[Yandex Cloud documentation](../../../index.md) > [Yandex Cloud Registry](../../index.md) > [Step-by-step guides](../index.md) > Managing a registry > IP address access policy > Setting up an access policy

# Configuring a registry access policy

You can set up policies for accessing a [registry](../../concepts/registry.md) from specific [IP addresses](../../../vpc/concepts/address.md).

{% list tabs group=instructions %}

- Management console {#console}

  1. In the [management console](https://console.yandex.cloud), select the [folder](../../../resource-manager/concepts/resources-hierarchy.md#folder) where the registry is located.
  1. Navigate to **Cloud Registry**.
  1. Select the registry.
  1. Navigate to the **Access for IP addresses** tab.
  1. Click **Configure access**.
  1. Enter the IP address and specify an action:
     * `PULL`: Permission to pull [artifacts](../../concepts/artifacts/index.md) from the registry.
     * `PUSH`: Permission to push artifacts to the registry.
  1. To configure access for multiple IPs, click **Add**.
  1. Click **Save**.

- CLI {#cli}

  If you do not have the Yandex Cloud CLI yet, [install and initialize it](../../../cli/quickstart.md#install).

  The folder used by default is the one specified when [creating](../../../cli/operations/profile/profile-create.md) the CLI profile. To change the default folder, use the `yc config set folder-id <folder_ID>` command. You can also specify a different folder for any command using `--folder-name` or `--folder-id`. If you access a resource by its name, the search will be limited to the default folder. If you access a resource by its ID, the search will be global, i.e., through all folders based on access permissions.

  1. Set the registry access policy:

     ```bash
     yc cloud-registry registry add-ip-permissions <registry_name_or_ID> \
       --pull <IP_address> \
       --push <IP_address>
     ```

     Where:
     * `--pull`: Flag that allows pulling [artifacts](../../concepts/artifacts/index.md) from the registry.
     * `--push`: Flag that allows pushing artifacts into the registry.

     Result:

     ```text
     done (1s)
     ```

     To delete all configured registry access policies and set new ones right away, use the `yc cloud-registry registry set-ip-permissions` command.

  1. Check the current permissions:

     ```bash
     yc cloud-registry registry list-ip-permissions <registry_name_or_ID>
     ```

     Result:

     ```text
     +--------+-----------+
     | ACTION |    IP     |
     +--------+-----------+
     | PULL   | 10.1.2.11 |
     | PUSH   | 10.1.2.11 |
     +--------+-----------+
     ```
- API {#api}

  To configure a registry access policy, use the [updateIpPermissions](../../api-ref/Registry/updateIpPermissions.md) REST API method for the [Registry](../../api-ref/Registry/index.md) resource or the [RegistryService/UpdateIpPermissions](../../api-ref/grpc/Registry/updateIpPermissions.md) gRPC API call.

{% endlist %}