תפקידים והרשאות

בדף הזה מפורטים התפקידים וההרשאות של IAM עבור Agent Registry.

מעניקים תפקידי IAM מתאימים של Agent Registry למשתמשים או לקבוצות שינהלו או יצפו בסוכנים ב-Agent Registry. כדי להקצות תפקידים, אפשר להשתמש בדף IAM במסוף Google Cloud או ב-Google Cloud CLI. הוראות מפורטות מופיעות במאמר ניהול הגישה לפרויקטים, לתיקיות ולארגונים.

תפקידים ב-Agent Registry

בטבלה הבאה מתוארים תפקידי ה-IAM של Agent Registry והאחריות האופיינית שלהם:

תפקיד

תיאור

מטרה

Agent Registry API Admin

ביצוע כל הפעולות, כולל רישום ידני של סוכנים ועדכון של מטא-נתונים.

  • רישום וניהול של סוכנים ושרתי MCP.
  • עדכון ההגדרות של כלי ונקודות קצה.

Agent Registry API Editor

עריכת הגישה למשאבים של Agent Registry.

  • רישום וניהול של סוכנים ושרתי MCP.
  • עדכון ההגדרות ונקודות הקצה של כלי.

Agent Registry API Viewer

צפייה בסוכנים, בכלים ובמאפיינים שלהם.

  • לגלות אילו סוכנים ושרתי MCP זמינים.
  • צפייה במיומנויות A2A, במיומנויות עצמאיות ובנקודות קצה לשילוב.

משתמש ב-Agent Registry

יצירה, עדכון ומחיקה של מיומנויות וגרסאות של מיומנויות.

  • ניהול סקילים עצמאיים של סוכנים במאגר הסוכנים.
  • לשמור את ניהול הגרסאות של שינויים בסקילים ולנהל באופן מרכזי את המצבים הפעילים של הסקילים.

הרשאות של Agent Registry

בטבלה הבאה מפורטות ההרשאות של כל תפקיד IAM ב-Agent Registry:

(roles/agentregistry.admin)

גישה מלאה למשאבי Agent Registry API.

agentregistry.*

  • agentregistry.agents.get
  • agentregistry.agents.list
  • agentregistry.agents.search
  • agentregistry.bindings.create
  • agentregistry.bindings.delete
  • agentregistry.bindings.fetchAvailable
  • agentregistry.bindings.get
  • agentregistry.bindings.list
  • agentregistry.bindings.update
  • agentregistry.endpoints.get
  • agentregistry.endpoints.list
  • agentregistry.locations.get
  • agentregistry.locations.list
  • agentregistry.mcpServers.get
  • agentregistry.mcpServers.list
  • agentregistry.mcpServers.search
  • agentregistry.operations.cancel
  • agentregistry.operations.delete
  • agentregistry.operations.get
  • agentregistry.operations.list
  • agentregistry.publishers.get
  • agentregistry.publishers.list
  • agentregistry.services.create
  • agentregistry.services.delete
  • agentregistry.services.get
  • agentregistry.services.list
  • agentregistry.services.update
  • agentregistry.skillRevisions.create
  • agentregistry.skillRevisions.delete
  • agentregistry.skillRevisions.get
  • agentregistry.skillRevisions.list
  • agentregistry.skills.create
  • agentregistry.skills.delete
  • agentregistry.skills.get
  • agentregistry.skills.list
  • agentregistry.skills.search
  • agentregistry.skills.update

(roles/agentregistry.editor)

עריכת הגישה למשאבי Agent Registry API.

agentregistry.agents.*

  • agentregistry.agents.get
  • agentregistry.agents.list
  • agentregistry.agents.search

agentregistry.bindings.fetchAvailable

agentregistry.bindings.get

agentregistry.bindings.list

agentregistry.endpoints.*

  • agentregistry.endpoints.get
  • agentregistry.endpoints.list

agentregistry.locations.*

  • agentregistry.locations.get
  • agentregistry.locations.list

agentregistry.mcpServers.*

  • agentregistry.mcpServers.get
  • agentregistry.mcpServers.list
  • agentregistry.mcpServers.search

agentregistry.operations.*

  • agentregistry.operations.cancel
  • agentregistry.operations.delete
  • agentregistry.operations.get
  • agentregistry.operations.list

agentregistry.publishers.*

  • agentregistry.publishers.get
  • agentregistry.publishers.list

agentregistry.services.*

  • agentregistry.services.create
  • agentregistry.services.delete
  • agentregistry.services.get
  • agentregistry.services.list
  • agentregistry.services.update

agentregistry.skillRevisions.*

  • agentregistry.skillRevisions.create
  • agentregistry.skillRevisions.delete
  • agentregistry.skillRevisions.get
  • agentregistry.skillRevisions.list

agentregistry.skills.*

  • agentregistry.skills.create
  • agentregistry.skills.delete
  • agentregistry.skills.get
  • agentregistry.skills.list
  • agentregistry.skills.search
  • agentregistry.skills.update

