Yandex Cloud
Search
Discuss with expertTry it for free
  • Customer Stories
  • Documentation
  • Blog
  • All Services
    • Cloud Interconnect
    • Cloud Backup
    • Cloud Registry
    • Yandex AI Studio
    • Compute Cloud
    • Object Storage
    • Managed Service for Kubernetes®
    • Yandex BareMetal
    • Smart Web Security
    • Security Deck
    • Managed Service for PostgreSQL
    • Managed Service for ClickHouse®
    • Monium
    • Cloud CDN
    • Network Load Balancer
    • Virtual Private Cloud
    • Cloud DNS
    • Application Load Balancer
    • Yandex Cloud Video
    • Stackland
    • Yandex Cloud Router
    • Yandex Managed Service for Trino
    • Managed Service for MySQL®
    • Managed Service for Valkey™
    • Managed Service for Apache Spark™
    • Yandex StoreDoc
    • Managed Service for OpenSearch
    • Managed Service for Apache Kafka®
    • Data Transfer
    • Yandex MPP Analytics Engine for PostgreSQL
    • Yandex Managed Service for Apache Airflow®
    • Data Processing
    • Yandex MetaData Hub
    • Managed Service for YDB
    • Managed Service for Sharded PostgreSQL
    • Managed Service for YTsaurus
    • Yandex WebSQL
    • DataLens
    • Yandex Search API
    • SpeechSense
    • SpeechKit
    • DataSphere
    • Vision OCR
    • Translate
    • Yandex Identity Hub
    • Key Management Service
    • Certificate Manager
    • Yandex Lockbox
    • Audit Trails
    • SmartCaptcha
    • Cloud Desktop
    • SourceCraft Code Assistant
    • Container Registry
    • Managed Service for GitLab
    • Managed Service for Prometheus®
    • Cloud Functions
    • API Gateway
    • Yandex Cloud Postbox
    • Message Queue
    • Serverless Integrations
    • IoT Core
    • Data Streams
    • Serverless Containers
    • Cloud Notification Service
    • Yandex Query
    • Identity and Access Management
    • Yandex Cloud Console
    • Resource Manager
    • Yandex Cloud Billing
    • Yandex Cloud Quota Manager
    • Cloud Apps
  • System Status
  • Marketplace
    • Featured
    • Infrastructure & Network
    • Data Platform
    • AI for business
    • Security
    • DevOps tools
    • Serverless
    • Monitoring & Resources
  • All Solutions
    • By industry
    • By use case
    • Economics and Pricing
    • Security
    • Technical Support
    • Start testing with double trial credits
    • Cloud credits to scale your IT product
    • Gateway to Russia
    • Cloud for Startups
    • Center for Technologies and Society
    • Yandex Cloud Partner program
    • Price calculator
    • Pricing plans
  • Customer Stories
  • Documentation
  • Blog
© 2026 Direct Cursus Technology L.L.C.
Yandex Managed Service for Apache Airflow™
  • Getting started
  • Access management
  • Pricing policy
  • Terraform reference
  • Yandex Monitoring metrics
  • Audit Trails events
  • Release notes
  • FAQ

In this article:

  • Access management
  • Resources you can assign a role for
  • Roles available in the service
  • Service roles
  • Primitive roles
  • Required roles
  • What's next

Access management in Managed Service for Apache Airflow™

Written by
Yandex Cloud
Updated at July 22, 2026
View in Markdown
  • Access management
  • Resources you can assign a role for
  • Roles available in the service
    • Service roles
    • Primitive roles
  • Required roles
  • What's next

In this section, you will learn about:

  • Resources you can assign a role for.
  • Roles this service has.

Access managementAccess management

Yandex Identity and Access Management checks all operations in Yandex Cloud. If an entity does not have required permissions, IAM returns an error.

To grant permissions for a resource, assign the relevant resource roles to an entity performing operations. You can assign roles to a Yandex account, service account, local user, federated user, user group, system group, or public group. For more information, see How access management works in Yandex Cloud.

To assign a role for a resource, you need the managed-airflow.admin role or one of the following roles for that resource:

  • admin
  • resource-manager.admin
  • organization-manager.admin
  • resource-manager.clouds.owner
  • organization-manager.organizations.owner

Resources you can assign a role forResources you can assign a role for

You can assign a role to an organization, cloud, or folder. The roles assigned to organizations, clouds, and folders also apply to their nested resources.

To allow access to Managed Service for Apache Airflow™ resources, assign the user the appropriate roles for the folder, cloud, or organization containing these resources.

You can also assign a role for an individual cluster in the management console, via the CLI, or API.

Roles available in the serviceRoles available in the service

Service rolesService roles

The list below shows all the roles used for access control in Managed Service for Apache Airflow™.

managed-airflow.auditormanaged-airflow.auditor

The managed-airflow.auditor role enables viewing info on Apache Airflow™ clusters, access permissions granted for them, and on quotas for Managed Service for Apache Airflow™.

managed-airflow.viewermanaged-airflow.viewer

The managed-airflow.viewer role enables viewing info on Apache Airflow™ clusters, access permissions granted for them, and their maintenance tasks, as well as on quotas for Managed Service for Apache Airflow™.

This role includes the managed-airflow.auditor and managed-airflow.maintenanceTask.viewer permissions.

managed-airflow.usermanaged-airflow.user

The managed-airflow.user role enables performing basic operations on Apache Airflow™ clusters.

Users with this role can:

  • View info on Apache Airflow™ clusters and access permissions granted for them.
  • Use the Apache Airflow™ web interface.
  • Send requests to the Apache Airflow™ API.
  • View info on maintenance tasks for Apache Airflow™ clusters.
  • View info on quotas for Managed Service for Apache Airflow™.

This role includes the managed-airflow.viewer permissions.

managed-airflow.editormanaged-airflow.editor

The managed-airflow.editor role enables managing Apache Airflow™ clusters.

Users with this role can:

  • View info on Apache Airflow™ clusters, as well as create, modify, run, stop, and delete them.
  • View info on access permissions granted for Apache Airflow™ clusters.
  • View info on maintenance tasks for Apache Airflow™ clusters and modify such tasks.
  • Use the Apache Airflow™ web interface.
  • Send requests to the Apache Airflow™ API.
  • View info on quotas for Managed Service for Apache Airflow™.

This role includes the managed-airflow.user and managed-airflow.maintenanceTask.editor permissions.

To create Apache Airflow™ clusters, you also need the vpc.user role.

managed-airflow.adminmanaged-airflow.admin

The managed-airflow.admin role enables managing Apache Airflow™ clusters and access to them.

Users with this role can:

  • View info on access permissions granted for Apache Airflow™ clusters and modify such permissions.
  • View info on Apache Airflow™ clusters, as well as create, modify, run, stop, and delete them.
  • View info on maintenance tasks for Apache Airflow™ clusters and modify such tasks.
  • Use the Apache Airflow™ web interface.
  • Send requests to the Apache Airflow™ API.
  • View info on quotas for Managed Service for Apache Airflow™.

This role includes the managed-airflow.editor permissions.

To create Apache Airflow™ clusters, you also need the vpc.user role.

managed-airflow.maintenanceTask.viewermanaged-airflow.maintenanceTask.viewer

The managed-airflow.maintenanceTask.viewer role enables viewing info on Apache Airflow™ clusters, access permissions granted for them, and their maintenance tasks, as well as on quotas for Managed Service for Apache Airflow™.

This role includes the managed-airflow.auditor permissions.

managed-airflow.maintenanceTask.editormanaged-airflow.maintenanceTask.editor

The managed-airflow.maintenanceTask.editor role enables viewing info on maintenance tasks for Apache Airflow™ clusters and modifying such tasks, as well as viewing info on Apache Airflow™ clusters, access permissions granted for them, and on quotas for Managed Service for Apache Airflow™.

This role includes the managed-airflow.maintenanceTask.viewer permissions.

managed-airflow.integrationProvidermanaged-airflow.integrationProvider

The managed-airflow.integrationProvider role allows the Apache Airflow™ cluster to work with user resources required for its operation on behalf of the service account. You can assign this role to a service account linked to the Apache Airflow™ cluster.

Service accounts with this role can:
  • Add entries to log groups.
  • View info on log groups.
  • View info on log sinks.
  • View info on granted access permissions for Cloud Logging resources.
  • View info on log exports.
  • View info on Monitoring metrics and their labels, as well as upload and download metrics.
  • View the list of Monitoring dashboards and widgets and info on them, as well as create, modify, and delete them.
  • View the Monitoring notification history.
  • View the list of buckets and info on them, including their deployment region, versioning, encryption, CORS configuration, static website hosting configuration, HTTPS configuration, logging settings, granted access permissions, public access, and default storage class.
  • View lists of objects in buckets and info on these objects, including object lifecycle configuration, granted access permissions for these objects, current multipart uploads, object versions with their metadata, and object locks (both with a retention period and legal hold).
  • View bucket, object, and object version labels, as well as Object Storage statistics.
  • View info on Yandex Lockbox secrets and granted access permissions for them.
  • View details on Object Storage, Monitoring, and Yandex Lockbox quotas.
  • View info on the relevant cloud and folder.

This role includes the logging.writer, monitoring.editor, storage.viewer, and lockbox.viewer permissions.

The role does not provide access to Yandex Lockbox secret contents. To grant the Apache Airflow™ cluster access to Yandex Lockbox secret contents, additionally assign the lockbox.payloadViewer role to the service account either for the relevant folder or for specific secrets.

Primitive rolesPrimitive roles

viewerviewer

The viewer role enables you to view information about Managed Service for Apache Airflow™ clusters and their performance logs.

editoreditor

Users with the editor role can manage any resource, e.g., create clusters and create or delete their subclusters.

This role includes the viewer role.

adminadmin

Users with the admin role can manage resource access permissions, e.g., allow other users to create Managed Service for Apache Airflow™ clusters or to view information about user permissions.

This role includes the editor role.

Required rolesRequired roles

As a user, you need the managed-airflow.editor role or higher for the folder that will contain the new cluster. The managed-airflow.viewer role only allows you to view the list of clusters.

To create a Managed Service for Apache Airflow™ cluster, you need the vpc.user role and the managed-airflow.editor role or higher.

To view managed database (MDB) clusters on the dashboard in the management console, you need the mdb.viewer role.

You can always assign a role with more permissions, e.g., managed-airflow.admin instead of managed-airflow.editor.

What's nextWhat's next

  • How to assign a role.
  • How to revoke a role.
  • Learn more about access management in Yandex Cloud.
  • Learn more about role inheritance.

Was the article helpful?

Previous
Maintenance
Next
Pricing policy
© 2026 Direct Cursus Technology L.L.C.