Yandex Identity and Access Management release notes
August 2026
Identity and Access Management updates
- The
compute.editorandcompute.adminroles in Compute Cloud, as well as thebaremetal.editorandbaremetal.adminin BareMetal now include permissions of thebackup.userrole.
New roles
Yandex Cloud Billing
billing.usagerecords.admin
To use the billing.usagerecords.admin role, you need to assign it for an organization, cloud, or folder. It enables viewing resource consumption details without access to the billing account.
Yandex Managed Service for ClickHouse®
managed-clickhouse.clusters.connector
The managed-clickhouse.clusters.connector role enables Yandex Cloud users to connect to databases in ClickHouse® clusters via Yandex Identity and Access Management.
Yandex Managed Service for GitLab
gitlab.backupAdmin
The gitlab.backupAdmin role enables completely managing Managed Service for GitLab instance backups. Users with this role can create and delete backups, restore instances from them, as well as download backups, including GitLab secrets from such backups.
This role includes the gitlab.backupRestorer and gitlab.backupDownloader permissions.
gitlab.backupDownloader
The gitlab.backupDownloader role enables downloading Managed Service for GitLab instance backups, including GitLab secrets from such backups.
gitlab.backupRestorer
The gitlab.backupRestorer role enables restoring Managed Service for GitLab instances from backups.
July 2026
Identity and Access Management updates
- Added the ability to suspend a service account and manage its lifetime.
- Added the
resourceManager.denyFolderRemovalauthorization policy template that allows you to prohibit folder deletion. - Added the
aistudio.responses.restrictNetworkAccessauthorization policy template that allows restricting access to the Responses API in Yandex Cloud AI Studio by IP addresses and cloud networks.
New roles
Yandex Cloud Registry
cloud-registry.artifacts.scanner
The cloud-registry.artifacts.scanner role enables scanning registry artifacts for vulnerabilities, pulling artifacts, as well as viewing info on artifacts and registries, on the access permissions granted for registries, and on the Cloud Registry quotas.
Users with this role can:
- Scan registry artifacts for vulnerabilities.
- View vulnerability scanning results.
- View info on artifacts and pull them.
- View info on registries.
- View registry access policies.
- View info on the access permissions granted for registries, folders within registries, and artifacts.
- View info on registry lifecycle policies.
- View info on the Cloud Registry quotas.
- View info on the relevant cloud and folder.
This role includes the cloud-registry.viewer permissions.
Yandex Security Deck
threat-detector.admin
The threat-detector.admin role enables viewing info on Threat Detector security management rules, creating exceptions from such rules, as well as viewing info on access permissions granted for Threat Detector and modifying them.
This role includes the threat-detector.editor permissions.
threat-detector.auditor
The threat-detector.auditor role enables viewing info on Threat Detector security management rules and access permissions granted for Threat Detector.
threat-detector.editor
The threat-detector.editor role enables viewing info on access permissions granted for Threat Detector and its security management rules, as well as creating exceptions from such rules.
This role includes the threat-detector.viewer permissions.
threat-detector.viewer
The threat-detector.viewer role enables viewing info on Threat Detector security management rules and access permissions granted for Threat Detector.
This role includes the threat-detector.auditor permissions.
threat-detector.worker
The threat-detector.worker enables viewing logs registered in the customer's infrastructure using Yandex Audit Trails.
The role is issued to the service account to perform Threat Detector-driven security management and extends to an organization, cloud, or folder. This service account should be specified when creating the workspace.
vulnerability-manager.admin
The vulnerability-manager.admin role enables viewing info on Vulnerability Management scan jobs, running and modifying them, as well as viewing their results.
This role includes the vulnerability-manager.editor permissions.
vulnerability-manager.auditor
The vulnerability-manager.auditor role enables viewing Vulnerability Management scan results.
vulnerability-manager.editor
The vulnerability-manager.editor enables viewing info on Vulnerability Management scan jobs, running and modifying them, as well as viewing their results.
This role includes the vulnerability-manager.viewer permissions.
vulnerability-manager.viewer
The vulnerability-manager.viewer enables viewing info on Vulnerability Management scan jobs and their results.
This role includes the vulnerability-manager.auditor permissions.
Yandex StoreDoc
managed-mongodb.clusters.connector
The managed-mongodb.clusters.connector role enables Yandex Cloud users to connect to databases in Yandex StoreDoc clusters via Yandex Identity and Access Management.
June 2026
Identity and Access Management updates
- Added the
resourceManager.denyCloudRemovalaccess policy template that allows you to prohibit cloud deletion.
New roles
Apache Hive™ Metastore
managed-metastore.maintenanceTask.editor
The managed-metastore.maintenanceTask.editor role enables viewing info on maintenance tasks for Apache Hive™ Metastore clusters and modifying such tasks, as well as viewing info on Apache Hive™ Metastore clusters, on access permissions granted for them, and on the quotas for Yandex Cloud managed DB services.
This role includes the managed-metastore.maintenanceTask.viewer permissions.
managed-metastore.maintenanceTask.viewer
The managed-metastore.maintenanceTask.viewer role enables viewing info on Apache Hive™ Metastore clusters, access permissions granted for them, their maintenance tasks, and on the quotas for Yandex Cloud managed DB services.
Yandex DataLens
datalens.collections.creator
The datalens.collections.creator is assigned for a collection and enables viewing it as well as creating objects within it without access to any other objects residing within the collection. In the DataLens UI, this role is referred to as Creator in collection. We recommend assigning this role only via the DataLens UI.
This role includes the datalens.collections.visitor permissions.
datalens.collections.entryBindingCreator
The datalens.collections.entryBindingCreator role is assigned for a collection and enables re-using common objects from it, both with and without delegation of access permissions. In the DataLens UI, this role is referred to as Bindings with delegation. We recommend assigning this role only via the DataLens UI.
This role includes the datalens.sharedEntries.entryBindingCreator permissions.
datalens.collections.limitedEntryBindingCreator
The datalens.collections.limitedEntryBindingCreator role is assigned for a collection and enables re-using common objects from it without delegation of access permissions. In the DataLens UI, this role is referred to as Bindings without delegation. We recommend assigning this role only via the DataLens UI.
This role includes the datalens.sharedEntries.limitedEntryBindingCreator permissions.
datalens.collections.visitor
The datalens.collections.visitor is assigned for a collection and enables viewing info on it without access to its nested objects. In the DataLens UI, this role is referred to as Visitor of collection. We recommend assigning this role only via the DataLens UI.
datalens.sharedEntries.admin
The datalens.sharedEntries.admin role is assigned for a common object and enables viewing it and entirely managing it, including editing, moving, deleting, and configuring its access permissions. In the DataLens UI, this role is referred to as Admin. We recommend assigning this role only via the DataLens UI.
This role includes the datalens.sharedEntries.editor and datalens.sharedEntries.entryBindingCreator permissions.
datalens.sharedEntries.editor
The datalens.sharedEntries.editor role is assigned for a common object and enables editing and viewing it, as well as viewing its access permissions. In the DataLens UI, this role is referred to as Editor. We recommend assigning this role only via the DataLens UI.
This role includes the datalens.sharedEntries.viewer permissions.
datalens.sharedEntries.entryBindingCreator
The datalens.sharedEntries.entryBindingCreator role is assigned for a common object and enables re-using it in workbooks, both with and without delegation of access permissions. In the DataLens UI, this role is referred to as Bindings with delegation. We recommend assigning this role only via the DataLens UI.
