Managing access to a Managed Service for Sharded PostgreSQL cluster
You can assign a user or service account a role that grants access to a specific cluster.
This allows you to issue granular roles to various users and service accounts for access to individual clusters.
Warning
Take note that apart from the role for access to the cluster, the user also needs the minimum role to view the folder's resources, e.g., managed-spqr.viewer (to view the info about all the folder's clusters) or the primitive viewer (to view all the folder's resources).
For example, you can issue the managed-spqr.viewer role for a folder and the managed-spqr.editor role for a specific cluster. This will enable the user to view the info about all the folder's clusters while using only one particular cluster.
To manage user view permissions for cluster lists, we recommend using different folders in your cloud.
Getting a list of roles assigned for a cluster
-
Get an IAM token for API authentication and put it into an environment variable:
export IAM_TOKEN="<IAM_token>" -
Call the Cluster.ListAccessBindings method, e.g., via the following cURL
request:curl \ --request GET \ --header "Authorization: Bearer $IAM_TOKEN" \ --header "Content-Type: application/json" \ --url 'https://mdb.api.cloud.yandex.net/managed-spqr/v1/clusters/<cluster_ID>:listAccessBindings'You can get the cluster ID with the list of clusters in the folder.
-
View the server response to make sure your request was successful.
-
Get an IAM token for API authentication and put it into an environment variable:
export IAM_TOKEN="<IAM_token>" -
Clone the cloudapi
repository:cd ~/ && git clone --depth=1 https://github.com/yandex-cloud/cloudapiBelow, we assume that the repository contents reside in the
~/cloudapi/directory. -
Call the ClusterService.ListAccessBindings method, e.g., via the following gRPCurl
request:grpcurl \ -format json \ -import-path ~/cloudapi/ \ -import-path ~/cloudapi/third_party/googleapis/ \ -proto ~/cloudapi/yandex/cloud/mdb/spqr/v1/cluster_service.proto \ -rpc-header "Authorization: Bearer $IAM_TOKEN" \ -d '{ "resource_id": "<cluster_ID>" }' \ mdb.api.cloud.yandex.net:443 \ yandex.cloud.mdb.spqr.v1.ClusterService.ListAccessBindingsYou can get the cluster ID with the list of clusters in the folder.
-
Check the server response to make sure your request was successful.
Assigning a role
-
Open the current configuration file with the Managed Service for Sharded PostgreSQL cluster description.
For information on how to create this file, see Creating a Sharded PostgreSQL cluster.
-
Add a resource description:
resource "yandex_mdb_sharded_postgresql_cluster_iam_binding" "<local_resource_name>" { cluster_id = "<cluster_ID>" role = "<role>" members = [ "<subject_type>:<subject_ID>" ] }Where:
-
cluster_id: Cluster ID which you can get with the list of clusters in the folder. -
role: Role, e.g.,managed-spqr.editor. -
members: List of designations of subjects the role is assigned to.Here is an example:
serviceAccount:aje6p030123a********userAccount:ajerq94vab34********system:allAuthenticatedUsers
Subject designations
To indicate a subject, use a combination of its type and unique ID, i.e.,
<subject_type>:<ID>. Here is how you can designate a subject:Subject type
Subject designation
userAccountuserAccount:<user_ID>serviceAccountserviceAccount:<service_account_ID>federatedUserfederatedUser:<user_ID>groupgroup:<group_ID>systemsystem:allAuthenticatedUsers(
All authenticated usersgroup)system:allUsers(
All usersgroup)system:group:organization:<organization_ID>:users(
All users in organization Xgroup)system:group:federation:<federation_ID>:users(
All users in federation Ngroup)system:group:userpool:<pool_ID>:users(
All users in userpool Pgroup)
-
-
Make sure the configuration files are correct.
-
In the command line, navigate to the directory that contains the current Terraform configuration files defining the infrastructure.
-
Run this command:
terraform validateTerraform will show any errors found in your configuration files.
-
-
Confirm resource changes.
-
Run this command to view the planned changes:
terraform planIf you described the configuration correctly, the terminal will display a list of the resources to update and their parameters. This is a verification step that does not apply changes to your resources.
-
If everything looks correct, apply the changes:
-
Run this command:
terraform apply -
Confirm updating the resources.
