Yandex Cloud
Search
Discuss with expertTry it for free
  • Customer Stories
  • Documentation
  • Blog
  • All Services
    • Cloud Interconnect
    • Cloud Backup
    • Cloud Registry
    • Yandex AI Studio
    • Compute Cloud
    • Object Storage
    • Managed Service for Kubernetes®
    • Yandex BareMetal
    • Smart Web Security
    • Security Deck
    • Managed Service for PostgreSQL
    • Managed Service for ClickHouse®
    • Monium
    • Cloud CDN
    • Network Load Balancer
    • Virtual Private Cloud
    • Cloud DNS
    • Application Load Balancer
    • Yandex Cloud Video
    • Stackland
    • Yandex Cloud Router
    • Yandex Managed Service for Trino
    • Managed Service for MySQL®
    • Managed Service for Valkey™
    • Managed Service for Apache Spark™
    • Yandex StoreDoc
    • Managed Service for OpenSearch
    • Managed Service for Apache Kafka®
    • Data Transfer
    • Yandex MPP Analytics Engine for PostgreSQL
    • Yandex Managed Service for Apache Airflow®
    • Data Processing
    • Yandex MetaData Hub
    • Managed Service for YDB
    • Managed Service for Sharded PostgreSQL
    • Managed Service for YTsaurus
    • Yandex WebSQL
    • DataLens
    • Yandex Search API
    • SpeechSense
    • SpeechKit
    • DataSphere
    • Vision OCR
    • Translate
    • Yandex Identity Hub
    • Key Management Service
    • Certificate Manager
    • Yandex Lockbox
    • Audit Trails
    • SmartCaptcha
    • Cloud Desktop
    • Yandex SIEM
    • SourceCraft Code Assistant
    • Container Registry
    • Managed Service for GitLab
    • Managed Service for Prometheus®
    • Cloud Functions
    • API Gateway
    • Yandex Cloud Postbox
    • Message Queue
    • Serverless Integrations
    • IoT Core
    • Data Streams
    • Serverless Containers
    • Cloud Notification Service
    • Yandex Query
    • Identity and Access Management
    • Yandex Cloud Console
    • Resource Manager
    • Yandex Cloud Billing
    • Yandex Cloud Quota Manager
    • Cloud Apps
  • System Status
  • Marketplace
    • Featured
    • Infrastructure & Network
    • Data Platform
    • AI for business
    • Security
    • DevOps tools
    • Serverless
    • Monitoring & Resources
  • All Solutions
    • By industry
    • By use case
    • Economics and Pricing
    • Security
    • Technical Support
    • Start testing with double trial credits
    • Cloud credits to scale your IT product
    • Gateway to Russia
    • Cloud for Startups
    • Center for Technologies and Society
    • Yandex Cloud Partner program
    • Price calculator
    • Pricing plans
  • Customer Stories
  • Documentation
  • Blog
© 2026 Direct Cursus Technology L.L.C.
Yandex Serverless Containers
  • Comparing with other Yandex Cloud services
    • All guides
    • Getting an IAM token for a service account using a container
      • Making a container public
      • Making a container private
      • Viewing roles assigned to a container
      • Assigning roles to a container
      • Revoking roles assigned to a container
    • Viewing operations with service resources
  • Access management
  • Tools
  • Pricing policy
  • Terraform reference
  • Monitoring metrics
  • Audit Trails events
  • Public materials
  • Release notes
  • FAQ
  1. Step-by-step guides
  2. Managing container access permissions
  3. Revoking roles assigned to a container

Revoking roles assigned for a container

Written by
Yandex Cloud
Improved by
ilya
Updated at September 30, 2026
View in Markdown
CLI
API

Run this command to revoke a role for a container:

yc serverless container remove-access-binding \
  --name <container_name> \
  --role <role_ID> \
  --subject <subject_type>:<subject_ID>

Where:

  • --role: ID of the role you need to revoke.

  • --subject: Subject to revoke the role from.

    Subject designations

    To indicate a subject, use the --subject parameter in <subject_type>:<ID> format. For some subject types, the Yandex Cloud CLI provides separate parameters instead of --subject, where you only need to specify the subject name or ID without the type. Possible subject designations and matching CLI parameters:

    Subject type

    Subject designation

    Yandex Cloud CLI parameter

    userAccount

    userAccount:<user_ID>

    --user-account-id or --user-yandex-login

    serviceAccount

    serviceAccount:<service_account_ID>

    --service-account-id or --service-account-name

    federatedUser

    federatedUser:<user_ID>

    --user-account-id

    group

    group:<group_ID>

    --group-members

    system

    system:allAuthenticatedUsers

    (All authenticated users group)

    --all-authenticated-users

    system:allUsers

    (All users group)

    —

    system:group:organization:<organization_ID>:users

    (All users in organization X group)

    --organization-users

    system:group:federation:<federation_ID>:users

    (All users in federation N group)

    --federation-users

    system:group:userpool:<pool_ID>:users

    (All users in userpool P group)

    —

To revoke roles for a container, use the updateAccessBindings REST API method for the Container resource or the ContainerService/UpdateAccessBindings gRPC API call. In the request body, set the action property to REMOVE and specify the subject type and ID under subject.

Subject designations

To indicate a subject, use a combination of its type and unique ID in the subject.type and subject.id fields of the request. Here are possible combinations:

subject.type

subject.id

userAccount

<user_ID>

serviceAccount

<service_account_ID>

federatedUser

<user_ID>

group

<group_ID>

system

allAuthenticatedUsers

(All authenticated users group)

allUsers

(All users group)

group:organization:<organization_ID>:users

(All users in organization X group)

group:federation:<federation_ID>:users

(All users in federation N group)

group:userpool:<pool_ID>:users

(All users in userpool P group)

Was the article helpful?

Previous
Assigning roles to a container
Next
Creating a container
© 2026 Direct Cursus Technology L.L.C.