This role includes the datalens.sharedEntries.limitedEntryBindingCreator permissions.
datalens.sharedEntries.limitedEntryBindingCreator
The datalens.sharedEntries.limitedEntryBindingCreator role is assigned for a common object and enables re-using it in workbooks without delegation of access permissions. In the DataLens UI, this role is referred to as Bindings without delegation. We recommend assigning this role only via the DataLens UI.
datalens.sharedEntries.limitedViewer
The datalens.sharedEntries.limitedViewer role is assigned for a common object and enables viewing its charts and the dashboards that use it, without direct access to the common object itself. In the DataLens UI, this role is referred to as Limited viewer. We recommend assigning this role only via the DataLens UI.
datalens.sharedEntries.viewer
The datalens.sharedEntries.viewer role is assigned for a common object and enables viewing it and its access permissions. In the DataLens UI, this role is referred to as Viewer. We recommend assigning this role only via the DataLens UI.
This role includes the datalens.sharedEntries.limitedViewer permissions.
May 2026
Identity and Access Management updates
- Added new API key scopes: to work with Yandex Cloud Registry and to run workflows in Workflows.
- Updated access policy templates: replaced the
serverless.restrictPrivateNetworkInvocationandserverless.restrictPublicInvocationshared templates with separate templates for Yandex Serverless Containers, Yandex Cloud Functions, MCP Hub, and Workflows.
New roles
Yandex Cloud Apps
cloudapps.admin
The cloudapps.admin role enables viewing info on installed Cloud Apps, as well as creating, modifying, and deleting them.
This role includes the cloudapps.editor permissions.
cloudapps.auditor
The cloudapps.auditor role enables viewing the metadata of installed Cloud Apps.
cloudapps.editor
The cloudapps.editor role enables viewing info on installed Cloud Apps, as well as creating, modifying, and deleting them.
This role includes the cloudapps.viewer permissions.
cloudapps.viewer
The cloudapps.viewer role enables viewing info on installed Cloud Apps.
This role includes the cloudapps.auditor permissions.
Yandex Cloud Marketplace
marketplace.productInstances.admin
The marketplace.productInstances.admin role enables managing installed Marketplace products and access to them.
Users with this role can:
- View info on installed Marketplace products.
- View info on access permissions granted for installed Marketplace products and modify such permissions.
- Create Marketplace products, modify their metadata, as well as activate and deactivate Marketplace products.
- View info on the relevant folder.
This role includes the marketplace.productInstances.editor permissions.
marketplace.productInstances.auditor
The marketplace.productInstances.auditor role enables viewing info on installed Marketplace products and access permissions granted for them, as well as viewing folder metadata.
marketplace.productInstances.editor
The marketplace.productInstances.editor role enables managing installed Marketplace products.
Users with this role can:
- View info on installed Marketplace products and access permissions granted for them.
- Create Marketplace products, modify their metadata, as well as activate and deactivate Marketplace products.
- View info on the relevant folder.
This role includes the marketplace.productInstances.user permissions.
marketplace.productInstances.saasSupervisor
The marketplace.productInstances.saasSupervisor role enables viewing info on installed Marketplace SaaS products and activating such products.
marketplace.productInstances.user
The marketplace.productInstances.user role enables viewing info on installed Marketplace products, activating and deactivating them, as well as viewing info on access permissions granted for them and on the relevant folder.
This role includes the marketplace.productInstances.viewer permissions.
marketplace.productInstances.viewer
The marketplace.productInstances.viewer role enables enables viewing info on installed Marketplace products, access permissions granted for them, and on the relevant folder.
This role includes the marketplace.productInstances.auditor permissions.
Yandex Cloud Postbox
postbox.messages.reader
The postbox.messages.reader role enables viewing info on sent emails in the Sent emails section of the management console
postbox.statistics.reader
The postbox.statistics.reader role enables viewing statistics on sent emails in the Statistics section of the management console
Yandex Identity and Access Management
iam.serviceAccounts.ephemeralAccessKeyAdmin
The iam.serviceAccounts.ephemeralAccessKeyAdmin role enables creating ephemeral access keys for service accounts.
Yandex Managed Service for Valkey™
managed-redis.clusters.connector
The managed-redis.clusters.connector role enables Yandex Cloud users to connect to databases in Valkey™ clusters via Yandex Identity and Access Management.
Yandex SIEM
ycem.executor
The ycem.executor role enables managing queries, investigations, datasets, and correlation rules.
Users with this role can:
- View info on investigations, as well as create, update, delete, and conduct them.
- View info on datasets and their contents, as well as create, update, and delete datasets.
- View info on queries, as well as create, update, delete, and run them.
- View info on correlation rules and update them.
- View info on exceptions and the list of queries that use these exceptions.
- View info on Yandex SIEM instances and their components.
This role includes the ycem.inspector permissions.
ycem.inspector
The ycem.inspector role enables managing queries, investigations, and datasets.
Users with this role can:
- View info on investigations, as well as create, update, delete, and conduct them.
- View info on datasets, as well as create, update, and delete them.
- View info on queries, as well as create, update, delete, and run them.
- View info on Yandex SIEM instances.
April 2026
Identity and Access Management updates
- Added the
MASKED KEYfield to display the last six characters of the secret part of the key in the API key list.
New roles
Yandex Cloud Notification Service
notifications.admin
The notifications.admin role enables managing all notification channels and topics, as well as sending notifications to all channels and topics.
Users with this role can:
- View info on topics and create, modify, and delete them.
- View info on subscriptions in topics, as well as create and delete them.
- View info on mobile push notification channels and their endpoints, as well as create, modify, and delete such channels and endpoints.
- View info on browser push notification channels and their endpoints, as well as create, modify, and delete such channels and endpoints.
- View info on text message (SMS) notification channels, as well as create, modify, and delete them.
- View info on text message (SMS) templates and test phone numbers, as well as modify them.
- Send notifications to all topics and channels.
- View info on Cloud Notification Service quotas.
This role includes the notifications.editor permissions.
notifications.auditor
The notifications.auditor role enables viewing metadata for all notification channels, topic metadata, and info on Cloud Notification Service quotas.
notifications.editor
The notifications.editor role enables managing all notification channels and topics, as well as sending notifications to all channels and topics.
Users with this role can:
- View info on topics and create, modify, and delete them.
- View info on subscriptions in topics, as well as create and delete them.
- View info on mobile push notification channels and their endpoints, as well as create, modify, and delete such channels and endpoints.
- View info on browser push notification channels and their endpoints, as well as create, modify, and delete such channels and endpoints.
- View info on text message (SMS) notification channels, as well as create, modify, and delete them.
- View info on text message (SMS) templates and test phone numbers, as well as modify them.
- Send notifications to all topics and channels.
- View info on Cloud Notification Service quotas.
This role includes the notifications.viewer and notifications.publisher permissions.
notifications.publisher
The notifications.publisher role enables sending notifications to all channels and topics.
notifications.viewer
The notifications.viewer role enables viewing info on topics, notification channels, and Cloud Notification Service quotas.
Users with this role can:
- View info on topics and subscriptions in them.
- View info on mobile push notification channels and their endpoints.
- View info on browser push notification channels and their endpoints.
- View info on text message (SMS) channels, SMS templates, and test phone numbers.
- View info on Cloud Notification Service quotas.
This role includes the notifications.auditor permissions.
Yandex DataLens
datalens.metaReader
The datalens.metaReader role enables executing requests from the Audit
You can get the following entities:
- Connection:
getConnectionmethod - Dataset:
getDatasetmethod - Wizard chart:
getWizardChartmethod - Editor chart:
getEditorChartmethod - QL chart:
getQLChartmethod - Dashboard:
getDashboardmethod - Report:
getReportmethod - Collection:
getCollectionmethod - Collection information:
getCollectionContentmethod - Workbook:
getWorkbookmethod - Workbook entries:
getWorkbookEntriesmethod - Entries:
getEntriesmethod - Entry relations:
getEntriesRelationsmethod
Warning
Getting entities will only work if the request includes the x-dl-audit-mode heading with the true value.
Yandex Cloud DNS
dns.firewallEditor
The dns.firewallEditor role enables managing DNS firewalls and using clouds, folders, and cloud networks as resources for them.
Users with this role can:
- View info on DNS firewalls and access permissions granted for them.
- Create, modify, and delete DNS firewalls.
- Use clouds, folders, and cloud networks as resources for DNS firewalls.
- View info on DNS zones and access permissions granted for them.
- View info on Cloud DNS quotas.
- View info on the relevant folder.
This role includes the dns.firewallUser permissions.
dns.firewallUser
The dns.firewallUser role enables using clouds, folders, and cloud networks as resources for DNS firewalls, as well as viewing info on Cloud DNS resources and quotas.
Users with this role can:
- View info on DNS firewalls and access permissions granted for them.
- Use clouds, folders, and cloud networks as resources for DNS firewalls.
- View info on DNS zones and access permissions granted for them.
- View info on Cloud DNS quotas.
- View info on the relevant folder.
This role includes the dns.auditor permissions.
Yandex Identity Hub
organization-manager.groups.viewer
The organization-manager.groups.viewer role enables viewing info on user groups and access permissions granted for them, as well as viewing the list of users and service accounts that are members of groups.
Yandex Managed Service for Kubernetes
k8s.cluster-api.admin
Users with the k8s.cluster-api.admin role get the yc:k8s-core-admin group and the admin role in Kubernetes RBAC.
Managed databases
mdb.maintenanceTask.editor
The mdb.maintenanceTask.editor role enables managing maintenance tasks for managed database clusters.
Users with this role can view information on maintenance tasks for managed database clusters and modify such tasks, view information on managed database clusters and access permissions granted for them, on cluster hosts and backups, as well as on service quotas and resource operations.
This role includes the mdb.maintenanceTask.viewer, managed-clickhouse.maintenanceTask.editor, managed-greenplum.maintenanceTask.editor, managed-kafka.maintenanceTask.editor, managed-mongodb.maintenanceTask.editor, managed-mysql.maintenanceTask.editor, managed-opensearch.maintenanceTask.editor, managed-postgresql.maintenanceTask.editor, managed-redis.maintenanceTask.editor, and managed-spqr.maintenanceTask.editor permissions.
mdb.maintenanceTask.viewer
The mdb.maintenanceTask.viewer role grants access to information on maintenance tasks for managed database clusters.
Users with this role can view information on managed database clusters, their maintenance tasks, and access permissions granted for them, on hosts and cluster backups, as well as on service quotas and resource operations.
This role includes the mdb.auditor, managed-clickhouse.maintenanceTask.viewer, managed-greenplum.maintenanceTask.viewer, managed-kafka.maintenanceTask.viewer, managed-mongodb.maintenanceTask.viewer, managed-mysql.maintenanceTask.viewer, managed-opensearch.maintenanceTask.viewer, managed-postgresql.maintenanceTask.viewer, managed-redis.maintenanceTask.viewer, and managed-spqr.maintenanceTask.viewer permissions.
mdb.switcher
The mdb.switcher role enables re-assigning the master host in managed database clusters and grants access to information on such clusters and their logs.
Users with this role can re-assign the master host in managed database clusters, view info on such clusters, their hosts, databases, and users, as well as view cluster logs, service quotas, and resource operations.
This role includes the mdb.viewer, managed-mongodb.switcher, managed-mysql.switcher, managed-postgresql.switcher, and managed-redis.switcher permissions.
March 2026
New roles
Yandex Cloud AI Studio
ai.guardrails.admin
The ai.guardrails.admin role enables viewing info on guardrails
This role includes the ai.guardrails.editor permissions.
ai.guardrails.auditor
The ai.guardrails.auditor role enables viewing metadata on guardrails
ai.guardrails.editor
The ai.guardrails.editor role enables viewing info on guardrails
This role includes the ai.guardrails.viewer and ai.guardrails.user permissions.
ai.guardrails.user
The ai.guardrails.user role enables applying guardrails
ai.guardrails.viewer
The ai.guardrails.viewer role enables viewing info on guardrails
This role includes the ai.guardrails.auditor permissions.
Yandex MPP Analytics for PostgreSQL
managed-greenplum.maintenanceTask.editor
The managed-greenplum.maintenanceTask.editor role enables viewing info on maintenance tasks for Yandex MPP Analytics for PostgreSQL clusters and modifying such tasks, as well as viewing info on Yandex MPP Analytics for PostgreSQL clusters and access permissions granted for them, on hosts and cluster backups, and on quotas and resource operations for Yandex MPP Analytics for PostgreSQL.
This role includes the managed-greenplum.maintenanceTask.viewer permissions.
managed-greenplum.maintenanceTask.viewer
The managed-greenplum.maintenanceTask.viewer role enables viewing info on Yandex MPP Analytics for PostgreSQL clusters, their maintenance tasks, and access permissions granted for them, on hosts and cluster backups, and on quotas and resource operations for Yandex MPP Analytics for PostgreSQL.
This role includes the managed-greenplum.auditor permissions.
managed-greenplum.user
The managed-greenplum.user role enables using Yandex MPP Analytics for PostgreSQL clusters.
Yandex Managed Service for Apache Airflow™
managed-airflow.maintenanceTask.editor
The managed-airflow.maintenanceTask.editor role enables viewing info on maintenance tasks for Apache Airflow™ clusters and modifying such tasks, as well as viewing info on Apache Airflow™ clusters, access permissions granted for them, and on quotas for Managed Service for Apache Airflow™.
This role includes the managed-airflow.maintenanceTask.viewer permissions.
managed-airflow.maintenanceTask.viewer
The managed-airflow.maintenanceTask.viewer role enables viewing info on Apache Airflow™ clusters, access permissions granted for them, and their maintenance tasks, as well as on quotas for Managed Service for Apache Airflow™.
This role includes the managed-airflow.auditor permissions.
Yandex Managed Service for Apache Kafka®
managed-kafka.maintenanceTask.editor
The managed-kafka.maintenanceTask.editor role enables viewing info on maintenance tasks for Apache Kafka® clusters and modifying such tasks, as well as viewing info on Apache Kafka® clusters, access permissions granted for them, and on quotas and resource operations for Managed Service for Apache Kafka®.
This role includes the managed-kafka.maintenanceTask.viewer permissions.
managed-kafka.maintenanceTask.viewer
The managed-kafka.maintenanceTask.viewer role enables viewing info on Apache Kafka® clusters, access permissions granted for them, their maintenance tasks, and on quotas and resource operations for Managed Service for Apache Kafka®.
This role includes the managed-kafka.auditor permissions.
managed-kafka.user
The managed-kafka.user role enables using Apache Kafka® clusters.
Yandex Managed Service for Apache Spark™
managed-spark.maintenanceTask.editor
The managed-spark.maintenanceTask.editor role enables viewing info on maintenance tasks for Apache Spark™ clusters and modifying such tasks, as well as viewing info on Apache Spark™ clusters, access permissions granted for them, and on quotas for Managed Service for Apache Spark™.
This role includes the managed-spark.maintenanceTask.viewer permissions.
managed-spark.maintenanceTask.viewer
The managed-spark.maintenanceTask.viewer role enables viewing info on Apache Spark™ clusters, access permissions granted for them, their maintenance tasks, and on quotas for Managed Service for Apache Spark™.
