Assigning roles for a function
If you do not have the Yandex Cloud CLI yet, install and initialize it.
The folder used by default is the one specified when creating the CLI profile. To change the default folder, use the yc config set folder-id <folder_ID> command. You can also specify a different folder for any command using --folder-name or --folder-id.
If you access a resource by its name, the search will be limited to the default folder. If you access a resource by its ID, the search will be global, i.e., through all folders based on access permissions.
Run this command to assign a role for a function:
yc serverless function add-access-binding \
--id <function_ID> \
--role <role> \
--subject <subject_type>:<subject_ID>
Where:
-
--role: Role. -
--subject: Subject getting the role.Subject designations
To indicate a subject, use the
--subjectparameter in<subject_type>:<ID>format. For some subject types, the Yandex Cloud CLI provides separate parameters instead of--subject, where you only need to specify the subject name or ID without the type. Possible subject designations and matching CLI parameters:Subject type
Subject designation
Yandex Cloud CLI parameter
userAccountuserAccount:<user_ID>--user-account-idor--user-yandex-loginserviceAccountserviceAccount:<service_account_ID>--service-account-idor--service-account-namefederatedUserfederatedUser:<user_ID>--user-account-idgroupgroup:<group_ID>--group-memberssystemsystem:allAuthenticatedUsers(
All authenticated usersgroup)--all-authenticated-userssystem:allUsers(
All usersgroup)—
system:group:organization:<organization_ID>:users(
All users in organization Xgroup)--organization-userssystem:group:federation:<federation_ID>:users(
All users in federation Ngroup)--federation-userssystem:group:userpool:<pool_ID>:users(
All users in userpool Pgroup)—
To assign roles for a function, use the setAccessBindings REST API method for the Function resource or the FunctionService/SetAccessBindings gRPC API call. In the request body, set the action property to ADD and specify the subject type and ID under subject.
Subject designations
To indicate a subject, use a combination of its type and unique ID in the subject.type and subject.id fields of the request. Here are possible combinations:
|
subject.type |
subject.id |
|
|
|
|
|
|
|
|
|
|
|
|
|
|
( |
|
( |
|
|
( |
|
|
( |
|
|
( |