Setting up AWS tools
To access a database via the Document API in the AWS DynamoDB compatibility mode, you can use these AWS tools:
Warning
The Document API only allows you to access document tables.
To use the AWS tools, follow these steps:
-
Create a service account you will use to access your database.
Create it in the folder with your database.
Management consoleCLIAPI-
In the management console
, click or in the top panel and select the folder. -
Navigate
to Identity and Access Management. -
Click Create service account.
-
Enter a name for the service account.
The naming requirements are as follows:
- Length: between 3 and 63 characters.
- It can only contain lowercase Latin letters, numbers, and hyphens.
- It must start with a letter and cannot end with a hyphen.
Make sure the service account name is unique within your cloud.
-
Click Create.
The folder used by default is the one specified when creating the CLI profile. To change the default folder, use the
yc config set folder-id <folder_ID>command. You can also specify a different folder for any command using--folder-nameor--folder-id.If you access a resource by its name, the search will be limited to the default folder. If you access a resource by its ID, the search will be global, i.e., through all folders based on access permissions.
-
View the description of the command for creating a service account:
yc iam service-account create --help -
Create a service account named
my-robot:yc iam service-account create --name my-robotFollow these naming requirements:
- Length: between 3 and 63 characters.
- It can only contain lowercase Latin letters, numbers, and hyphens.
- It must start with a letter and cannot end with a hyphen.
To create a service account, use the create method for the ServiceAccount resource.
-
-
Assign the
editorrole to the service account.You can assign roles to a service account for any resources in any cloud if these resources belong to the same organization as the service account. You can also assign roles for the entire organization.
Assigning a role for a resource
Child resources inherit access permissions from their parent resources. For example, if a service account gets a role for a cloud, it will also get the required permissions for all resources across the cloud's folders.
To assign a role for a resource, you need the
adminorservice-name.adminrole, whereservice-nameis the name of the service to which the resource belongs.Learn which resources you can assign a role for.
To assign a role for a resource:
Management consoleCLITerraformAPIRoles are assigned to a service account the same way as to a user account.
To assign a role for a cloud or folder to a service account:
- In the management console
, click or in the top panel and select the cloud or folder. - Navigate to the Access bindings tab.
- Click Configure access.
- In the window that opens, select Service accounts.
- Select the service account from the list or use the search bar.
- Click
Add role and select the role from the list or use the search bar. - Click Save.
If you do not have the Yandex Cloud CLI yet, install and initialize it.
The folder used by default is the one specified when creating the CLI profile. To change the default folder, use the
yc config set folder-id <folder_ID>command. You can also specify a different folder for any command using--folder-nameor--folder-id.If you access a resource by its name, the search will be limited to the default folder. If you access a resource by its ID, the search will be global, i.e., through all folders based on access permissions.
To assign a role for a cloud or folder to a service account, run this command:
yc resource-manager <resource_category> add-access-binding <resource_name_or_ID> \ --role <role_ID> \ --service-account-id <service_account_ID>Where:
<resource_category>:cloudto assign a role for a cloud orfolderto assign a role for a folder.<resource_name_or_ID>: Name or ID of the resource to assign the role for.--role: Role ID, e.g.,viewer.--service-account-id: ID of the service account you are assigning the role to.
For example, to assign a role for a folder to a service account:
-
Select a role to assign to the service account. For role descriptions, see the Yandex Cloud role reference in the Yandex Identity and Access Management documentation.
-
Get the ID of the service account by its name:
yc iam service-account get <service_account_name>Result:
id: aje6o61dvog2******** folder_id: b1gvmob95yys******** created_at: "2018-10-15T18:01:25Z" name: my-robotIf you do not know the name of your service account, get a list of service accounts with their IDs:
yc iam service-account listResult:
+----------------------+------------------+-----------------+ | ID | NAME | DESCRIPTION | +----------------------+------------------+-----------------+ | aje6o61dvog2******** | my-robot | my description | +----------------------+------------------+-----------------+ -
Assign the role to the service account using its ID:
yc resource-manager folder add-access-binding <folder_name_or_ID> \ --role <role> \ --service-account-id <service_account_ID>Where:
--role: ID of the role to assign.--service-account-id: Service account ID. You can also use the--service-account-nameparameter and specify the username instead of the ID.
If you do not have Terraform yet, install it and configure the Yandex Cloud provider.
To manage infrastructure using Terraform under a service account or user accounts (a Yandex account, a federated account, or a local user), authenticate using the appropriate method.