This role includes the managed-spark.auditor permissions.
Yandex Managed Service for ClickHouse®
managed-clickhouse.maintenanceTask.editor
The managed-clickhouse.maintenanceTask.editor role enables viewing info on maintenance tasks for ClickHouse® clusters and modifying such tasks, as well as viewing info on ClickHouse® clusters, access permissions granted for them, and on quotas and resource operations for Managed Service for ClickHouse®.
This role includes the managed-clickhouse.maintenanceTask.viewer permissions.
managed-clickhouse.maintenanceTask.viewer
The managed-clickhouse.maintenanceTask.viewer role enables viewing info on ClickHouse® clusters, their maintenance tasks, access permissions granted for them, and on quotas and resource operations for Managed Service for ClickHouse®.
This role includes the managed-clickhouse.auditor permissions.
managed-clickhouse.user
The managed-clickhouse.user role enables using ClickHouse® clusters.
Yandex Managed Service for MySQL®
managed-mysql.maintenanceTask.editor
The managed-mysql.maintenanceTask.editor role enables viewing info on maintenance tasks for MySQL® clusters and modifying such tasks, as well as viewing info on MySQL® clusters and access permissions granted for them, on hosts and cluster backups, and on quotas and resource operations for Yandex Managed Service for MySQL®.
This role includes the managed-mysql.maintenanceTask.viewer permissions.
managed-mysql.maintenanceTask.viewer
The managed-mysql.maintenanceTask.viewer role enables viewing info on MySQL® clusters, their maintenance tasks, and access permissions granted for them, on hosts and cluster backups, and on quotas and resource operations for Yandex Managed Service for MySQL®.
This role includes the managed-mysql.auditor permissions.
managed-mysql.switcher
The managed-mysql.switcher role enables re-assigning the master host in MySQL® clusters, viewing info on MySQL® clusters, hosts, databases, and users, as well as viewing cluster logs, quotas, and resource operations.
Users with this role can:
- Re-assign the master host in MySQL® clusters.
- View info on MySQL® clusters and access permissions granted for them.
- View info on maintenance tasks for MySQL® clusters.
- View info on MySQL® cluster hosts.
- View info on MySQL® databases.
- View info on MySQL® users.
- View info on MySQL® cluster backups.
- View info on MySQL® alerts.
- View MySQL® cluster logs.
- View info on the results of MySQL® cluster performance diagnostics.
- View info on quotas for Managed Service for MySQL®.
- View info on resource operations for Managed Service for MySQL®.
This role includes the managed-mysql.viewer permissions.
managed-mysql.user
The managed-mysql.user role enables using MySQL® clusters.
Yandex Managed Service for OpenSearch
managed-opensearch.maintenanceTask.editor
The managed-opensearch.maintenanceTask.editor role enables viewing info on maintenance tasks for OpenSearch clusters and modifying such tasks, as well as viewing info on OpenSearch clusters, access permissions granted for them, and on quotas and resource operations for Managed Service for OpenSearch.
This role includes the managed-opensearch.maintenanceTask.viewer permissions.
managed-opensearch.maintenanceTask.viewer
The managed-opensearch.maintenanceTask.viewer role enables viewing info on OpenSearch clusters, access permissions granted for them, their maintenance tasks, and on quotas and resource operations for Managed Service for OpenSearch.
This role includes the managed-opensearch.auditor permissions.
managed-opensearch.user
The managed-opensearch.user role enables using OpenSearch clusters.
Yandex Managed Service for PostgreSQL
managed-postgresql.maintenanceTask.editor
The managed-postgresql.maintenanceTask.editor role enables viewing info on maintenance tasks for PostgreSQL clusters and modifying such tasks, as well as viewing info on PostgreSQL clusters and access permissions granted for them, on hosts and cluster backups, and on quotas and resource operations for Managed Service for PostgreSQL.
This role includes the managed-postgresql.maintenanceTask.viewer permissions.
managed-postgresql.maintenanceTask.viewer
The managed-postgresql.maintenanceTask.viewer role enables viewing info on PostgreSQL clusters, their maintenance tasks, and access permissions granted for them, on hosts and cluster backups, and on quotas and resource operations for Managed Service for PostgreSQL.
This role includes the managed-postgresql.auditor permissions.
managed-postgresql.switcher
The managed-postgresql.switcher role enables re-assigning the master host in PostgreSQL clusters, viewing info on PostgreSQL clusters, hosts, databases, and users, as well as viewing cluster logs, quotas, and resource operations.
Users with this role can:
- Re-assign the master host in PostgreSQL clusters.
- View info on PostgreSQL clusters and access permissions granted for them.
- View info on maintenance tasks for PostgreSQL clusters.
- View info on PostgreSQL cluster hosts.
- View info on PostgreSQL databases.
- View info on PostgreSQL users.
- View info on PostgreSQL cluster backups.
- View info on PostgreSQL alerts.
- View PostgreSQL cluster logs.
- View info on the results of PostgreSQL cluster performance diagnostics.
- View info on quotas for Managed Service for PostgreSQL.
- View info on resource operations for Managed Service for PostgreSQL.
This role includes the managed-postgresql.viewer permissions.
managed-postgresql.user
The managed-postgresql.user role enables using PostgreSQL clusters.
Yandex Managed Service for Sharded PostgreSQL
managed-spqr.maintenanceTask.editor
The managed-spqr.maintenanceTask.editor role enables viewing info on maintenance tasks for Sharded PostgreSQL clusters and modifying such tasks, as well as viewing info on Sharded PostgreSQL clusters, access permissions granted for them, cluster hosts, quotas, and resource operations for Managed Service for Sharded PostgreSQL.
This role includes the managed-spqr.maintenanceTask.viewer permissions.
managed-spqr.maintenanceTask.viewer
The managed-spqr.maintenanceTask.viewer role enables viewing info on Sharded PostgreSQL clusters, their maintenance tasks, access permissions granted for them, hosts, and on quotas and resource operations for Managed Service for Sharded PostgreSQL.
This role includes the managed-spqr.auditor permissions.
Yandex Managed Service for Trino
managed-trino.maintenanceTask.editor
The managed-trino.maintenanceTask.editor role enables viewing info on maintenance tasks for Trino clusters and modifying such tasks, as well as viewing info on Trino clusters, access permissions granted for them, and on quotas for Managed Service for Trino.
This role includes the managed-trino.maintenanceTask.viewer permissions.
managed-trino.maintenanceTask.viewer
The managed-trino.maintenanceTask.viewer role enables viewing info on Trino clusters, access permissions granted for them, their maintenance tasks, and on quotas for Managed Service for Trino.
This role includes the managed-trino.auditor permissions.
Yandex Managed Service for Valkey™
managed-redis.maintenanceTask.editor
The managed-redis.maintenanceTask.editor role enables viewing info on maintenance tasks for Valkey™ clusters and modifying such tasks, as well as viewing info on Valkey™ clusters and access permissions granted for them, on hosts and cluster backups, and on quotas and resource operations for Yandex Managed Service for Valkey™.
This role includes the managed-redis.maintenanceTask.viewer permissions.
managed-redis.maintenanceTask.viewer
The managed-redis.maintenanceTask.viewer role enables viewing info on Valkey™ clusters, their maintenance tasks, and access permissions granted for them, on hosts and cluster backups, and on quotas and resource operations for Yandex Managed Service for Valkey™.
This role includes the managed-redis.auditor permissions.
managed-redis.switcher
The managed-redis.switcher enables re-assigning the master host in Valkey™ clusters and viewing info on Valkey™ hosts, clusters and their logs, as well as on quotas and resource operations.