-
Wait for the operation to complete.
-
For more information, see this Terraform provider guide.
-
-
Get an IAM token for API authentication and put it into an environment variable:
export IAM_TOKEN="<IAM_token>" -
Call the Cluster.UpdateAccessBindings method, e.g., via the following cURL
request:curl \ --request PATCH \ --header "Authorization: Bearer $IAM_TOKEN" \ --header "Content-Type: application/json" \ --url 'https://mdb.api.cloud.yandex.net/managed-spqr/v1/clusters/<cluster_ID>:updateAccessBindings' \ --data '{ "access_binding_deltas": [ { "action": "ADD", "access_binding": { "role_id": "<role>", "subject": { "id": "<subject_ID>", "type": "<subject_type>" } } } ] }'Where:
-
<cluster_ID>: Cluster ID which you can get with the list of clusters in the folder. -
access_binding_deltas.roleId: Role, e.g.,managed-spqr.editor. -
access_binding_deltas.subject.id: ID of the subject the role is assigned to. -
access_binding_deltas.subject.type: Type of subject the role is assigned to.Subject designations
To indicate a subject, use a combination of its type and unique ID in the
subject.typeandsubject.idfields of the request. Here are possible combinations:subject.type
subject.id
userAccount<user_ID>serviceAccount<service_account_ID>federatedUser<user_ID>group<group_ID>systemallAuthenticatedUsers(
All authenticated usersgroup)allUsers(
All usersgroup)group:organization:<organization_ID>:users(
All users in organization Xgroup)group:federation:<federation_ID>:users(
All users in federation Ngroup)group:userpool:<pool_ID>:users(
All users in userpool Pgroup)
-
-
Check the server response to make sure your request was successful.
-
Get an IAM token for API authentication and put it into an environment variable:
export IAM_TOKEN="<IAM_token>" -
Clone the cloudapi
repository:cd ~/ && git clone --depth=1 https://github.com/yandex-cloud/cloudapiBelow, we assume that the repository contents reside in the
~/cloudapi/directory. -
Call the ClusterService.UpdateAccessBindings method, e.g., via the following gRPCurl
request:grpcurl \ -format json \ -import-path ~/cloudapi/ \ -import-path ~/cloudapi/third_party/googleapis/ \ -proto ~/cloudapi/yandex/cloud/mdb/spqr/v1/cluster_service.proto \ -rpc-header "Authorization: Bearer $IAM_TOKEN" \ -d '{ "resource_id": "<cluster_ID>", "access_binding_deltas": [ { "action": "ADD", "access_binding": { "role_id": "<role>", "subject": { "id": "<subject_ID>", "type": "<subject_type>" } } } ] }' \ mdb.api.cloud.yandex.net:443 \ yandex.cloud.mdb.spqr.v1.ClusterService.UpdateAccessBindingsWhere:
-
resource_id: Cluster ID which you can get with the list of clusters in the folder. -
access_binding_deltas.roleId: Role, e.g.,managed-spqr.editor. -
access_binding_deltas.subject.id: ID of the subject the role is assigned to. -
access_binding_deltas.subject.type: Type of subject the role is assigned to.Subject designations
To indicate a subject, use a combination of its type and unique ID in the
subject.typeandsubject.idfields of the request. Here are possible combinations:subject.type
subject.id
userAccount<user_ID>serviceAccount<service_account_ID>federatedUser<user_ID>group<group_ID>systemallAuthenticatedUsers(
All authenticated usersgroup)allUsers(
All usersgroup)group:organization:<organization_ID>:users(
All users in organization Xgroup)group:federation:<federation_ID>:users(
All users in federation Ngroup)group:userpool:<pool_ID>:users(
All users in userpool Pgroup)
-
-
Check the server response to make sure your request was successful.
Assigning multiple roles
-
Open the current Terraform configuration file with the infrastructure plan.
For information on how to create this file, see Creating a cluster.
-
Add resource descriptions:
resource "yandex_mdb_sharded_postgresql_cluster_iam_binding" "<resource_1_local_name>" { cluster_id = "<cluster_ID>" role = "<role_1>" members = [ "<subject_type>:<subject_1_ID>", "<subject_type>:<subject_2_ID>" ] } resource "yandex_mdb_sharded_postgresql_cluster_iam_binding" "<resource_2_local_name>" { cluster_id = "<cluster_ID>" role = "<role_2>" members = [ "<subject_type>:<subject_3_ID>" ] }Where:
-
cluster_id: Cluster ID which you can get with the list of clusters in the folder. -
role: Role, e.g.,managed-spqr.editor. -
members: List of designations of subjects the role is assigned to.Here is an example:
serviceAccount:aje6p030123a********userAccount:ajerq94vab34********system:allAuthenticatedUsers
Subject designations
To indicate a subject, use a combination of its type and unique ID, i.e.,
<subject_type>:<ID>. Here is how you can designate a subject:Subject type
Subject designation
userAccountuserAccount:<user_ID>serviceAccountserviceAccount:<service_account_ID>federatedUserfederatedUser:<user_ID>groupgroup:<group_ID>systemsystem:allAuthenticatedUsers(
All authenticated usersgroup)system:allUsers(
All usersgroup)system:group:organization:<organization_ID>:users(
All users in organization Xgroup)system:group:federation:<federation_ID>:users(
All users in federation Ngroup)system:group:userpool:<pool_ID>:users(
All users in userpool Pgroup)
-
-
Make sure the configuration files are correct.
-
In the command line, navigate to the directory that contains the current Terraform configuration files defining the infrastructure.
-
Run this command:
terraform validateTerraform will show any errors found in your configuration files.
-
-
Confirm resource changes.
-
Run this command to view the planned changes:
terraform planIf you described the configuration correctly, the terminal will display a list of the resources to update and their parameters. This is a verification step that does not apply changes to your resources.
-
If everything looks correct, apply the changes:
-
Run this command:
terraform apply -
Confirm updating the resources.
-
Wait for the operation to complete.
-
For more information, see this Terraform provider guide.
-
Alert
The setAccessBindings method overwrites access permissions for the resource. All roles previously assigned for this resource will be deleted.
-
Get an IAM token for API authentication and put it into an environment variable:
export IAM_TOKEN="<IAM_token>" -
Call the Cluster.SetAccessBindings method, e.g., via the following cURL
request:curl \ --request POST \ --header "Authorization: Bearer $IAM_TOKEN" \ --header "Content-Type: application/json" \ --url 'https://mdb.api.cloud.yandex.net/managed-spqr/v1/clusters/<cluster_ID>:setAccessBindings' \ --data '{ "accessBindings": [ { "roleId": "<role>", "subject": { "id": "<subject_1_ID>", "type": "<subject_type>" } }, { "roleId": "<role>", "subject": { "id": "<subject_2_ID>", "type": "<subject_type>" } }, ... { "roleId": "<role>", "subject": { "id": "<subject_N_ID>", "type": "<subject_type>" } } ] }'Where:
-
<cluster_ID>: Cluster ID which you can get with the list of clusters in the folder. -
accessBindings.roleId: Role, e.g.,managed-spqr.editor. -
accessBindings.subject.id: ID of the subject the role is assigned to. -
accessBindings.subject.type: Type of subject the role is assigned to.Subject designations
To indicate a subject, use a combination of its type and unique ID in the
subject.typeandsubject.idfields of the request. Here are possible combinations:subject.type
subject.id
userAccount<user_ID>serviceAccount<service_account_ID>federatedUser<user_ID>group<group_ID>systemallAuthenticatedUsers(
All authenticated usersgroup)allUsers(
All usersgroup)group:organization:<organization_ID>:users(
All users in organization Xgroup)group:federation:<federation_ID>:users(
All users in federation Ngroup)group:userpool:<pool_ID>:users(
All users in userpool Pgroup)
-
-
Check the server response to make sure your request was successful.
Alert
The ClusterService.SetAccessBindings method completely overwrites access permissions for the resource. All roles previously assigned for this resource will be deleted.
