Links
- Site: https://yandex.cloud
This is the multi-page printable view of this section. Click here to print.
Describe organization-level Yandex Cloud folder provisioning derived from Vault
AppRole identities. The direct infra/yandex_cloud owner currently contains one
concrete organization package, org1, covered here. This baseline does not
assert that the cloud organization or its folders were inspected live.
Baseline source revision: 550d7e79b1f5fdbc2b6017b75178471d6914082f.
Observation date: 2026-09-08. Sources are linked in full; no excerpts are used.
Sources: top-level documentation, organization package, organization targets, Terraform packaging, folder derivation, provider configuration, and credential injection.
The Yandex Cloud tree SHALL expose its documentation through the infrastructure
documentation boundary and keep org1’s AL configuration and Terraform package
under infra/yandex_cloud/org1.
org1 identifies the current organization configuration//infra/yandex_cloud/org1:alTerraform SHALL read the Vault identity group named approles, resolve its
member entities, and instantiate the shared yc_folder module once per entity
name. Folder names SHALL replace underscores with hyphens, and secret references
SHALL use the corresponding yandex.cloud/org1/folders/ path.
approles group contains an entity named example_serviceexample-serviceyandex.cloud/org1/folders/example-servicecloud_id variableThe Terraform Bazel package SHALL include its provider lock, shared folder and
backend modules, and Vault backend and injector tools. Its operational wrapper
SHALL select the Terraform plugin and the default_default Vault environment;
the package SHALL also expose the configured Terraform test map.