-
In the configuration file, describe the resources you want to create:
Here is an example of the configuration file structure for assigning a role for a folder:
resource "yandex_resourcemanager_folder_iam_member" "admin-account-iam" { folder_id = "<folder_ID>" role = "<role>" member = "serviceAccount:<service_account_ID>" }Where:
-
folder_id: Folder ID. This is a required setting. -
role: Role. For role descriptions, see the Yandex Cloud role reference in the Yandex Identity and Access Management documentation. This is a required setting. -
member: Subject getting the role. For a service account, specifyserviceAccount:<service_account_ID>.Subject designations
To indicate a subject, use a combination of its type and unique ID, i.e.,
<subject_type>:<ID>. Here is how you can designate a subject:Subject type
Subject designation
userAccountuserAccount:<user_ID>serviceAccountserviceAccount:<service_account_ID>federatedUserfederatedUser:<user_ID>groupgroup:<group_ID>systemsystem:allAuthenticatedUsers(
All authenticated usersgroup)system:allUsers(
All usersgroup)system:group:organization:<organization_ID>:users(
All users in organization Xgroup)system:group:federation:<federation_ID>:users(
All users in federation Ngroup)system:group:userpool:<pool_ID>:users(
All users in userpool Pgroup)
For more information about the resources you can create with Terraform, see this provider guide.
-
-
Create the resources:
-
In the terminal, navigate to the configuration file directory.
-
Make sure the configuration is correct using this command:
terraform validateIf the configuration is valid, you will get this message:
Success! The configuration is valid. -
Run this command:
terraform planYou will see a list of resources and their properties. No changes will be made at this step. Terraform will show any errors in the configuration.
-
Apply the configuration changes:
terraform apply -
Type
yesand press Enter to confirm the changes.
This will assign access permissions for the folder. You can check the role assignment using the management console
or this CLI command:yc resource-manager folder list-access-bindings <folder_name_or_ID> -
To assign a role for a cloud or folder to a service account, use the
updateAccessBindingsREST API method for the Cloud or Folder resource:-
Select a role to assign to the service account. For role descriptions, see the Yandex Cloud role reference in the Yandex Identity and Access Management documentation.
-
Get the ID of the folder with service accounts.
-
Get an IAM token for authentication in the Yandex Cloud API.
-
Get a list of service accounts in the folder to find out their IDs:
export FOLDER_ID=<folder_ID> export IAM_TOKEN=<IAM_token> curl \ --header "Authorization: Bearer ${IAM_TOKEN}" \ "https://iam.api.cloud.yandex.net/iam/v1/serviceAccounts?folderId=${FOLDER_ID}"Result:
{ "serviceAccounts": [ { "id": "ajebqtreob2d********", "folderId": "b1gvmob95yys********", "createdAt": "2018-10-18T13:42:40Z", "name": "my-robot", "description": "my description" } ] } -
Create a request body, e.g., in the
body.jsonfile. SpecifyADDin theactionproperty:{ "accessBindingDeltas": [{ "action": "ADD", "accessBinding": { "roleId": "<role>", "subject": { "id": "<service_account_ID>", "type": "serviceAccount" } } }] }Where:
-
roleId: Role. -
subject: Subject getting the role.Subject designations
To indicate a subject, use a combination of its type and unique ID in the
subject.typeandsubject.idfields of the request. Here are possible combinations:subject.type
subject.id
userAccount<user_ID>serviceAccount<service_account_ID>federatedUser<user_ID>group<group_ID>systemallAuthenticatedUsers(
All authenticated usersgroup)allUsers(
All usersgroup)group:organization:<organization_ID>:users(
All users in organization Xgroup)group:federation:<federation_ID>:users(
All users in federation Ngroup)group:userpool:<pool_ID>:users(
All users in userpool Pgroup)
-
-
Assign a role to a service account, e.g., for the folder with the
b1gvmob95yys********ID:export FOLDER_ID=b1gvmob95yys******** export IAM_TOKEN=CggaAT******** curl \ --request POST \ --header "Content-Type: application/json" \ --header "Authorization: Bearer ${IAM_TOKEN}" \ --data '@body.json' \ "https://resource-manager.api.cloud.yandex.net/resource-manager/v1/folders/${FOLDER_ID}:updateAccessBindings"
Assigning a role for an organization
All resources created within an organization inherit access permissions assigned to that organization. For example, if a service account gets a role for an organization, it will also get the required permissions for all resources across the organization's clouds.
To grant organization access permissions to a service account, you need the
organization-manager.adminrole or higher.Cloud Center UICLITerraformAPI-
Log in to Yandex Identity Hub
using an administrator or organization owner account. -
In the left-hand panel, select
Access bindings. -
In the Account type filter, select
Service accounts. -
If the service account you need already has at least one role assigned, click
in the row with that service account and select Assign roles.If the service account is not on the list, click Assign roles in the top-right corner. In the window that opens, go to Service accounts and select the account from the list or use the search bar to locate it.