Users with this role can:
- Re-assign the master host in Valkey™ clusters.
- View info on Valkey™ clusters and access permissions granted for them.
- View info on maintenance tasks for Valkey™ clusters.
- View info on Valkey™ cluster hosts.
- View info on Valkey™ cluster shards.
- View info on Valkey™ users.
- View info on Valkey™ cluster backups.
- View info on Valkey™ alerts.
- View Valkey™ cluster logs.
- View info on quotas for Yandex Managed Service for Valkey™.
- View info on resource operations for Yandex Managed Service for Valkey™.
This role includes the managed-redis.viewer permissions.
managed-redis.user
The managed-redis.user role enables using Valkey™ clusters.
Yandex StoreDoc
managed-mongodb.maintenanceTask.editor
The managed-mongodb.maintenanceTask.editor role enables viewing info on maintenance tasks for Yandex StoreDoc clusters and modifying such tasks, as well as viewing info on Yandex StoreDoc clusters and access permissions granted for them, on hosts and cluster backups, and on quotas and resource operations.
This role includes the managed-mongodb.maintenanceTask.viewer permissions.
managed-mongodb.maintenanceTask.viewer
The managed-mongodb.maintenanceTask.viewer role enables viewing info on Yandex StoreDoc clusters, their maintenance tasks, and access permissions granted for them, on hosts and cluster backups, and on quotas and resource operations.
This role includes the managed-mongodb.auditor permissions.
managed-mongodb.switcher
The managed-mongodb.switcher role enables re-assigning the master host in Yandex StoreDoc clusters and viewing info on Yandex StoreDoc clusters, hosts, shards, databases, users, cluster logs, quotas, and resource operations.
Users with this role can:
- Re-assign the master host in Yandex StoreDoc clusters.
- View info on Yandex StoreDoc clusters and access permissions granted for them.
- View info on maintenance tasks for Yandex StoreDoc clusters and modify such tasks.
- View info on Yandex StoreDoc cluster hosts.
- View info on Yandex StoreDoc cluster shards.
- View info on Yandex StoreDoc databases.
- View info on Yandex StoreDoc users.
- View info on Yandex StoreDoc cluster backups.
- View info on Yandex StoreDoc alerts.
- View Yandex StoreDoc cluster logs.
- View info on the results of Yandex StoreDoc cluster performance diagnostics.
- View info on Yandex StoreDoc quotas.
- View info on resource operations for Yandex StoreDoc.
This role includes the managed-mongodb.viewer permissions.
managed-mongodb.user
The managed-mongodb.user role enables using Yandex StoreDoc clusters.
February 2026
Identity and Access Management updates
- Added access policies.
New roles
Yandex Cloud Backup
backup.auditor
The backup.auditor role enables viewing information on target resources connected to Cloud Backup, on backup policies and service quotas, as well as on the relevant cloud and folder.
Users with this role can:
- View info on the connected backup providers.
- View info on backup policies as well as on resources linked to such policies.
- View info on access permissions granted for backup policies.
- View info on resources connected to Cloud Backup.
- View info on Cloud Backup quotas.
- View info on the relevant cloud.
- View info on the relevant folder and its statistics.
To assign the backup.auditor role, you need the admin role for the cloud or backup.admin for the folder.
December 2025
Identity and Access Management updates
- Added ephemeral keys.
- In the
yandex_iam_oauth_clientTerraform resource, fixed the comparison between thescopesandredirect_urisfields: now their type issetto avoid comparison conflicts.
New roles
Yandex Cloud Backup
backup.user
The backup.user role enables connecting backup providers, connecting target resources to Cloud Backup, linking backup policies to target resources and unlinking them, as well as viewing info on Cloud Backup resources and quotas and on the relevant cloud and folder.
Users with this role can:
- View info on connected backup providers, as well as connect providers available in Cloud Backup.
- View info on resources connected to Cloud Backup, as well as connect and disconnect resources to and from it.
- View info on backup policies as well as on resources linked to such policies.
- Link backup policies to target resources and unlink them.
- View info on access permissions granted for backup policies.
- View info on Cloud Backup quotas.
- View info on the relevant cloud.
- View info on the relevant folder and its statistics.
This role includes the backup.auditor permissions.
To assign the backup.user role, you need the admin role for the cloud or backup.admin for the folder.
Yandex Managed Service for MySQL®
managed-mysql.clusters.connector
The managed-mysql.clusters.connector role enables Yandex Cloud users to connect to databases in MySQL® clusters via Yandex Identity and Access Management.
Yandex Managed Service for PostgreSQL
managed-postgresql.clusters.connector
The managed-postgresql.clusters.connector role enables Yandex Cloud users to connect to databases in PostgreSQL clusters via Yandex Identity and Access Management.
Yandex Monium
monium.admin
The monium.admin role enables managing Monium resources, read and write all types of telemetry, and manage projects and access to them.
Users with this role can:
- View info on projects and create, set up, and delete them.
- View info on access permissions granted for projects and modify such permissions.
- Read and write all types of Monium telemetry, such as metrics, logs, and distributed tracing.
- View dashboards and their widgets, as well as create, modify, and delete dashboards.
- View the set-up context links on dashboard charts, as well as create, edit, and delete such links.
- View the list of the set-up quick links and info on them in the project menu, as well as create, modify, and delete such links.
- View info on shards, clusters, services and their quotas, as well as create, modify, and delete shards.
- View the list of alerts, their settings, and trigger history, as well as create, modify, and delete alerts.
- View the set-up service level objectives (SLOs), as well as create, modify, and delete SLOs.
- View the list of alert notification channels and info on them, as well as create, modify, and delete such channels.
- View the list and settings of alert escalation policies, as well as create, modify, and delete such policies.
- View info on alert notifications and escalations, as well as create, modify, and delete escalations.
- View, create, edit, and delete mutes, i.e., rules for temporarily disabling alert notifications.
- View, add new, edit, and delete the existing labels to log errors.
- View info on the Yandex Managed Service for Prometheus® rules, as well as create, modify, and delete such rules.
- View info on the relevant folder.
This role includes the monium.editor permissions.
monium.editor
The monium.editor role enables managing Monium resources, as well as reading and writing all types of telemetry.
Users with this role can:
- View info on projects and access permissions assigned to them, as well as set up projects.
- Read and write all types of Monium telemetry, such as metrics, logs, and distributed tracing.
- View dashboards and their widgets, as well as create, modify, and delete dashboards.
- View the set-up context links on dashboard charts, as well as create, edit, and delete such links.
- View the list of the set-up quick links and info on them in the project menu, as well as create, modify, and delete such links.
- View info on shards, clusters, services and their quotas, as well as create, modify, and delete shards.
- View the list of alerts, their settings, and trigger history, as well as create, modify, and delete alerts.
- View the set-up service level objectives (SLOs), as well as create, modify, and delete SLOs.
- View the list of alert notification channels and info on them, as well as create, modify, and delete such channels.
- View the list and settings of alert escalation policies, as well as create, modify, and delete such policies.
- View info on alert notifications and escalations, as well as create, modify, and delete escalations.
- View, create, edit, and delete mutes, i.e., rules for temporarily disabling alert notifications.
- View, add new, edit, and delete the existing labels to log errors.
- View info on the Yandex Managed Service for Prometheus® rules, as well as create, modify, and delete such rules.
- View info on the relevant folder.