-
Get an IAM token for API authentication and put it into an environment variable:
export IAM_TOKEN="<IAM_token>" -
Clone the cloudapi
repository:cd ~/ && git clone --depth=1 https://github.com/yandex-cloud/cloudapiBelow, we assume that the repository contents reside in the
~/cloudapi/directory. -
Call the ClusterService.SetAccessBindings method, e.g., via the following gRPCurl
request:grpcurl \ -format json \ -import-path ~/cloudapi/ \ -import-path ~/cloudapi/third_party/googleapis/ \ -proto ~/cloudapi/yandex/cloud/mdb/spqr/v1/cluster_service.proto \ -rpc-header "Authorization: Bearer $IAM_TOKEN" \ -d '{ "resource_id": "<cluster_ID>", "accessBindings": [ { "roleId": "<role>", "subject": { "id": "<subject_1_ID>", "type": "<subject_type>" } }, { "roleId": "<role>", "subject": { "id": "<subject_2_ID>", "type": "<subject_type>" } }, ... { "roleId": "<role>", "subject": { "id": "<subject_N_ID>", "type": "<subject_type>" } } ] }' \ mdb.api.cloud.yandex.net:443 \ yandex.cloud.mdb.spqr.v1.ClusterService.SetAccessBindingsWhere:
-
resource_id: Cluster ID which you can get with the list of clusters in the folder. -
accessBindings.roleId: Role, e.g.,managed-spqr.editor. -
accessBindings.subject.id: ID of the subject the role is assigned to. -
accessBindings.subject.type: Type of subject the role is assigned to.Subject designations
To indicate a subject, use a combination of its type and unique ID in the
subject.typeandsubject.idfields of the request. Here are possible combinations:subject.type
subject.id
userAccount<user_ID>serviceAccount<service_account_ID>federatedUser<user_ID>group<group_ID>systemallAuthenticatedUsers(
All authenticated usersgroup)allUsers(
All usersgroup)group:organization:<organization_ID>:users(
All users in organization Xgroup)group:federation:<federation_ID>:users(
All users in federation Ngroup)group:userpool:<pool_ID>:users(
All users in userpool Pgroup)
-
-
Check the server response to make sure your request was successful.
Revoking a role
-
Open the current Terraform configuration file with the infrastructure plan.
For information on how to create this file, see Creating a cluster.
-
Find the description of the resource with the role you want to revoke and delete this description:
resource "yandex_mdb_sharded_postgresql_cluster_iam_binding" "<local_resource_name>" { cluster_id = "<cluster_ID>" role = "<role>" members = [ "<subject_type>:<subject_ID>" ] } -
Make sure the configuration files are correct.
-
In the command line, navigate to the directory that contains the current Terraform configuration files defining the infrastructure.
-
Run this command:
terraform validateTerraform will show any errors found in your configuration files.
-
-
Confirm resource changes.
-
Run this command to view the planned changes:
terraform planIf you described the configuration correctly, the terminal will display a list of the resources to update and their parameters. This is a verification step that does not apply changes to your resources.
-
If everything looks correct, apply the changes:
-
Run this command:
terraform apply -
Confirm updating the resources.
-
Wait for the operation to complete.
-
For more information, see this Terraform provider guide.
-
-
Get an IAM token for API authentication and put it into an environment variable:
export IAM_TOKEN="<IAM_token>" -
Call the Cluster.UpdateAccessBindings method, e.g., via the following cURL
request:curl \ --request PATCH \ --header "Authorization: Bearer $IAM_TOKEN" \ --header "Content-Type: application/json" \ --url 'https://mdb.api.cloud.yandex.net/managed-spqr/v1/clusters/<cluster_ID>:updateAccessBindings' \ --data '{ "access_binding_deltas": [ { "action": "REMOVE", "access_binding": { "role_id": "<role>", "subject": { "id": "<subject_ID>", "type": "<subject_type>" } } } ] }'Where:
-
<cluster_ID>: Cluster ID which you can get with the list of clusters in the folder. -
access_binding_deltas.roleId: Role being revoked, e.g.,managed-spqr.editor. -
access_binding_deltas.subject.id: ID of the subject to revoke the role from. -
access_binding_deltas.subject.type: Subject type to revoke a role from.Subject designations
To indicate a subject, use a combination of its type and unique ID in the
subject.typeandsubject.idfields of the request. Here are possible combinations:subject.type
subject.id
userAccount<user_ID>serviceAccount<service_account_ID>federatedUser<user_ID>group<group_ID>systemallAuthenticatedUsers(
All authenticated usersgroup)allUsers(
All usersgroup)group:organization:<organization_ID>:users(
All users in organization Xgroup)group:federation:<federation_ID>:users(
All users in federation Ngroup)group:userpool:<pool_ID>:users(
All users in userpool Pgroup)
-
-
Check the server response to make sure your request was successful.
