Viewing assigned roles
To view permissions granted to an account for a resource, get a list of roles assigned for the resource and its parent resources. Roles assigned to a parent resource are inherited by its child resources. For example, if you want to find out what permissions an account has for a folder, check the roles assigned:
- For that folder.
- For the cloud that the folder belongs to.
- For the organization that the cloud belongs to.
You can view a list of inherited roles for a folder or cloud in the management console, in the Access bindings section of the folder or cloud.
Learn which resources you can assign a role for.
Note
Even if an operation with resources pertaining to Yandex Cloud services is allowed by a role, it may still be blocked if the organization, cloud, or folder is subject to an access policy prohibiting this operation.
To view assigned roles:
To view the roles of a Yandex account user, federated user, local user, or service account for a cloud:
- In the management console
, click or in the top panel and select the cloud. - Navigate to the Access bindings tab.
- Find the user in the list. The Roles column lists assigned roles.
To view roles of a service account for a folder and its child resources:
- In the management console
, click or in the top panel and select the folder the service account belongs to. - Navigate
to Identity and Access Management. - In the left-hand panel, select
Service accounts. - The service account roles are listed in the Roles in folder field.
If you do not have the Yandex Cloud CLI yet, install and initialize it.
-
Get the account ID:
-
Get the resource ID or name.
-
View the roles assigned for the resource:
yc <service_name> <resource_category> list-access-bindings <resource_name_or_ID>Where:
<service_name>: Name of the service the resource belongs to, e.g.,resource-manager.<resource_category>: Resource category, e.g.,folder.<resource_name_or_ID>: Resource name or ID. You can specify the resource by name or ID.
For example, you can view the roles and the assignees for the
defaultfolder:yc resource-manager folder list-access-bindings defaultResult:
+---------------------+----------------+----------------------+ | ROLE ID | SUBJECT TYPE | SUBJECT ID | +---------------------+----------------+----------------------+ | editor | serviceAccount | ajepg0mjas06******** | | viewer | userAccount | aje6o61dvog2******** | +---------------------+----------------+----------------------+In the server response, find all rows where the subject contains the account ID, and the
All usersandAll authenticated userspublic groups are specified as the subject. -
Repeat the previous two steps for all parent resources.
-
Get the account ID:
-
Get the resource ID or name.
-
View the roles and assignees for the resource using the
listAccessBindingsREST API method. For example, to view roles for theb1gvmob95yys********folder:export FOLDER_ID=b1gvmob95yys******** export IAM_TOKEN=CggaATEVAgA... curl \ --header "Authorization: Bearer ${IAM_TOKEN}" \ "https://resource-manager.api.cloud.yandex.net/resource-manager/v1/folders/${FOLDER_ID}:listAccessBindings"Result:
{ "accessBindings": [ { "subject": { "id": "ajei8n54hmfh********", "type": "userAccount" }, "roleId": "editor" } ] }In the server response, find all rows where the subject contains the account ID, and the
All usersandAll authenticated userspublic groups are specified as the subject. -
Repeat the previous two steps for all parent resources.