This role includes the monium.viewer, monium.telemetry.writer, monium.dashboards.editor, monium.shards.editor, monium.contextLinks.editor, monium.quickLinks.editor, monium.alerts.editor, monium.serviceLevelObjectives.editor, monium.channels.editor, monium.escalationPolicies.editor, monium.escalations.editor, monium.mutes.editor, and monium.logErrorLabels.editor permissions.
monium.viewer
The monium.viewer role enables viewing information on Monium resources. It also enables reading all types of telemetry data.
Users with this role can:
- View info on projects and access permissions assigned to them.
- Read all types of Monium telemetry, such as metrics, logs, and distributed tracing.
- View dashboards and their widgets.
- View the set-up context links on dashboard charts.
- View the list of the set-up quick links and info on them in the project menu.
- View info on shards, clusters, services and their quotas.
- View the list of alerts, their settings, and trigger history.
- View the set-up service level objectives (SLOs).
- View the list of alert notification channels and info on them.
- View the list and settings of alert escalation policies.
- View info on alert notifications and escalations.
- View mutes, i.e., rules for temporarily disabling alert notifications.
- View labels assigned to log errors.
- View info on the Yandex Managed Service for Prometheus® rules.
- View info on the relevant folder.
This role includes the monium.auditor and monium.telemetry.reader permissions.
monium.auditor
The monium.auditor role enables viewing information on Monium resources. However, it does not allow reading the telemetry data.
Users with this role can:
- View info on projects and access permissions assigned to them.
- View dashboards and their widgets.
- View the set-up context links on dashboard charts.
- View the list of the set-up quick links and info on them in the project menu.
- View info on shards, clusters, services and their quotas.
- View the list of alerts, their settings, and trigger history.
- View the set-up service level objectives (SLOs).
- View the list of alert notification channels and info on them.
- View the list and settings of alert escalation policies.
- View info on alert notifications and escalations.
- View mutes, i.e., rules for temporarily disabling alert notifications.
- View labels assigned to log errors.
- View info on the Yandex Managed Service for Prometheus® rules.
This role includes the monium.dashboards.viewer, monium.shards.viewer, monium.contextLinks.viewer, monium.quickLinks.viewer, monium.alerts.viewer, monium.serviceLevelObjectives.viewer, monium.channels.viewer, monium.escalationPolicies.viewer, monium.escalations.viewer, monium.mutes.viewer, and monium.logErrorLabels.viewer permissions.
monium.alerts.editor
The monium.alerts.editor role enables viewing the list of alerts, their settings, and trigger history, as well as creating, modifying, and deleting alerts.
This role includes the monium.alerts.viewer permissions.
monium.alerts.viewer
The monium.alerts.viewer role enables viewing the list of alerts, their settings, and trigger history.
monium.channels.editor
The monium.channels.editor role enables viewing the list of alert notification channels and info on them, as well as creating, modifying, and deleting such channels.
This role includes the monium.channels.viewer permissions.
monium.channels.viewer
The monium.channels.viewer role enables viewing the list of alert notification channels and info on them.
monium.contextLinks.editor
The monium.contextLinks.editor role enables viewing the set-up context links on dashboard charts, as well as creating, editing, and deleting such links.
This role includes the monium.contextLinks.viewer permissions.
monium.contextLinks.viewer
The monium.contextLinks.viewer role enables viewing the set-up context links on dashboard charts.
monium.dashboards.editor
The monium.dashboards.editor role enables viewing dashboards and their widgets, as well as creating, modifying, and deleting dashboards.
This role includes the monium.dashboards.viewer permissions.
monium.dashboards.viewer
The monium.dashboards.viewer role enables viewing dashboards and their widgets.
monium.escalationPolicies.editor
The monium.escalationPolicies.editor role enables viewing the list and settings of alert escalation policies, as well as creating, modifying, and deleting such policies.
This role includes the monium.escalationPolicies.viewer permissions.
monium.escalationPolicies.viewer
The monium.escalationPolicies.viewer role enables viewing the list and settings of alert escalation policies.
monium.escalations.editor
The monium.escalations.editor role enables viewing info on alert notifications and escalations, as well as creating, modifying, and deleting escalations.
This role includes the monium.escalations.viewer permissions.
monium.escalations.viewer
The monium.escalations.viewer role enables viewing info on alert notifications and escalations.
monium.logErrorLabels.editor
The monium.logErrorLabels.editor role enables viewing, adding new, editing, and deleting the existing labels to log errors.
This role includes the monium.logErrorLabels.viewer permissions.
monium.logErrorLabels.viewer
The monium.logErrorLabels.viewer role enables viewing labels assigned to log errors.
monium.logs.reader
The monium.logs.reader role enables reading logs and viewing log error stats.
monium.logs.writer
The monium.logs.writer role enables writing Monium logs.
monium.metrics.reader
The monium.metrics.reader role enables reading metrics, their values, and labels.
monium.metrics.writer
The monium.metrics.writer role enables writing metrics.
monium.mutes.editor
The monium.mutes.editor role enables viewing, creating, editing, and deleting mutes, i.e., rules for temporarily disabling alert notifications.
This role includes the monium.mutes.viewer permissions.
monium.mutes.viewer
The monium.mutes.viewer role enables viewing mutes, i.e., rules for temporarily disabling alert notifications.
monium.quickLinks.editor
The monium.quickLinks.editor role enables viewing the list of the set-up quick links and info on them in the project menu, as well as creating, modifying, and deleting such links.
This role includes the monium.quickLinks.viewer permissions.
monium.quickLinks.viewer
The monium.quickLinks.viewer role enables viewing the list of the set-up quick links and info on them in the project menu.
monium.serviceLevelObjectives.editor
The monium.serviceLevelObjectives.editor role enables viewing the set-up service level objectives (SLOs), as well as creating, modifying, and deleting SLOs.
This role includes the monium.serviceLevelObjectives.viewer permissions.
monium.serviceLevelObjectives.viewer
The monium.serviceLevelObjectives.viewer role enables viewing the set-up service level objectives (SLOs).
monium.shards.editor
The monium.shards.editor enables viewing info on shards, clusters, services and their quotas, as well as creating, modifying, and deleting shards.
This role includes the monium.shards.viewer permissions.
monium.shards.viewer
The monium.shards.viewer role enables viewing info on shards, clusters, services and their quotas.
monium.telemetry.reader
The monium.telemetry.reader role enables reading all types of Monium telemetry, such as metrics, logs, and distributed tracing.
This role includes the monium.metrics.reader, monium.logs.reader, and monium.traces.reader permissions.
monium.telemetry.writer
The monium.telemetry.writer role enables writing all types of Monium telemetry, such as metrics, logs, and distributed tracing.
This role includes the monium.metrics.writer, monium.logs.writer, and monium.traces.writer permissions.
monium.traces.reader
The monium.traces.reader role enables viewing distributed tracing data.
monium.traces.writer
The monium.traces.writer role enables writing distributed tracing data.
Yandex MPP Analytics for PostgreSQL
managed-greenplum.clusters.connector
The managed-greenplum.clusters.connector role enables Yandex Cloud users to connect to databases in Yandex MPP Analytics for PostgreSQL clusters within Yandex MPP Analytics for PostgreSQL via Yandex Identity and Access Management.
Yandex Security Deck
security-deck.alertSinks.admin
The security-deck.alertSinks.admin role enables managing alert sinks and alerts, as well as access to them.
Users with this role can:
- View info on alert sinks, as well as create, use, modify, and delete them.
- View info on access permissions granted for alert sinks and modify such permissions.
- View info on alerts, as well as create, modify, and delete them.
- View info on access permissions granted for alerts and modify such permissions.
- View additional info on alerts and their sources, the list of affected resources, and tips on resolving issues.