(roles/agentregistry.viewer)

גישה לקריאה בלבד למשאבים של Agent Registry API.

agentregistry.agents.*

  • agentregistry.agents.get
  • agentregistry.agents.list
  • agentregistry.agents.search

agentregistry.bindings.fetchAvailable

agentregistry.bindings.get

agentregistry.bindings.list

agentregistry.endpoints.*

  • agentregistry.endpoints.get
  • agentregistry.endpoints.list

agentregistry.locations.*

  • agentregistry.locations.get
  • agentregistry.locations.list

agentregistry.mcpServers.*

  • agentregistry.mcpServers.get
  • agentregistry.mcpServers.list
  • agentregistry.mcpServers.search

agentregistry.operations.get

agentregistry.operations.list

agentregistry.publishers.*

  • agentregistry.publishers.get
  • agentregistry.publishers.list

agentregistry.services.get

agentregistry.services.list

agentregistry.skillRevisions.get

agentregistry.skillRevisions.list

agentregistry.skills.get

agentregistry.skills.list

agentregistry.skills.search

(roles/agentregistry.user)

יצירה, עדכון ומחיקה של סקילים וגרסאות של סקילים.

agentregistry.agents.*

  • agentregistry.agents.get
  • agentregistry.agents.list
  • agentregistry.agents.search

agentregistry.bindings.fetchAvailable

agentregistry.bindings.get

agentregistry.bindings.list

agentregistry.endpoints.*

  • agentregistry.endpoints.get
  • agentregistry.endpoints.list

agentregistry.locations.*

  • agentregistry.locations.get
  • agentregistry.locations.list

agentregistry.mcpServers.*

  • agentregistry.mcpServers.get
  • agentregistry.mcpServers.list
  • agentregistry.mcpServers.search

agentregistry.operations.get

agentregistry.operations.list

agentregistry.publishers.*

  • agentregistry.publishers.get
  • agentregistry.publishers.list

agentregistry.services.get

agentregistry.services.list

agentregistry.skillRevisions.*

  • agentregistry.skillRevisions.create
  • agentregistry.skillRevisions.delete
  • agentregistry.skillRevisions.get
  • agentregistry.skillRevisions.list

agentregistry.skills.*

  • agentregistry.skills.create
  • agentregistry.skills.delete
  • agentregistry.skills.get
  • agentregistry.skills.list
  • agentregistry.skills.search
  • agentregistry.skills.update

מידע נוסף על הרשאות IAM זמין במאמרים איך מוצאים את התפקידים המוגדרים מראש שמתאימים לכם ואינדקס של תפקידים והרשאות ב-IAM.

בקרת גישה למשאבים רשומים

תפקידים ב-Agent Registry קובעים מי יכול לנהל ולגלות משאבים ב-Agent Registry עצמו. כדי לקבוע אילו סוכנים יכולים לתקשר עם שירותים, נקודות קצה ושרתי MCP רשומים דרך Agent Gateway, משתמשים במדיניות יציאה של Identity-Aware Proxy:

  • הרשאות גישה ליציאה: כדי לתת לסוכן הרשאה להפנות תנועה לסוכן רשום, לשרת MCP או לנקודת קצה, צריך לתת לסוכן את התפקיד IAP-secured Egressor ‏ (roles/iap.egressor) בזהות החשבון הראשי של הסוכן במשאב היעד.
  • הרשאות ניהול מדיניות: כדי להגדיר מדיניות IAM של IAP לאינטרנט במשאבים רשומים, צריך לקבל את התפקיד IAP Policy Admin (roles/iap.admin) בפרויקט שמארח את המרשם.

הוראות מפורטות להגדרת מדיניות יציאה של IAP מופיעות במאמר הגדרת מדיניות של סוכן IAM.