgroup)
For more information about the properties of the
yandex_compute_placement_group_iam_bindingresource, see this provider guide. -
-
Apply the changes:
-
In the terminal, navigate to the configuration file directory.
-
Make sure the configuration is correct using this command:
terraform validateIf the configuration is valid, you will get this message:
Success! The configuration is valid. -
Run this command:
terraform planYou will see a list of resources and their properties. No changes will be made at this step. Terraform will show any errors in the configuration.
-
Apply the configuration changes:
terraform apply -
Type
yesand press Enter to confirm the changes.
Terraform will create all the required resources. You can check the updates using the management console
or this CLI command:yc compute placement-group list-access-bindings <placement_group_ID> -
To assign a role, use the updateAccessBindings REST API method for the PlacementGroup resource or the PlacementGroupService/UpdateAccessBindings gRPC API call. In the request body, set the action property to ADD and specify the subject type and ID under subject.
Subject designations
To indicate a subject, use a combination of its type and unique ID in the subject.type and subject.id fields of the request. Here are possible combinations:
|
subject.type |
subject.id |
|
|
|
|
|
|
|
|
|
|
|
|
|
|
( |
|
( |
|
|
( |
|
|
( |
|
|
( |
Assigning multiple roles
- In the management console
, select the folder hosting your placement group. - Navigate
to Compute Cloud. - In the left-hand panel, select
Placement groups. - On the Virtual machine placement groups tab, click the name of the group.
- Navigate to the Access bindings tab.
- Click Assign roles.
- In the window that opens, select the group, user, or service account you want to grant access to the placement group.
- Click
Add role and select the required role. - To add another role, click
Add role. - Click Save.
If you do not have the Yandex Cloud CLI yet, install and initialize it.
The folder used by default is the one specified when creating the CLI profile. To change the default folder, use the yc config set folder-id <folder_ID> command. You can also specify a different folder for any command using --folder-name or --folder-id.
If you access a resource by its name, the search will be limited to the default folder. If you access a resource by its ID, the search will be global, i.e., through all folders based on access permissions.
You can assign multiple roles using the set-access-bindings command.
Alert
The set-access-bindings command completely rewrites access permissions for the resource. All current roles for the resource will be deleted.
-
Make sure the resource has no roles assigned that you would not want to lose:
yc compute placement-group list-access-bindings <placement_group_ID> -
See the description of the CLI command for assigning roles for a VM placement group:
yc compute placement-group set-access-bindings --help -
Assign the roles:
yc compute placement-group set-access-bindings <placement_group_ID> \ --access-binding role=<role>,subject=<subject_type>:<subject_ID> \ --access-binding role=<role>,subject=<subject_type>:<subject_ID>Where
--access-bindingcontains access permission settings:-
role: Role. -
subject: Subject getting the role.Indicating a subject
To indicate a subject, use the
--subjectparameter in<subject_type>:<ID>format. For some subject types, the Yandex Cloud CLI provides separate parameters instead of--subject, where you only need to specify the subject name or ID without the type. Possible subject designations and matching CLI parameters:Subject type
Subject designation
Yandex Cloud CLI parameter
userAccountuserAccount:<user_ID>--user-account-idor--user-yandex-loginserviceAccountserviceAccount:<service_account_ID>--service-account-idor--service-account-namefederatedUserfederatedUser:<user_ID>--user-account-idgroupgroup:<group_ID>--group-memberssystemsystem:allAuthenticatedUsers(
All authenticated usersgroup)--all-authenticated-userssystem:allUsers(
All usersgroup)—
system:group:organization:<organization_ID>:users(
All users in organization Xgroup)--organization-userssystem:group:federation:<federation_ID>:users(
All users in federation Ngroup)--federation-userssystem:group:userpool:<pool_ID>:users(
All users in userpool Pgroup)—
For example, assign roles to several users and one service account:
yc compute placement-group set-access-bindings my-group \ --access-binding role=editor,subject=userAccount:gfei8n54hmfh******** \ --access-binding role=viewer,subject=userAccount:helj89sfj80a******** \ --access-binding role=editor,subject=serviceAccount:ajel6l0jcb9s******** -
With Terraform
Terraform is distributed under the Business Source License
For more information about the provider resources, see the guides on the Terraform
If you do not have Terraform yet, install it and configure the Yandex Cloud provider.
To manage infrastructure using Terraform under a service account or user accounts (a Yandex account, a federated account, or a local user), authenticate using the appropriate method.
To assign multiple roles for a VM placement group using Terraform:
-
In the Terraform configuration file, describe the resources you want to create:
resource "yandex_compute_placement_group_iam_binding" "role1" { placement_group_id = "<placement_group_ID>" role = "<role_1>" members = ["<subject_type>:<subject_ID>"] } resource "yandex_compute_placement_group_iam_binding" "role2" { placement_group_id = "<placement_group_ID>" role = "<role_2>" members = ["<subject_type>:<subject_ID>"] }Where:
-
placement_group_id: VM placement group ID. -
role: Role. -
members: List of designations of subjects the role is assigned to.Subject designations
To indicate a subject, use a combination of its type and unique ID, i.e.,
<subject_type>:<ID>. Here is how you can designate a subject:Subject type
Subject designation
userAccountuserAccount:<user_ID>serviceAccountserviceAccount:<service_account_ID>federatedUserfederatedUser:<user_ID>groupgroup:<group_ID>systemsystem:allAuthenticatedUsers(
All authenticated usersgroup)system:allUsers(
All usersgroup)system:group:organization:<organization_ID>:users(
All users in organization Xgroup)system:group:federation:<federation_ID>:users(
All users in federation Ngroup)system:group:userpool:<pool_ID>:users(
All users in userpool Pgroup)
For more information about the properties of the
yandex_compute_placement_group_iam_bindingresource, see this provider guide. -
-
Apply the changes:
-
In the terminal, navigate to the configuration file directory.
-
Make sure the configuration is correct using this command:
terraform validateIf the configuration is valid, you will get this message:
Success! The configuration is valid. -
Run this command:
terraform planYou will see a list of resources and their properties. No changes will be made at this step. Terraform will show any errors in the configuration.
-
Apply the configuration changes:
terraform apply -
Type
yesand press Enter to confirm the changes.
Terraform will create all the required resources. You can check the updates using the management console
or this CLI command:yc compute placement-group list-access-bindings <placement_group_ID> -
To assign roles for a placement group, use the setAccessBindings REST API method for the PlacementGroup resource or the PlacementGroupService/SetAccessBindings gRPC API call. In the request body, specify the subject type and ID under subject.
Subject designations
To indicate a subject, use a combination of its type and unique ID in the subject.type and subject.id fields of the request. Here are possible combinations:
|
subject.type |
subject.id |
|
|
|
|
|
|
|
|
|
|
|
|
|
|
( |
|
( |
|
|
( |
|
|
( |
|
|
( |
Alert
The setAccessBindings method and the PlacementGroupService/SetAccessBindings call overwrite all existing access permissions for the resource. All current roles for the resource will be deleted.
Revoking a role
- In the management console
, select the folder hosting your placement group. - Navigate
to Compute Cloud. - In the left-hand panel, select
Placement groups. - On the Virtual machine placement groups tab, click the name of the group.
- Navigate to the Access bindings tab.
- In the line with the user in question, click
and select Edit roles. - Next to the role, click
. - Click Save.
If you do not have the Yandex Cloud CLI yet, install and initialize it.
The folder used by default is the one specified when creating the CLI profile. To change the default folder, use the yc config set folder-id <folder_ID> command. You can also specify a different folder for any command using --folder-name or --folder-id.
If you access a resource by its name, the search will be limited to the default folder. If you access a resource by its ID, the search will be global, i.e., through all folders based on access permissions.
-
See the description of the CLI command for revoking a role for a placement group:
yc compute placement-group remove-access-binding --help -
View the list of users and their roles for the resource:
yc compute placement-group list-access-bindings <placement_group_ID> -
To revoke access permissions, run this command:
yc compute placement-group remove-access-binding <placement_group_ID> \ --role=<role> \ --subject=<subject_type>:<subject_ID>Where:
-
--role: ID of the role you need to revoke. -
--subject: Designation of the subject you want to revoke the role from.Subject designations
To indicate a subject, use the
--subjectparameter in<subject_type>:<ID>format. For some subject types, the Yandex Cloud CLI provides separate parameters instead of--subject, where you only need to specify the subject name or ID without the type. Possible subject designations and matching CLI parameters:Subject type
Subject designation
Yandex Cloud CLI parameter
userAccountuserAccount:<user_ID>--user-account-idor--user-yandex-loginserviceAccountserviceAccount:<service_account_ID>--service-account-idor--service-account-namefederatedUserfederatedUser:<user_ID>--user-account-idgroupgroup:<group_ID>--group-memberssystemsystem:allAuthenticatedUsers(
All authenticated usersgroup)--all-authenticated-userssystem:allUsers(
All usersgroup)—
system:group:organization:<organization_ID>:users(
All users in organization Xgroup)--organization-userssystem:group:federation:<federation_ID>:users(
All users in federation Ngroup)--federation-userssystem:group:userpool:<pool_ID>:users(
All users in userpool Pgroup)—
For example, this command revokes the
viewerrole for the placement group from a user with theajel6l0jcb9s********ID:yc compute placement-group remove-access-binding my-group \ --role viewer \ --subject userAccount:ajel6l0jcb9s******** -
With Terraform
Terraform is distributed under the Business Source License
For more information about the provider resources, see the guides on the Terraform
If you do not have Terraform yet, install it and configure the Yandex Cloud provider.
To manage infrastructure using Terraform under a service account or user accounts (a Yandex account, a federated account, or a local user), authenticate using the appropriate method.
To revoke a role assigned for a VM placement group using Terraform:
-
Open the Terraform configuration file and delete the fragment describing the role:
resource "yandex_compute_placement_group_iam_binding" "sa-access" { placement_group_id = "<placement_group_ID>" role = "<role>" members = ["<subject_type>:<subject_ID>"] } -
Apply the changes:
-
In the terminal, navigate to the configuration file directory.
-
Make sure the configuration is correct using this command:
terraform validateIf the configuration is valid, you will get this message:
Success! The configuration is valid. -
Run this command:
terraform planYou will see a list of resources and their properties. No changes will be made at this step. Terraform will show any errors in the configuration.
-
Apply the configuration changes:
terraform apply -
Type
yesand press Enter to confirm the changes.
You can check the updates using the management console
or this CLI command:yc compute placement-group list-access-bindings <placement_group_ID> -
To revoke a role, use the updateAccessBindings REST API method for the PlacementGroup resource or the PlacementGroupService/UpdateAccessBindings gRPC API call. In the request body, set the action property to REMOVE and specify the subject type and ID under subject.
Subject designations
To indicate a subject, use a combination of its type and unique ID in the subject.type and subject.id fields of the request. Here are possible combinations:
|
subject.type |
subject.id |
|
|
|
|
|
|
|
|
|
|
|
|
|
|
( |
|
( |
|
|
( |
|
|
( |
|
|
( |