-
Get an IAM token for API authentication and put it into an environment variable:
export IAM_TOKEN="<IAM_token>" -
Clone the cloudapi
repository:cd ~/ && git clone --depth=1 https://github.com/yandex-cloud/cloudapiBelow, we assume that the repository contents reside in the
~/cloudapi/directory. -
Call the ClusterService.UpdateAccessBindings method, e.g., via the following gRPCurl
request:grpcurl \ -format json \ -import-path ~/cloudapi/ \ -import-path ~/cloudapi/third_party/googleapis/ \ -proto ~/cloudapi/yandex/cloud/mdb/spqr/v1/cluster_service.proto \ -rpc-header "Authorization: Bearer $IAM_TOKEN" \ -d '{ "resource_id": "<cluster_ID>", "access_binding_deltas": [ { "action": "REMOVE", "access_binding": { "role_id": "<role>", "subject": { "id": "<subject_ID>", "type": "<subject_type>" } } } ] }' \ mdb.api.cloud.yandex.net:443 \ yandex.cloud.mdb.spqr.v1.ClusterService.UpdateAccessBindingsWhere:
-
resource_id: Cluster ID which you can get with the list of clusters in the folder. -
access_binding_deltas.roleId: Role being revoked, e.g.,managed-spqr.editor. -
access_binding_deltas.subject.id: ID of the subject to revoke the role from. -
access_binding_deltas.subject.type: Subject type to revoke a role from.Subject designations
To indicate a subject, use a combination of its type and unique ID in the
subject.typeandsubject.idfields of the request. Here are possible combinations:subject.type
subject.id
userAccount<user_ID>serviceAccount<service_account_ID>federatedUser<user_ID>group<group_ID>systemallAuthenticatedUsers(
All authenticated usersgroup)allUsers(
All usersgroup)group:organization:<organization_ID>:users(
All users in organization Xgroup)group:federation:<federation_ID>:users(
All users in federation Ngroup)group:userpool:<pool_ID>:users(
All users in userpool Pgroup)
-
-
Check the server response to make sure your request was successful.
Examples
Granting cluster management access to a service account
For a service account to be able to view the info of all Managed Service for Sharded PostgreSQL clusters in the folder but modify the resources in one particular cluster alone, give it the managed-spqr.viewer role for the folder and the managed-spqr.editor role for that cluster:
-
Open the current Terraform configuration file with the infrastructure plan.
For information on how to create this file, see Creating a cluster.
-
Add a resource description:
resource "yandex_mdb_sharded_postgresql_cluster_iam_binding" "spqr-cluster-editor" { cluster_id = "<cluster_ID>" role = "managed-spqr.editor" members = [ "serviceAccount:<service_account_ID>" ] }Where:
-
Make sure the configuration files are correct.
-
In the command line, navigate to the directory that contains the current Terraform configuration files defining the infrastructure.
-
Run this command:
terraform validateTerraform will show any errors found in your configuration files.
-
-
Confirm resource changes.
-
Run this command to view the planned changes:
terraform planIf you described the configuration correctly, the terminal will display a list of the resources to update and their parameters. This is a verification step that does not apply changes to your resources.
-
If everything looks correct, apply the changes:
-
Run this command:
terraform apply -
Confirm updating the resources.
-
Wait for the operation to complete.
-
For more information, see this Terraform provider guide.
-
-
Get an IAM token for API authentication and put it into an environment variable:
export IAM_TOKEN="<IAM_token>" -
Assign the role for the folder:
curl \ --request POST \ --header "Authorization: Bearer $IAM_TOKEN" \ --header "Content-Type: application/json" \ --url 'https://resource-manager.api.cloud.yandex.net/resource-manager/v1/folders/<folder_ID>:updateAccessBindings' \ --data '{ "access_binding_deltas": [ { "action": "ADD", "access_binding": { "role_id": "managed-spqr.viewer", "subject": { "id": "<service_account_ID>", "type": "serviceAccount" } } } ] }'access_binding_deltas.subject.id: ID of the service account the role is assigned to. -
Call the Cluster.UpdateAccessBindings method, e.g., via the following cURL
request:curl \ --request PATCH \ --header "Authorization: Bearer $IAM_TOKEN" \ --header "Content-Type: application/json" \ --url 'https://mdb.api.cloud.yandex.net/managed-spqr/v1/clusters/<cluster_ID>:updateAccessBindings' \ --data '{ "access_binding_deltas": [ { "action": "ADD", "access_binding": { "role_id": "managed-spqr.editor", "subject": { "id": "<service_account_ID>", "type": "serviceAccount" } } } ] }'access_binding_deltas.subject.id: ID of the service account the role is assigned to. -
Check the list of roles assigned for the folder:
curl \ --request GET \ --header "Authorization: Bearer $IAM_TOKEN" \ --header "Content-Type: application/json" \ --url 'https://resource-manager.api.cloud.yandex.net/resource-manager/v1/folders/<folder_ID>:listAccessBindings' -
Check the list of roles assigned for the cluster:
curl \ --request GET \ --header "Authorization: Bearer $IAM_TOKEN" \ --header "Content-Type: application/json" \ --url 'https://mdb.api.cloud.yandex.net/managed-spqr/v1/clusters/<cluster_ID>:listAccessBindings'
-
Get an IAM token for API authentication and put it into an environment variable:
export IAM_TOKEN="<IAM_token>" -
Clone the cloudapi
repository:cd ~/ && git clone --depth=1 https://github.com/yandex-cloud/cloudapiBelow, we assume that the repository contents reside in the
~/cloudapi/directory. -
Assign the role for the folder:
grpcurl \ -format json \ -import-path ~/cloudapi/ \ -import-path ~/cloudapi/third_party/googleapis/ \ -proto ~/cloudapi/yandex/cloud/resourcemanager/v1/folder_service.proto \ -rpc-header "Authorization: Bearer $IAM_TOKEN" \ -d '{ "resource_id": "<folder_ID>", "access_binding_deltas": [ { "action": "ADD", "access_binding": { "role_id": "managed-spqr.viewer", "subject": { "id": "<service_account_ID>", "type": "serviceAccount" } } } ] }' \ resource-manager.api.cloud.yandex.net:443 \ yandex.cloud.resourcemanager.v1.FolderService.UpdateAccessBindingsaccess_binding_deltas.subject.id: ID of the service account the role is assigned to. -
Assign the role for the cluster:
grpcurl \ -format json \ -import-path ~/cloudapi/ \ -import-path ~/cloudapi/third_party/googleapis/ \ -proto ~/cloudapi/yandex/cloud/mdb/spqr/v1/cluster_service.proto \ -rpc-header "Authorization: Bearer $IAM_TOKEN" \ -d '{ "resource_id": "<cluster_ID>", "access_binding_deltas": [ { "action": "ADD", "access_binding": { "role_id": "managed-spqr.editor", "subject": { "id": "<service_account_ID>", "type": "serviceAccount" } } } ] }' \ mdb.api.cloud.yandex.net:443 \ yandex.cloud.mdb.spqr.v1.ClusterService.UpdateAccessBindingsaccess_binding_deltas.subject.id: ID of the service account the role is assigned to. -
Check the list of roles assigned for the folder:
grpcurl \ -format json \ -import-path ~/cloudapi/ \ -import-path ~/cloudapi/third_party/googleapis/ \ -proto ~/cloudapi/yandex/cloud/resourcemanager/v1/folder_service.proto \ -rpc-header "Authorization: Bearer $IAM_TOKEN" \ -d '{ "resource_id": "<folder_ID>" }' \ resource-manager.api.cloud.yandex.net:443 \ yandex.cloud.resourcemanager.v1.FolderService.ListAccessBindings -
Check the list of roles assigned for the cluster:
grpcurl \ -format json \ -import-path ~/cloudapi/ \ -import-path ~/cloudapi/third_party/googleapis/ \ -proto ~/cloudapi/yandex/cloud/mdb/spqr/v1/cluster_service.proto \ -rpc-header "Authorization: Bearer $IAM_TOKEN" \ -d '{ "resource_id": "<cluster_ID>" }' \ mdb.api.cloud.yandex.net:443 \ yandex.cloud.mdb.spqr.v1.ClusterService.ListAccessBindings