Yandex Cloud
Search
Contact UsGet started
  • Pricing
  • Customer Stories
  • Documentation
  • Blog
  • All Services
  • System Status
    • Featured
    • Infrastructure & Network
    • Data Platform
    • Containers
    • Developer tools
    • Serverless
    • Security
    • Monitoring & Resources
    • AI for business
    • Business tools
  • All Solutions
    • By industry
    • By use case
    • Economics and Pricing
    • Security
    • Technical Support
    • Start testing with double trial credits
    • Cloud credits to scale your IT product
    • Gateway to Russia
    • Cloud for Startups
    • Center for Technologies and Society
    • Yandex Cloud Partner program
  • Pricing
  • Customer Stories
  • Documentation
  • Blog
© 2025 Direct Cursus Technology L.L.C.
Security in Yandex Cloud
  • Key security principles
  • Division of responsibility for security
  • Compliance
  • Security measures on the Yandex Cloud side
  • Security tools available to cloud service users
    • All tutorials
  • User support policy during vulnerability scanning
  • Security bulletins
  • Public IP address ranges

In this article:

  • Authentication and access management
  • Network security
  • Secure virtual environment configuration
  • Data encryption and key management
  • Collecting, monitoring, and analyzing audit logs
  • Application security
  • Kubernetes security
  1. Tutorials
  2. All tutorials

Yandex Cloud security tutorials

Written by
Yandex Cloud
Updated at October 13, 2025
  • Authentication and access management
  • Network security
  • Secure virtual environment configuration
  • Data encryption and key management
  • Collecting, monitoring, and analyzing audit logs
  • Application security
  • Kubernetes security

Authentication and access managementAuthentication and access management

  • Access control for user groups with different roles in Yandex Identity Hub
  • Using a service account with an OS Login profile for VM management via Ansible
  • Managing identity federations
    • Authentication using Active Directory
    • Authentication using Google Workspace
    • Authentication using Microsoft Entra ID
    • Authentication using Keycloak
    • User group mapping
      • User group mapping in Microsoft Active Directory Federation Services
      • User group mapping in Microsoft Entra ID
      • User group mapping in Keycloak

Network securityNetwork security

  • Setting up virtual hosting
  • Automatically copying objects from one Yandex Object Storage bucket to another
  • Loading data from Yandex Direct to a Yandex Managed Service for ClickHouse® data mart using Yandex Cloud Functions, Yandex Object Storage, and Yandex Data Transfer
  • Creating a load balancer with DDoS protection
  • Secure user access to cloud resources based on WireGuard VPN
  • Providing secure access to content in Yandex Cloud CDN

Secure virtual environment configurationSecure virtual environment configuration

  • Hosting a static Gatsby website in Yandex Object Storage
  • Storing Apache Airflow™ connections and variables in Yandex Lockbox
  • Deploying a fault-tolerant architecture with preemptible VMs
  • Migrating services from NLB to L7 ALB for DDoS protection using Yandex Smart Web Security
    • Migrating services from an NLB with VMs as targets to an L7 ALB
    • Migrating services from an NLB with an instance group as a target to an L7 ALB
    • Migrating services from an external NLB to an L7 ALB with an internal NLB as a target

Data encryption and key managementData encryption and key management

  • Data encryption
    • Which encryption method should I choose?
    • Encrypting data using the Yandex Cloud CLI and API
    • Encrypting data using the Yandex Cloud SDK
    • Encrypting data using the AWS Encryption SDK
    • Encrypting data using Google Tink
  • Managing Yandex Key Management Service keys with Hashicorp Terraform
  • Encrypting secrets in Hashicorp Terraform
  • Auto Unseal in Hashicorp Vault
  • Secure password transmission to an initialization script
  • Terminating TLS connections
  • Secure storage of GitLab CI passwords as Yandex Lockbox secrets
  • Using a Yandex Lockbox secret to store a static access key
  • Getting Yandex Lockbox secret value on the GitHub side
  • Getting the Yandex Lockbox secret value on the GitLab side

Collecting, monitoring, and analyzing audit logsCollecting, monitoring, and analyzing audit logs

  • Searching for Yandex Cloud events in Yandex Query
  • Searching for Yandex Cloud events in Yandex Object Storage
  • Searching for Yandex Cloud events in Yandex Cloud Logging
  • Alert settings in Yandex Monitoring
  • Configuring responses in Yandex Cloud Logging and Yandex Cloud Functions
  • Processing Yandex Audit Trails events
  • Exporting audit logs to SIEM systems
    • Exporting audit logs to MaxPatrol SIEM
    • Uploading audit logs to Splunk SIEM
    • Uploading audit logs to ArcSight SIEM
    • Uploading Yandex Audit Trails audit logs to KUMA SIEM
  • Transferring logs from a VM to Yandex Cloud Logging
  • Writing load balancer logs to PostgreSQL
  • Transferring logs from Container Optimized Image to Yandex Cloud Logging

Application securityApplication security

  • Installing an NGINX ingress controller with a Yandex Certificate Manager certificate
  • Building a CI/CD pipeline in GitLab with serverless products
  • Creating an interactive serverless application using WebSocket
  • Creating an L7 Yandex Application Load Balancer with a Yandex Smart Web Security profile
  • Yandex API Gateway protection with Yandex Smart Web Security
  • Adding an HTML page to work with Yandex SmartCaptcha
  • Yandex SmartCaptcha in Android apps
  • Invisible Yandex SmartCaptcha in Android apps
  • Yandex SmartCaptcha in an Android app on Flutter
  • Yandex SmartCaptcha in iOS apps

Kubernetes securityKubernetes security

  • Encrypting secrets in Yandex Managed Service for Kubernetes
  • Signing and verifying Yandex Container Registry Docker images in Yandex Managed Service for Kubernetes
  • Syncing with Yandex Managed Service for Kubernetes secrets
  • Getting the Yandex Lockbox secret value on the custom Kubernetes installation side
  • Accessing the Yandex Cloud API from a Managed Service for Kubernetes cluster using a workload identity federation in Identity and Access Management
  • Creating an L7 load balancer with a Yandex Smart Web Security security profile through an Yandex Application Load Balancer Ingress controller
  • Migrating services from an NLB with a Yandex Managed Service for Kubernetes cluster as a target to an L7 ALB
  • Transferring Yandex Managed Service for Kubernetes cluster logs to Yandex Cloud Logging

Was the article helpful?

Previous
Integrations and third-party solutions
Next
Access control for user groups with different roles in Identity Hub
© 2025 Direct Cursus Technology L.L.C.