- View the list of comments to alerts, as well as create, modify, and delete such comments.
This role includes the security-deck.alertSinks.editor permissions.
security-deck.alertSinks.editor
The security-deck.alertSinks.editor role enables managing alert sinks, alerts, and comments in them.
Users with this role can:
- View info on alert sinks and access permissions granted for them.
- Create, use, modify, and delete alert sinks.
- View info on alerts and access permissions granted for them.
- View additional info on alerts and their sources, the list of affected resources, and tips on resolving issues.
- Create, modify, and delete alerts.
- View the list of comments to alerts, as well as create, modify, and delete such comments.
This role includes the security-deck.alertSinks.viewer and security-deck.alertSinks.user permissions.
security-deck.alertSinks.user
The security-deck.alertSinks.user role enables viewing info on alert sinks and using them.
security-deck.alertSinks.viewer
The security-deck.alertSinks.viewer role enables viewing info on alerts and alert sinks as well as on access permissions granted for them.
Users with this role can:
- View info on alert sinks and access permissions granted for them.
- View info on alerts and access permissions granted for them.
- View additional info on alerts and their sources, the list of affected resources, and tips on resolving issues.
This role includes the security-deck.alertSinks.auditor permissions.
security-deck.alertSinks.auditor
The security-deck.alertSinks.auditor role enables viewing info on alert sinks and access permissions granted for them.
November 2025
Identity and Access Management updates
- Added the ability to view a list of a subject's accesses.
New roles
Yandex Cloud Interconnect
cic.admin
The cic.admin role enables managing Cloud Interconnect resources.
Users with this role can:
- View info on trunk links, as well as create, modify, and delete them.
- View info on private connections, as well as create, modify, and delete them.
- View info on public connections, as well as create, modify, and delete them.
- View info on the points of presence.
- View info on CIC partners.
- View info on Cloud Interconnect quotas.
- View info on the relevant cloud.
- View information on the relevant folder.
This role includes the cic.editor permissions.
Yandex Cloud Router
cloud-router.admin
The cloud-router.admin role enables managing Cloud Router resources.
Users with this role can:
- View info on routing instances, as well as create, modify, and delete them.
- Add, modify, and remove cloud subnet IP prefixes in routing instances.
- View info on Cloud Router quotas.
- View info on the relevant cloud.
- View information on the relevant folder.
This role includes the cloud-router.editor permissions.
cloud-router.prefixEditor
The cloud-router.prefixEditor role enables managing cloud subnet IP prefixes in routing instances, as well as viewing info on Cloud Router resources.
Users with this role can:
- View info on the routing instances.
- Add, modify, and remove cloud subnet IP prefixes in routing instances.
- View info on Cloud Router quotas.
- View info on the relevant cloud.
- View information on the relevant folder.
This role includes the cloud-router.viewer permissions.
Yandex Identity Hub
organization-manager.idpInstances.billingAdmin
The organization-manager.idpInstances.billingAdmin role enables managing a subscription to the paid-for Yandex Identity Hub features.
Users with this role can:
- Link Yandex Identity Hub to a billing account.
- View info on a subscription to the paid-for Yandex Identity Hub features.
- View info on stats regarding the use of the quotes within a subscription to the paid-for Yandex Identity Hub features, as well as edit these quotas.
- View the list of users who employ the Yandex Identity Hub authentication quota in the current reporting period.
This role includes the organization-manager.idpInstances.billingViewer permissions.
organization-manager.idpInstances.billingViewer
The organization-manager.idpInstances.billingViewer role enables viewing the list of users who employ the Yandex Identity Hub authentication quota in the current reporting period, as well as viewing info on a subscription to the paid-for Yandex Identity Hub features and stats regarding the use of the quotas within this subscription.
October 2025
Identity and Access Management updates
- Added the ability to manage the access of services to the user's resources.
New roles
Managed databases
mdb.restorer
The mdb.restorer role enables restoring managed database clusters from backups and grants read access to such clusters and their logs.
Users with this role can restore managed database clusters from backups, read from databases, view cluster logs, and view info on clusters, their maintenance tasks, quotas, and resource operations.
This role includes the mdb.viewer, managed-opensearch.restorer, managed-mysql.restorer, managed-postgresql.restorer, managed-spqr.restorer, managed-greenplum.restorer, managed-clickhouse.restorer, managed-redis.restorer, and managed-mongodb.restorer permissions.
Yandex Identity Hub
organization-manager.groups.externalConverter
The organization-manager.groups.externalConverter role enables adding an attribute with an external group ID to Yandex Identity Hub user groups when synchronizing with user groups in Active Directory or another external source.
organization-manager.groups.externalCreator
The organization-manager.groups.externalCreator role enables creating Yandex Identity Hub user groups when synchronizing with user groups in Active Directory or another external source.
organization-manager.userpools.syncAgent
The organization-manager.userpools.syncAgent role enables synchronizing Yandex Identity Hub users and groups with users and groups in Active Directory or another external source.
Users with this role can:
- View info on sync sessions between Yandex Identity Hub Sync Agent and Yandex Identity Hub, as well as create and modify such sessions.
- View info on user pools and sync settings in user pools.
- View the list of and info on Yandex Identity Hub user groups associated with user pools through synchronization with user groups in Active Directory or another external source.
- Associate user groups with user pools through synchronization with user groups in Active Directory or another external source.
- View info on Yandex Identity Hub users, create, modify, activate, deactivate, and delete such users, as well as edit their passwords and other data.
This role includes the organization-manager.userpools.extGroupsManager permissions.
Yandex Managed Service for Apache Kafka®
managed-kafka.restorer
The managed-kafka.restorer role enables restoring Apache Kafka® clusters from backups and viewing info on such clusters, their logs, and details on quotas and resource operations for Managed Service for Apache Kafka®.
Users with this role can:
- View info on Apache Kafka® clusters and access permissions granted for them.
- Restore Apache Kafka® clusters from backups.
- View info on maintenance tasks for Apache Kafka® clusters.
- View Apache Kafka® cluster logs.
- View info on quotas for Managed Service for Apache Kafka®.
- View info on resource operations for Managed Service for Apache Kafka®.
This role includes the managed-kafka.viewer permissions.
Yandex Managed Service for ClickHouse®
managed-clickhouse.restorer
The managed-clickhouse.restorer role enables restoring ClickHouse® clusters from backups and viewing info on such clusters, their logs, and details on quotas and resource operations for Managed Service for ClickHouse®.
Users with this role can:
- Restore ClickHouse® clusters from backups.
- View info on ClickHouse® clusters and access permissions granted for them.
- View info on maintenance tasks for ClickHouse® clusters.
- View ClickHouse® cluster logs.
- View info on the results of ClickHouse® cluster performance diagnostics.
- View info on quotas for Managed Service for ClickHouse®.
- View info on resource operations for Managed Service for ClickHouse®.
This role includes the managed-clickhouse.viewer permissions.
Yandex Managed Service for MySQL®
managed-mysql.restorer
The managed-mysql.restorer role enables restoring MySQL® clusters from backups and viewing info on MySQL® clusters, hosts, databases, and users, viewing cluster logs, as well as viewing info on quotas and resource operations.
Users with this role can:
- View info on MySQL® cluster backups and restore clusters from backups.
- View info on MySQL® clusters and access permissions granted for them.
- View info on maintenance tasks for MySQL® clusters.
- View info on MySQL® cluster hosts.
- View info on MySQL® databases.
- View info on MySQL® users.
- View info on MySQL® alerts.
- View MySQL® cluster logs.
- View info on the results of MySQL® cluster performance diagnostics.
- View info on quotas for Managed Service for MySQL®.
- View info on resource operations for Managed Service for MySQL®.
This role includes the managed-mysql.viewer permissions.
Yandex Managed Service for OpenSearch
managed-opensearch.restorer
The managed-opensearch.restorer role enables restoring OpenSearch clusters from backups and viewing info on OpenSearch clusters, their logs, as well as info on quotas and resource operations for Managed Service for OpenSearch.
Users with this role can:
- View info on OpenSearch clusters and access permissions granted for them.
- Restore OpenSearch clusters from backups.
- View info on maintenance tasks for OpenSearch clusters.
- View OpenSearch cluster logs.
- View info on quotas for Managed Service for OpenSearch.
- View info on resource operations for Managed Service for OpenSearch.
This role includes the managed-opensearch.viewer permissions.
Yandex Managed Service for PostgreSQL
managed-postgresql.restorer
The managed-postgresql.restorer role enables restoring PostgreSQL clusters from backups and viewing info on PostgreSQL clusters, hosts, databases, and users, viewing cluster logs, as well as viewing info on quotas and resource operations.
Users with this role can:
- View info on PostgreSQL cluster backups and restore clusters from backups.
- View info on PostgreSQL clusters and access permissions granted for them.
- View info on maintenance tasks for PostgreSQL clusters.
- View info on PostgreSQL cluster hosts.
- View info on PostgreSQL databases.
- View info on PostgreSQL users.
- View info on PostgreSQL alerts.
- View PostgreSQL cluster logs.
- View info on the results of PostgreSQL cluster performance diagnostics.
- View info on quotas for Managed Service for PostgreSQL.
- View info on resource operations for Managed Service for PostgreSQL.
This role includes the managed-postgresql.viewer permissions.
Yandex Managed Service for Sharded PostgreSQL
managed-spqr.restorer
The managed-spqr.restorer role enables restoring Sharded PostgreSQL clusters from backups and viewing info on Sharded PostgreSQL clusters, hosts, databases, and users, cluster logs, as well as info on quotas and resource operations.
Users with this role can:
- View info on Sharded PostgreSQL cluster backups and restore clusters from backups.
- View info on Sharded PostgreSQL clusters and access permissions granted for them.
- View info on maintenance tasks for Sharded PostgreSQL clusters.
- View info on Sharded PostgreSQL cluster hosts.
- View info on databases in Sharded PostgreSQL clusters.
- View info on users in Sharded PostgreSQL clusters.
- View Sharded PostgreSQL cluster logs.
- View info on quotas for Managed Service for Sharded PostgreSQL.
- View info on resource operations for Managed Service for Sharded PostgreSQL.
This role includes the managed-spqr.viewer permissions.
Yandex Managed Service for Valkey™
managed-redis.restorer
The managed-redis.restorer role enables restoring Valkey™ clusters from backups, viewing info on Valkey™ hosts, clusters, and their logs, as well as on quotas and resource operations.
Users with this role can:
- View info on Valkey™ cluster backups and restore clusters from backups.
- View info on Valkey™ clusters and access permissions granted for them.
- View info on maintenance tasks for Valkey™ clusters.
- View info on Valkey™ cluster hosts.
- View info on Valkey™ cluster shards.
- View info on Valkey™ users.
- View info on Valkey™ alerts.
- View Valkey™ cluster logs.
- View info on quotas for Yandex Managed Service for Valkey™.
- View info on resource operations for Yandex Managed Service for Valkey™.
This role includes the managed-redis.viewer permissions.
Yandex MPP Analytics for PostgreSQL
managed-greenplum.restorer
The managed-greenplum.restorer role enables restoring Yandex MPP Analytics for PostgreSQL clusters from backups within Yandex MPP Analytics for PostgreSQL, viewing info on Yandex MPP Analytics for PostgreSQL clusters and hosts, their logs, as well as info on quotas and service resource operations.
Users with this role can:
- View info on Yandex MPP Analytics for PostgreSQL cluster backups and restore clusters from backups.
- View info on Yandex MPP Analytics for PostgreSQL clusters and access permissions granted for them.
- View info on maintenance tasks for Yandex MPP Analytics for PostgreSQL clusters.
- View info on Yandex MPP Analytics for PostgreSQL cluster hosts.
- View Yandex MPP Analytics for PostgreSQL cluster logs.
- View info on the results of Yandex MPP Analytics for PostgreSQL cluster performance diagnostics.
- View info on quotas for Yandex MPP Analytics for PostgreSQL.
- View info on resource operations for Yandex MPP Analytics for PostgreSQL.
This role includes the managed-greenplum.viewer permissions.
Yandex StoreDoc
managed-mongodb.restorer
The managed-mongodb.restorer role enables restoring Yandex StoreDoc clusters from backups and viewing info on Yandex StoreDoc clusters, hosts, shards, databases, users, cluster logs, quotas, and resource operations.
Users with this role can:
- View info on Yandex StoreDoc cluster backups and restore clusters from backups.
- View info on Yandex StoreDoc clusters and access permissions granted for them.
- View info on maintenance tasks for Yandex StoreDoc clusters and modify such tasks.
- View info on Yandex StoreDoc cluster hosts.
- View info on Yandex StoreDoc cluster shards.
- View info on Yandex StoreDoc databases.
- View info on Yandex StoreDoc users.
- View info on Yandex StoreDoc alerts.
- View Yandex StoreDoc cluster logs.
- View info on the results of Yandex StoreDoc cluster performance diagnostics.
- View info on Yandex StoreDoc quotas.
- View info on resource operations for Yandex StoreDoc.
This role includes the managed-mongodb.viewer permissions.
Q3 2025
- Implemented management of OAuth client secrets using the CLI and API.
CLIAPI - Added a group of commands for OAuth client management to the CLI and API.
CLIAPI
Q2 2025
- Enabled creating and using refresh tokens.
CLI
Q1 2025
- Added new scopes for API keys and the ability to assign more than one scope per service.
Management consoleCLITerraformAPI - Workload identity federations are now available to all users.
Management consoleCLITerraformAPI - Added creating an ID token for service account, a special short-lived token for authentication in third-party systems.
Management consoleCLITerraformAPI
Q4 2024
- Added sending the
CreateIamTokendata event when creating an IAM token. - Expanded the scope of limited lifetime API keys to work with Yandex Managed Service for YDB in compatibility mode with PostgreSQL, Yandex Cloud Postbox, and Yandex Serverless Containers.
Management consoleCLITerraformAPI - You can now see the service account's last authentication date and time. You can get the information in the
last_authenticated_atfield using theyc iam user-account getYandex Cloud CLI command.CLI
Q3 2024
- Added Workload Identity Federations that allow you to grant access to external applications without using long-lived access keys.
Management consoleCLITerraformAPI - You can now create API keys with limited scope and validity period.
Management consoleCLITerraformAPI - Added the ResolveAgent REST API method.
API - Added the ability to revoke an IAM token using the Yandex Cloud CLI.
CLI - Added
All users in organization XandAll users in federation Nsystem groups. - Added the Terraform data source used to get the service agent ID.
Terraform
Q2 2024
- Added the last used date info for service account access keys. You can find this info on the service account page in the management console
or in thelast_used_atfield when using the API to invoke access key management methods.Management consoleAPI
Q1 2024
- Added the Security Token Service component to get temporary access keys compatible with AWS S3 API. This feature is at the Preview stage.
CLIAPI - Added OAuth client authentication support by authenticating a service account token.
- Added the option of using masked token ID for Audit Trails logs.
- Improved the key rotation mechanism in OpenID Connect
.