-
Click
Add role and select a role to assign to the service account. You can assign multiple roles.For descriptions of available roles, see the Yandex Cloud role reference in the Yandex Identity and Access Management documentation.
-
Click Save.
If you do not have the Yandex Cloud CLI yet, install and initialize it.
The folder used by default is the one specified when creating the CLI profile. To change the default folder, use the
yc config set folder-id <folder_ID>command. You can also specify a different folder for any command using--folder-nameor--folder-id.If you access a resource by its name, the search will be limited to the default folder. If you access a resource by its ID, the search will be global, i.e., through all folders based on access permissions.
To assign a role for an organization to a service account, run this command:
yc organization-manager organization add-access-binding <organization_name_or_ID> \ --role <role_ID> \ --service-account-id <service_account_ID>Where:
<organization_name_or_ID>: Technical name or ID of the organization.--role: Role ID, e.g.,viewer.--service-account-id: ID of the service account you are assigning the role to.
For example, to assign the
viewerrole for theMyOrgorganization to a service account:-
Select a role to assign to the service account. For role descriptions, see the Yandex Cloud role reference in the Yandex Identity and Access Management documentation.
-
Get a list of available organizations to find out their IDs and technical names:
yc organization-manager organization listResult:
+---------------------------------+---------------------------------+----------------------+ | ID | NAME | TITLE | +---------------------------------+---------------------------------+----------------------+ | bpf1smsil5q0******** | hdt5j5uw******** | MyOrg | +---------------------------------+---------------------------------+----------------------+The organization's technical name is in the
NAMEcolumn, and its ID, in theIDcolumn. -
Get the ID of the service account by its name:
yc iam service-account get my-robotResult:
id: aje6o61dvog2******** folder_id: b1gvmob95yys******** created_at: "2018-10-15T18:01:25Z" name: my-robotIf you do not know the name of your service account, get a full list of service accounts with their IDs:
yc iam service-account listResult:
+----------------------+------------------+-----------------+ | ID | NAME | DESCRIPTION | +----------------------+------------------+-----------------+ | aje6o61dvog2******** | my-robot | my description | +----------------------+------------------+-----------------+ -
Assign the
my-robotservice account theviewerrole for the organization with thebpf1smsil5q0********ID:yc organization-manager organization add-access-binding bpf1smsil5q0******** \ --role viewer \ --service-account-id aje6o61dvog2********
If you do not have Terraform yet, install it and configure the Yandex Cloud provider.
To manage infrastructure using Terraform under a service account or user accounts (a Yandex account, a federated account, or a local user), authenticate using the appropriate method.
-
In the configuration file, describe the resources you want to create:
Here is an example of the configuration file structure:
resource "yandex_organizationmanager_organization_iam_binding" "editor" { organization_id = "<organization_ID>" role = "<role>" members = ["serviceAccount:<service_account_ID>",] }Where:
organization_id: Organization ID. This is a required setting.role: Role. For role descriptions, see the Yandex Cloud role reference in the Yandex Identity and Access Management documentation. For each role, you can only use oneyandex_organizationmanager_organization_iam_bindingresource. This is a required setting.members: List of subjects getting the role. This is a required setting.
For more on the properties of the
yandex_organizationmanager_organization_iam_bindingresource, see this provider guide. -
Make sure the settings are correct.
-
In the command line, navigate to the directory that contains the current Terraform configuration files defining the infrastructure.
-
Run this command:
terraform validateTerraform will show any errors found in your configuration files.
-
-
Assign the role.
-
Run this command to view the planned changes:
terraform planIf you described the configuration correctly, the terminal will display a list of the resources to update and their parameters. This is a verification step that does not apply changes to your resources.
-
If everything looks correct, apply the changes:
-
Run this command:
terraform apply -
Confirm updating the resources.
-
Wait for the operation to complete.
-
This will assign access permissions for the organization. You can check the role assignment using the management console
or this CLI command:yc organization-manager organization list-access-bindings <organization_name_or_ID> -
To assign a role for an organization to a service account, use the updateAccessBindings REST API method for the Organization resource or the OrganizationService/UpdateAccessBindings gRPC API call:
-
Select a role to assign to the service account. For role descriptions, see the Yandex Cloud role reference in the Yandex Identity and Access Management documentation.
-
Get the ID of the folder with service accounts.
-
Get an IAM token for authentication in the Yandex Cloud API.
-
Get a list of service accounts in the folder to find out their IDs:
export FOLDER_ID=<folder_ID> export IAM_TOKEN=<IAM_token> curl \ --header "Authorization: Bearer ${IAM_TOKEN}" \ "https://iam.api.cloud.yandex.net/iam/v1/serviceAccounts?folderId=${FOLDER_ID}"Result:
{ "serviceAccounts": [ { "id": "ajebqtreob2d********", "folderId": "b1gvmob95yys********", "createdAt": "2018-10-18T13:42:40Z", "name": "my-robot", "description": "my description" } ] } -
Get a list of organizations to find out their IDs:
export IAM_TOKEN=<IAM_token> curl \ --header "Authorization: Bearer ${IAM_TOKEN}" \ --request GET \ "https://organization-manager.api.cloud.yandex.net/organization-manager/v1/organizations"Result:
{ "organizations": [ { "id": "bpfaidqca8vd********", "createdAt": "2023-04-07T08:11:54.313033Z", "name": "xvdq9q22********", "title": "MyOrg" } ] } -
Create a request body, e.g., in the
body.jsonfile. SpecifyADDin theactionproperty:body.json:
{ "accessBindingDeltas": [{ "action": "ADD", "accessBinding": { "roleId": "<role>", "subject": { "id": "<service_account_ID>", "type": "serviceAccount" } } }] }Where:
-
roleId: Role. -
subject: Subject getting the role.Subject designations
To indicate a subject, use a combination of its type and unique ID in the
subject.typeandsubject.idfields of the request. Here are possible combinations:subject.type
subject.id
userAccount<user_ID>serviceAccount<service_account_ID>federatedUser<user_ID>group<group_ID>systemallAuthenticatedUsers(
All authenticated usersgroup)allUsers(
All usersgroup)group:organization:<organization_ID>:users(
All users in organization Xgroup)group:federation:<federation_ID>:users(
All users in federation Ngroup)group:userpool:<pool_ID>:users(
All users in userpool Pgroup)
-
-
Assign the role to the service account:
export ORGANIZATION_ID=<organization_ID> export IAM_TOKEN=<IAM_token> curl \ --header "Content-Type: application/json" \ --header "Authorization: Bearer ${IAM_TOKEN}" \ --data '@body.json' \ --request POST \ "https://organization-manager.api.cloud.yandex.net/organization-manager/v1/organizations/${ORGANIZATION_ID}:updateAccessBindings"
- In the management console
-
Get the key ID and access key of the service account you created:
Management consoleCLIAPI-
In the management console
, select the folder the service account belongs to. -
Navigate
to Identity and Access Management. -
In the left-hand panel, select
Service accounts and then select the required service account. -
Click Create new key in the top panel.
-
Select Create static access key.
-
Enter a description of the key so that you can easily find it in the management console.
-
Save the ID and secret key.
Alert
After you close this dialog, the key value will no longer be available.
The folder used by default is the one specified when creating the CLI profile. To change the default folder, use the
yc config set folder-id <folder_ID>command. You can also specify a different folder for any command using--folder-nameor--folder-id.If you access a resource by its name, the search will be limited to the default folder. If you access a resource by its ID, the search will be global, i.e., through all folders based on access permissions.
-
View the description of the command for creating a static access key:
yc iam access-key create --help -
Select a service account, e.g.,
my-robot:yc iam service-account list +----------------------+------------------+-------------------------------+ | ID | NAME | DESCRIPTION | +----------------------+------------------+-------------------------------+ | aje6o61dvog2******** | my-robot | | ... -
Create an access key for the
my-robotservice account:yc iam access-key create --service-account-name my-robot access_key: id: aje6t3vsbj8l******** service_account_id: ajepg0mjt06s******** created_at: "2018-11-22T14:37:51Z" key_id: 0n8X6WY6S24N******** secret: JyTRFdqw8t1kh2-OJNz4JX5ZTz9Dj1rI******** -
Save the
key_idandsecretvalues. You will not be able to get the secret key again.
-
-
Install the AWS CLI
. -
Configure the AWS CLI environment: Run the
aws configurecommand and enter the previously saved key ID and secret key one by one. Useru-central1as the region:aws configure AWS Access Key ID [None]: AKIAIOSFODNN******** AWS Secret Access Key [None]: wJalr********/*******/bPxRfiCYEX******** Default region name [None]: ru-central1 Default output format [None]:This will create the
~/.aws/credentialsand~/.aws/configfiles (C:\Users\USERNAME\.aws\credentialsandC:\Users\USERNAME\.aws\configon Windows). -
Check that the settings are correct by running the table listing command against the database you created. For
--endpoint, specify the Document API endpoint you can find in the Overview tab of your database in the management console .aws dynamodb list-tables \ --endpoint https://docapi.serverless.yandexcloud.net/ru-central1/b1gia87mbaomkfvs6rgl/etnudu2n9ri35luqe4h1Result:
{ "TableNames": [ ] }