Revoking roles assigned for an EventRouter resource
Warning
Yandex Serverless Integrations will be discontinued on October 8, 2026. For more information on the timing and procedure, see Yandex Serverless Integrations shutdown.
If you do not have the Yandex Cloud CLI yet, install and initialize it.
The folder used by default is the one specified when creating the CLI profile. To change the default folder, use the yc config set folder-id <folder_ID> command. You can also specify a different folder for any command using --folder-name or --folder-id.
If you access a resource by its name, the search will be limited to the default folder. If you access a resource by its ID, the search will be global, i.e., through all folders based on access permissions.
Run this command to revoke a role for an EventRouter resource from:
yc serverless <resource_type> remove-access-binding <resource_name_or_ID> \
--user-account-id <user_ID> \
--role <role>
Where:
-
--role: ID of the role you need to revoke. -
--subject: Subject to revoke the role from.Subject designations
To indicate a subject, use the
--subjectparameter in<subject_type>:<ID>format. For some subject types, the Yandex Cloud CLI provides separate parameters instead of--subject, where you only need to specify the subject name or ID without the type. Possible subject designations and matching CLI parameters:Subject type
Subject designation
Yandex Cloud CLI parameter
userAccountuserAccount:<user_ID>--user-account-idor--user-yandex-loginserviceAccountserviceAccount:<service_account_ID>--service-account-idor--service-account-namefederatedUserfederatedUser:<user_ID>--user-account-idgroupgroup:<group_ID>--group-memberssystemsystem:allAuthenticatedUsers(
All authenticated usersgroup)--all-authenticated-userssystem:allUsers(
All usersgroup)—
system:group:organization:<organization_ID>:users(
All users in organization Xgroup)--organization-userssystem:group:federation:<federation_ID>:users(
All users in federation Ngroup)--federation-userssystem:group:userpool:<pool_ID>:users(
All users in userpool Pgroup)—
Example
Revoking a role for a bus from a service account:
yc serverless eventrouter bus remove-access-binding epdplu8jn7sr******** \
--service-account-id rrbilgiqaptv******** \
--role serverless.eventrouter.auditor
Result:
...1s...done (3s)
Use the updateAccessBinding REST API method for the relevant resource or the <service>/UpdateAccessBinding gRPC API call.
For example, for a bus, use the updateAccessBinding REST API method for the Bus resource or the BusService/UpdateAccessBinding gRPC API call. In the request body, set the action property to REMOVE and specify the subject type and ID under subject.
Subject designations
To indicate a subject, use a combination of its type and unique ID in the subject.type and subject.id fields of the request. Here are possible combinations:
|
subject.type |
subject.id |
|
|
|
|
|
|
|
|
|
|
|
|
|
|
( |
|
( |
|
|
( |
|
|
( |
|
|
( |