> ## Documentation Index
> Fetch the complete documentation index at: https://opensre.com/docs/llms.txt
> Use this file to discover all available pages before exploring further.

# Yandex Cloud

> Connect OpenSRE to a Yandex Cloud folder

OpenSRE reads a Yandex Cloud folder to investigate incidents in it. This page
covers connecting the account; the tools that read metrics, logs and resources
arrive in follow-up releases.

## What you need

**A folder ID.** Every Yandex Cloud read is folder-scoped — the Monitoring API
rejects cross-folder queries outright — so nothing works without it. Take it
from the console URL, or run:

```bash theme={null}
yc config get folder-id
```

**One credential.** Four kinds work, in the order you would normally reach for
them:

| Credential                  | Use it when                                                  |
| --------------------------- | ------------------------------------------------------------ |
| Service-account key file    | the normal choice for anything unattended                    |
| Service-account key, inline | same, where there is no writable filesystem                  |
| OAuth token                 | quick local use with your own account                        |
| IAM token                   | short-lived, mostly for testing — it expires within 12 hours |

**Or nothing at all.** Running on a Yandex Cloud VM with an attached service
account, the instance metadata service issues tokens and already knows the
folder. Choose that mode and there is nothing to type or store.

## Permissions

Grant the service account **`viewer`** on the folder. OpenSRE only reads: the
client sends `GET` and nothing else, and every mutating Yandex Cloud API uses a
different verb.

## Connect

```bash theme={null}
opensre integrations setup yandex_cloud
```

The wizard asks how to authenticate, then for the folder and the credential.
On a Yandex Cloud VM the folder and cloud ids are filled in from the instance,
so pressing enter accepts them.

Check it:

```bash theme={null}
opensre integrations verify yandex_cloud
```

A working connection reports the folder name and how many service endpoints
answered.

## Environment variables

Setting these connects the integration without running the wizard — useful in a
container or CI job. Supply `YC_FOLDER_ID` plus exactly one credential.

| Variable          | Meaning                                                      |
| ----------------- | ------------------------------------------------------------ |
| `YC_FOLDER_ID`    | folder to read; required unless `YC_USE_METADATA` is set     |
| `YC_CLOUD_ID`     | only needed by the APIs that list folders                    |
| `YC_SA_KEY_FILE`  | path to an authorized key JSON file                          |
| `YC_SA_KEY`       | the same key inline                                          |
| `YC_TOKEN`        | OAuth token                                                  |
| `YC_IAM_TOKEN`    | ready IAM token                                              |
| `YC_USE_METADATA` | `true` on a Yandex Cloud VM with an attached service account |

The names match the ones the `yc` CLI already reads, so a shell that can run
`yc` can run OpenSRE without a second set of exports.

## Troubleshooting

**"Yandex Cloud needs a folder\_id".** The folder is missing and the credential
is not the metadata service. Set `YC_FOLDER_ID`, or choose the instance
metadata mode when running on a VM.

**Verification fails with a permission error.** The service account has no
`viewer` on that folder — check that the role was granted on the folder you
configured, not on a different one.

**The key file cannot be read.** `YC_SA_KEY_FILE` must point at the authorized
key JSON produced by `yc iam key create`, readable by the user running OpenSRE.
