For extended API usage, such as setting max_size, folder_id, anonymous_access_flags, default_storage_class and https parameters for bucket, will be used default authorization method, i.e. IAM / OAuth token from provider block will be used. This might be a little bit confusing in cases when separate service account is used for managing buckets because in this case buckets will be accessed by two different accounts that might have different permissions for buckets.
yandex_storage_bucket
returns HTTP 403 when trying to set bucket policy.There is somewhat similar issue https://github.com/yandex-cloud/terraform-provider-yandex/issues/261 No solution is mentioned there, only a handwavy pointer to docs:
CLI error: