Para limitar el acceso de los usuarios de un proyecto o una organización, puedes usar roles de gestión de identidades y accesos (IAM) para Dataflow. Puedes controlar el acceso a los recursos relacionados con Dataflow, en lugar de conceder a los usuarios el rol Lector, Editor o Propietario en todo el proyecto de Google Cloud Platform.
En esta página se explica cómo usar los roles de gestión de identidades y accesos de Dataflow. Para obtener una descripción detallada de IAM y de sus características, consulta la documentación de IAM.
Todos los métodos de Dataflow exigen que el llamador cuente con los permisos necesarios. Para ver una lista de los permisos y roles que admite Dataflow, consulta la siguiente sección.
Permisos y roles
En esta sección se resumen los permisos y roles que admite la gestión de identidades y accesos de Dataflow.
Permisos obligatorios
En la siguiente tabla se indican los permisos que debe tener el llamante para invocar cada método:
| Método | Permisos obligatorios |
|---|---|
dataflow.jobs.create |
dataflow.jobs.create |
dataflow.jobs.cancel |
dataflow.jobs.cancel |
dataflow.jobs.updateContents |
dataflow.jobs.updateContents |
dataflow.jobs.list |
dataflow.jobs.list |
dataflow.jobs.get |
dataflow.jobs.get |
dataflow.messages.list |
dataflow.messages.list |
dataflow.metrics.get |
dataflow.metrics.get |
dataflow.jobs.snapshot |
dataflow.jobs.snapshot |
Roles
En la siguiente tabla se indican los roles de gestión de identidades y accesos de Dataflow, así como una lista de los permisos relacionados con Dataflow que incluye cada rol. Cada permiso se aplica a un tipo de recurso concreto. Para ver una lista de permisos, consulta la página Roles de la consolaGoogle Cloud .
(
Minimal role for creating and managing dataflow jobs.
(
Provides the permissions necessary to execute and manipulate
Dataflow jobs.
Lowest-level resources where you can grant this role:
(
Gives Cloud Dataflow service account access to managed resources. Includes access to service accounts.
(
Provides read-only access to all Dataflow-related
resources.
Lowest-level resources where you can grant this role: (
Provides the permissions necessary for a Compute Engine service
account to execute work units for a Dataflow pipeline.
Lowest-level resources where you can grant this role:
Role
Permissions
Dataflow Admin
roles/)
cloudbuild.builds.createcloudbuild.builds.getcloudbuild.builds.listcloudbuild.builds.updatecloudbuild.locations.*
cloudbuild.locations.getcloudbuild.locations.listcloudbuild.operations.*
cloudbuild.operations.getcloudbuild.operations.listcloudkms.keyHandles.*
cloudkms.keyHandles.createcloudkms.keyHandles.getcloudkms.keyHandles.listcloudkms.operations.getcloudkms.compute.machineTypes.getcompute.projects.getcompute.regions.listcompute.zones.listdataflow.jobs.*
dataflow.jobs.canceldataflow.jobs.createdataflow.jobs.getdataflow.jobs.listdataflow.jobs.snapshotdataflow.jobs.updateContentsdataflow.messages.listdataflow.metrics.getdataflow.snapshots.*
dataflow.snapshots.deletedataflow.snapshots.getdataflow.snapshots.listrecommender.
recommender.recommender.recommender.remotebuildexecution.blobs.getresourcemanager.projects.getresourcemanager.projects.liststorage.buckets.getstorage.objects.createstorage.objects.getstorage.objects.list
Dataflow Developer
roles/)
cloudbuild.builds.createcloudbuild.builds.getcloudbuild.builds.listcloudbuild.builds.updatecloudbuild.locations.*
cloudbuild.locations.getcloudbuild.locations.listcloudbuild.operations.*
cloudbuild.operations.getcloudbuild.operations.listcloudkms.keyHandles.*
cloudkms.keyHandles.createcloudkms.keyHandles.getcloudkms.keyHandles.listcloudkms.operations.getcloudkms.compute.projects.getcompute.regions.listcompute.zones.listdataflow.jobs.*
dataflow.jobs.canceldataflow.jobs.createdataflow.jobs.getdataflow.jobs.listdataflow.jobs.snapshotdataflow.jobs.updateContentsdataflow.messages.listdataflow.metrics.getdataflow.snapshots.*
dataflow.snapshots.deletedataflow.snapshots.getdataflow.snapshots.listrecommender.
recommender.recommender.recommender.remotebuildexecution.blobs.getresourcemanager.projects.getresourcemanager.projects.list
Cloud Dataflow Service Agent
roles/)
backupdr.backupdr.backupdr.backupdr.backupdr.backupdr.backupdr.backupdr.backupdr.backupdr.backupdr.backupdr.backupPlans.getbackupdr.backupPlans.listbackupdr.backupdr.backupdr.backupVaults.getbackupdr.backupVaults.listbackupdr.locations.listbackupdr.operations.getbackupdr.operations.listbackupdr.bigquery.bireservations.*
bigquery.bireservations.getbigquery.bireservations.updatebigquery.capacityCommitments.*
bigquery.bigquery.bigquery.bigquery.bigquery.bigquery.config.*
bigquery.config.getbigquery.config.updatebigquery.connections.*
bigquery.connections.createbigquery.connections.delegatebigquery.connections.deletebigquery.connections.getbigquery.bigquery.connections.listbigquery.bigquery.connections.updatebigquery.connections.updateTagbigquery.connections.usebigquery.dataPolicies.attachbigquery.dataPolicies.createbigquery.dataPolicies.deletebigquery.dataPolicies.getbigquery.bigquery.dataPolicies.listbigquery.bigquery.dataPolicies.updatebigquery.datasets.*
bigquery.datasets.createbigquery.bigquery.datasets.deletebigquery.bigquery.datasets.getbigquery.datasets.getIamPolicybigquery.datasets.linkbigquery.bigquery.bigquery.bigquery.datasets.setIamPolicybigquery.datasets.updatebigquery.datasets.updateTagbigquery.jobs.*
bigquery.jobs.createbigquery.bigquery.jobs.deletebigquery.jobs.getbigquery.jobs.listbigquery.jobs.listAllbigquery.bigquery.jobs.updatebigquery.models.*
bigquery.models.createbigquery.models.deletebigquery.models.exportbigquery.models.getDatabigquery.models.getMetadatabigquery.models.listbigquery.models.updateDatabigquery.models.updateMetadatabigquery.models.updateTagbigquery.objectRefs.*
bigquery.objectRefs.readbigquery.objectRefs.writebigquery.readsessions.*
bigquery.readsessions.createbigquery.readsessions.getDatabigquery.readsessions.updatebigquery.
bigquery.bigquery.bigquery.bigquery.bigquery.reservationGroups.*
bigquery.bigquery.bigquery.reservationGroups.getbigquery.bigquery.reservations.*
bigquery.reservations.createbigquery.reservations.deletebigquery.reservations.getbigquery.reservations.listbigquery.bigquery.reservations.updatebigquery.reservations.usebigquery.routines.*
bigquery.routines.createbigquery.routines.deletebigquery.routines.getbigquery.routines.listbigquery.routines.updatebigquery.routines.updateTagbigquery.bigquery.bigquery.rowAccessPolicies.getbigquery.bigquery.bigquery.bigquery.bigquery.bigquery.savedqueries.*
bigquery.savedqueries.createbigquery.savedqueries.deletebigquery.savedqueries.getbigquery.savedqueries.listbigquery.savedqueries.updatebigquery.tables.*
bigquery.tables.createbigquery.tables.createIndexbigquery.tables.createSnapshotbigquery.bigquery.tables.deletebigquery.tables.deleteIndexbigquery.tables.deleteSnapshotbigquery.bigquery.tables.exportbigquery.tables.getbigquery.tables.getDatabigquery.tables.getIamPolicybigquery.tables.listbigquery.bigquery.bigquery.tables.replicateDatabigquery.bigquery.tables.setCategorybigquery.bigquery.tables.setIamPolicybigquery.tables.updatebigquery.tables.updateDatabigquery.tables.updateIndexbigquery.tables.updateTagbigquery.transfers.*
bigquery.transfers.getbigquery.transfers.updatebigquerymigration.clouddebugger.breakpoints.listclouddebugger.clouddebugger.clouddebugger.debuggees.createcloudnotifications.compute.acceleratorTypes.*
compute.acceleratorTypes.getcompute.acceleratorTypes.listcompute.addresses.*
compute.addresses.createcompute.compute.compute.addresses.deletecompute.compute.compute.addresses.getcompute.addresses.listcompute.compute.compute.addresses.setLabelscompute.addresses.usecompute.addresses.useInternalcompute.autoscalers.*
compute.autoscalers.createcompute.autoscalers.deletecompute.autoscalers.getcompute.autoscalers.listcompute.autoscalers.updatecompute.backendBuckets.*
compute.compute.backendBuckets.createcompute.compute.backendBuckets.deletecompute.compute.compute.backendBuckets.getcompute.compute.backendBuckets.listcompute.compute.compute.compute.compute.backendBuckets.updatecompute.backendBuckets.usecompute.backendServices.*
compute.compute.backendServices.createcompute.compute.backendServices.deletecompute.compute.compute.backendServices.getcompute.compute.backendServices.listcompute.compute.compute.compute.compute.backendServices.updatecompute.backendServices.usecompute.crossSiteNetworks.*
compute.compute.compute.crossSiteNetworks.getcompute.crossSiteNetworks.listcompute.compute.diskSettings.*
compute.diskSettings.getcompute.diskSettings.updatecompute.diskTypes.*
compute.diskTypes.getcompute.diskTypes.listcompute.disks.*
compute.compute.disks.createcompute.disks.createSnapshotcompute.disks.createTagBindingcompute.disks.deletecompute.disks.deleteTagBindingcompute.disks.getcompute.disks.getIamPolicycompute.disks.listcompute.compute.disks.listTagBindingscompute.compute.disks.resizecompute.disks.setIamPolicycompute.disks.setLabelscompute.compute.compute.compute.disks.updatecompute.disks.updateKmsKeycompute.disks.usecompute.disks.useReadOnlycompute.externalVpnGateways.*
compute.compute.compute.compute.compute.compute.compute.compute.compute.compute.compute.firewallPolicies.getcompute.firewallPolicies.listcompute.compute.compute.firewallPolicies.usecompute.firewalls.getcompute.firewalls.listcompute.compute.compute.forwardingRules.*
compute.forwardingRules.createcompute.compute.forwardingRules.deletecompute.compute.forwardingRules.getcompute.forwardingRules.listcompute.compute.compute.compute.compute.compute.compute.compute.compute.forwardingRules.updatecompute.forwardingRules.usecompute.globalAddresses.*
compute.globalAddresses.createcompute.compute.compute.globalAddresses.deletecompute.compute.compute.globalAddresses.getcompute.globalAddresses.listcompute.compute.compute.compute.globalAddresses.usecompute.
compute.compute.compute.compute.compute.compute.compute.compute.compute.compute.compute.compute.compute.compute.compute.compute.
compute.compute.compute.compute.compute.compute.compute.compute.compute.compute.compute.compute.globalOperations.getcompute.globalOperations.listcompute.compute.compute.compute.compute.healthChecks.*
compute.healthChecks.createcompute.compute.healthChecks.deletecompute.compute.healthChecks.getcompute.healthChecks.listcompute.compute.compute.healthChecks.updatecompute.healthChecks.usecompute.compute.httpHealthChecks.*
compute.compute.compute.compute.compute.httpHealthChecks.getcompute.httpHealthChecks.listcompute.compute.compute.compute.httpHealthChecks.usecompute.compute.httpsHealthChecks.*
compute.compute.compute.compute.compute.httpsHealthChecks.getcompute.httpsHealthChecks.listcompute.compute.compute.compute.httpsHealthChecks.usecompute.compute.images.*
compute.images.createcompute.compute.images.deletecompute.compute.images.deprecatecompute.images.getcompute.images.getFromFamilycompute.images.getIamPolicycompute.images.listcompute.compute.images.listTagBindingscompute.images.setIamPolicycompute.images.setLabelscompute.images.updatecompute.images.useReadOnlycompute.
compute.compute.compute.compute.compute.compute.compute.compute.compute.compute.compute.instanceGroups.*
compute.instanceGroups.createcompute.compute.instanceGroups.deletecompute.compute.instanceGroups.getcompute.instanceGroups.listcompute.compute.compute.instanceGroups.updatecompute.instanceGroups.usecompute.instanceSettings.getcompute.instanceTemplates.*
compute.compute.compute.instanceTemplates.getcompute.compute.instanceTemplates.listcompute.compute.compute.instances.*
compute.compute.compute.compute.instances.attachDiskcompute.instances.createcompute.compute.instances.deletecompute.compute.compute.compute.instances.detachDiskcompute.instances.getcompute.compute.compute.instances.getIamPolicycompute.compute.compute.compute.compute.instances.listcompute.compute.compute.compute.instances.osAdminLogincompute.instances.osLogincompute.compute.compute.instances.resetcompute.instances.resumecompute.compute.compute.compute.instances.setIamPolicycompute.instances.setLabelscompute.compute.compute.instances.setMetadatacompute.compute.instances.setNamecompute.compute.compute.compute.compute.compute.instances.setTagscompute.compute.instances.startcompute.compute.instances.stopcompute.instances.suspendcompute.instances.updatecompute.compute.compute.compute.compute.compute.compute.instances.usecompute.instances.useReadOnlycompute.instantSnapshots.*
compute.compute.compute.compute.instantSnapshots.getcompute.compute.instantSnapshots.listcompute.compute.compute.compute.
compute.compute.compute.compute.compute.compute.
compute.compute.compute.compute.compute.compute.compute.compute.compute.compute.compute.compute.interconnectGroups.*
compute.compute.compute.interconnectGroups.getcompute.compute.compute.
compute.compute.compute.
compute.compute.compute.interconnects.*
compute.interconnects.createcompute.compute.interconnects.deletecompute.compute.interconnects.getcompute.compute.interconnects.listcompute.compute.compute.compute.interconnects.updatecompute.interconnects.usecompute.licenseCodes.*
compute.licenseCodes.getcompute.compute.licenseCodes.listcompute.compute.licenses.*
compute.licenses.createcompute.licenses.deletecompute.licenses.getcompute.licenses.getIamPolicycompute.licenses.listcompute.licenses.setIamPolicycompute.licenses.updatecompute.machineImages.*
compute.machineImages.createcompute.machineImages.deletecompute.machineImages.getcompute.compute.machineImages.listcompute.compute.compute.compute.machineTypes.*
compute.machineTypes.getcompute.machineTypes.listcompute.multiMig.*
compute.multiMig.createcompute.multiMig.deletecompute.multiMig.getcompute.multiMig.listcompute.networkAttachments.*
compute.compute.compute.compute.compute.networkAttachments.getcompute.compute.compute.compute.compute.compute.compute.networkAttachments.usecompute.
compute.compute.compute.compute.compute.compute.compute.compute.compute.compute.compute.compute.networkProfiles.*
compute.networkProfiles.getcompute.networkProfiles.listcompute.networks.*
compute.networks.accesscompute.networks.addPeeringcompute.networks.createcompute.compute.networks.deletecompute.compute.networks.getcompute.compute.compute.networks.listcompute.compute.compute.compute.networks.mirrorcompute.networks.removePeeringcompute.compute.compute.compute.networks.updatecompute.networks.updatePeeringcompute.networks.updatePolicycompute.networks.usecompute.networks.useExternalIpcompute.packetMirrorings.getcompute.packetMirrorings.listcompute.compute.compute.projects.getcompute.compute.compute.compute.compute.compute.compute.compute.regionBackendBuckets.*
compute.compute.compute.compute.compute.compute.compute.compute.compute.compute.compute.compute.compute.
compute.compute.compute.compute.compute.compute.compute.compute.compute.compute.compute.compute.compute.compute.
compute.compute.compute.compute.compute.compute.compute.compute.compute.compute.compute.
compute.compute.compute.compute.compute.compute.
compute.compute.compute.compute.compute.compute.compute.regionHealthChecks.*
compute.compute.compute.compute.compute.regionHealthChecks.getcompute.compute.compute.compute.compute.regionHealthChecks.usecompute.compute.regionHealthSources.*
compute.compute.compute.compute.compute.compute.
compute.compute.compute.compute.compute.compute.compute.compute.compute.compute.compute.compute.
compute.compute.compute.compute.compute.compute.compute.
compute.compute.compute.compute.compute.compute.compute.regionOperations.getcompute.regionOperations.listcompute.compute.compute.compute.compute.compute.compute.compute.compute.compute.regionSslPolicies.*
compute.compute.compute.compute.compute.regionSslPolicies.getcompute.regionSslPolicies.listcompute.compute.compute.compute.compute.regionSslPolicies.usecompute.
compute.compute.compute.compute.compute.compute.compute.compute.compute.compute.compute.
compute.compute.compute.compute.compute.compute.compute.compute.compute.compute.compute.compute.compute.
compute.compute.compute.compute.compute.compute.compute.compute.compute.compute.regionUrlMaps.*
compute.regionUrlMaps.createcompute.compute.regionUrlMaps.deletecompute.compute.regionUrlMaps.getcompute.compute.regionUrlMaps.listcompute.compute.compute.regionUrlMaps.updatecompute.regionUrlMaps.usecompute.regionUrlMaps.validatecompute.regions.*
compute.regions.getcompute.regions.listcompute.reservationBlocks.getcompute.reservationBlocks.listcompute.reservationSubBlocks.*
compute.compute.compute.compute.compute.reservations.getcompute.reservations.listcompute.resourcePolicies.*
compute.compute.compute.resourcePolicies.getcompute.compute.resourcePolicies.listcompute.compute.compute.resourcePolicies.usecompute.compute.routers.*
compute.routers.createcompute.compute.routers.deletecompute.compute.compute.routers.getcompute.routers.getRoutePolicycompute.routers.listcompute.routers.listBgpRoutescompute.compute.compute.compute.routers.updatecompute.compute.routers.usecompute.routes.*
compute.routes.createcompute.compute.routes.deletecompute.compute.routes.getcompute.routes.listcompute.compute.routes.listTagBindingscompute.securityPolicies.getcompute.securityPolicies.listcompute.compute.compute.securityPolicies.usecompute.serviceAttachments.*
compute.compute.compute.compute.compute.serviceAttachments.getcompute.compute.compute.compute.compute.compute.compute.serviceAttachments.usecompute.snapshots.*
compute.snapshots.createcompute.compute.snapshots.deletecompute.compute.snapshots.getcompute.snapshots.getIamPolicycompute.snapshots.listcompute.compute.compute.snapshots.setIamPolicycompute.snapshots.setLabelscompute.snapshots.updateKmsKeycompute.snapshots.useReadOnlycompute.sslCertificates.getcompute.sslCertificates.listcompute.compute.compute.sslPolicies.*
compute.sslPolicies.createcompute.compute.sslPolicies.deletecompute.compute.sslPolicies.getcompute.sslPolicies.listcompute.compute.compute.compute.sslPolicies.updatecompute.sslPolicies.usecompute.storagePools.*
compute.storagePools.createcompute.storagePools.deletecompute.storagePools.getcompute.compute.storagePools.listcompute.compute.storagePools.updatecompute.storagePools.usecompute.subnetworks.*
compute.subnetworks.createcompute.compute.subnetworks.deletecompute.compute.compute.subnetworks.getcompute.compute.subnetworks.listcompute.compute.compute.subnetworks.mirrorcompute.compute.compute.subnetworks.updatecompute.subnetworks.usecompute.compute.compute.targetGrpcProxies.*
compute.compute.compute.compute.compute.targetGrpcProxies.getcompute.targetGrpcProxies.listcompute.compute.compute.compute.targetGrpcProxies.usecompute.targetHttpProxies.*
compute.compute.compute.compute.compute.targetHttpProxies.getcompute.targetHttpProxies.listcompute.compute.compute.compute.compute.targetHttpProxies.usecompute.targetHttpsProxies.*
compute.compute.compute.compute.compute.targetHttpsProxies.getcompute.compute.compute.compute.compute.compute.compute.compute.compute.compute.targetHttpsProxies.usecompute.targetInstances.*
compute.targetInstances.createcompute.compute.targetInstances.deletecompute.compute.targetInstances.getcompute.targetInstances.listcompute.compute.compute.compute.targetInstances.usecompute.targetPools.*
compute.compute.compute.targetPools.createcompute.compute.targetPools.deletecompute.compute.targetPools.getcompute.targetPools.listcompute.compute.compute.compute.compute.compute.targetPools.updatecompute.targetPools.usecompute.targetSslProxies.*
compute.compute.compute.compute.compute.targetSslProxies.getcompute.targetSslProxies.listcompute.compute.compute.compute.compute.compute.compute.compute.compute.targetSslProxies.usecompute.targetTcpProxies.*
compute.compute.compute.compute.compute.targetTcpProxies.getcompute.targetTcpProxies.listcompute.compute.compute.compute.targetTcpProxies.usecompute.targetVpnGateways.*
compute.compute.compute.compute.compute.targetVpnGateways.getcompute.targetVpnGateways.listcompute.compute.compute.compute.targetVpnGateways.usecompute.urlMaps.*
compute.urlMaps.createcompute.compute.urlMaps.deletecompute.compute.urlMaps.getcompute.compute.urlMaps.listcompute.compute.compute.urlMaps.updatecompute.urlMaps.usecompute.urlMaps.validatecompute.vpnGateways.*
compute.vpnGateways.createcompute.compute.vpnGateways.deletecompute.compute.vpnGateways.getcompute.vpnGateways.listcompute.compute.compute.vpnGateways.setLabelscompute.vpnGateways.usecompute.vpnTunnels.*
compute.vpnTunnels.createcompute.compute.vpnTunnels.deletecompute.compute.vpnTunnels.getcompute.vpnTunnels.listcompute.compute.compute.vpnTunnels.setLabelscompute.wireGroups.*
compute.wireGroups.createcompute.wireGroups.deletecompute.wireGroups.getcompute.wireGroups.listcompute.wireGroups.updatecompute.zoneOperations.getcompute.zoneOperations.listcompute.zones.*
compute.zones.getcompute.zones.listdataflow.jobs.*
dataflow.jobs.canceldataflow.jobs.createdataflow.jobs.getdataflow.jobs.listdataflow.jobs.snapshotdataflow.jobs.updateContentsdataflow.messages.listdataflow.metrics.getdataflow.snapshots.*
dataflow.snapshots.deletedataflow.snapshots.getdataflow.snapshots.listdataform.*
dataform.commentThreads.createdataform.commentThreads.deletedataform.commentThreads.getdataform.commentThreads.listdataform.commentThreads.updatedataform.comments.createdataform.comments.deletedataform.comments.getdataform.comments.listdataform.comments.updatedataform.dataform.dataform.dataform.dataform.config.getdataform.config.updatedataform.folders.addContentsdataform.folders.createdataform.folders.deletedataform.folders.getdataform.folders.getIamPolicydataform.folders.movedataform.folders.queryContentsdataform.folders.setIamPolicydataform.folders.updatedataform.locations.getdataform.locations.listdataform.operations.canceldataform.operations.deletedataform.operations.getdataform.operations.listdataform.releaseConfigs.createdataform.releaseConfigs.deletedataform.releaseConfigs.getdataform.releaseConfigs.listdataform.releaseConfigs.updatedataform.repositories.commitdataform.dataform.repositories.createdataform.repositories.deletedataform.dataform.dataform.repositories.getdataform.dataform.repositories.listdataform.repositories.movedataform.dataform.repositories.readFiledataform.dataform.dataform.dataform.repositories.updatedataform.teamFolders.createdataform.teamFolders.deletedataform.teamFolders.getdataform.dataform.dataform.teamFolders.updatedataform.dataform.dataform.workflowConfigs.getdataform.workflowConfigs.listdataform.dataform.dataform.dataform.dataform.dataform.dataform.dataform.workspaces.commitdataform.workspaces.createdataform.workspaces.deletedataform.dataform.dataform.dataform.workspaces.getdataform.dataform.dataform.workspaces.listdataform.dataform.dataform.workspaces.moveFiledataform.workspaces.pulldataform.workspaces.pushdataform.dataform.workspaces.readFiledataform.dataform.workspaces.removeFiledataform.workspaces.resetdataform.dataform.dataform.workspaces.writeFiledataplex.datascans.*
dataplex.datascans.createdataplex.datascans.deletedataplex.datascans.getdataplex.datascans.getDatadataplex.dataplex.datascans.listdataplex.datascans.rundataplex.dataplex.datascans.updatedataplex.operations.getdataplex.operations.listdataplex.projects.searchdns.firebase.projects.getiam.serviceAccounts.actAsiam.serviceAccounts.getiam.iam.iam.serviceAccounts.listiam.serviceAccounts.signBlobiam.serviceAccounts.signJwtlogging.buckets.createlogging.logging.buckets.deletelogging.logging.buckets.getlogging.buckets.listlogging.logging.logging.buckets.undeletelogging.buckets.updatelogging.exclusions.*
logging.exclusions.createlogging.exclusions.deletelogging.exclusions.getlogging.exclusions.listlogging.exclusions.updatelogging.links.*
logging.links.createlogging.links.deletelogging.links.getlogging.links.listlogging.locations.*
logging.locations.getlogging.locations.listlogging.logEntries.createlogging.logEntries.routelogging.logMetrics.*
logging.logMetrics.createlogging.logMetrics.deletelogging.logMetrics.getlogging.logMetrics.listlogging.logMetrics.updatelogging.logScopes.*
logging.logScopes.createlogging.logScopes.deletelogging.logScopes.getlogging.logScopes.listlogging.logScopes.updatelogging.logServiceIndexes.listlogging.logServices.listlogging.logs.listlogging.notificationRules.*
logging.logging.logging.notificationRules.getlogging.notificationRules.listlogging.logging.operations.*
logging.operations.cancellogging.operations.getlogging.operations.listlogging.settings.*
logging.settings.getlogging.settings.updatelogging.sinks.*
logging.sinks.createlogging.sinks.deletelogging.sinks.getlogging.sinks.listlogging.sinks.updatelogging.sqlAlerts.*
logging.sqlAlerts.createlogging.sqlAlerts.updatelogging.views.createlogging.views.deletelogging.views.getlogging.views.getIamPolicylogging.views.listlogging.views.updatemonitoring.alertPolicies.getmonitoring.alertPolicies.listmonitoring.monitoring.monitoring.alerts.*
monitoring.alerts.getmonitoring.alerts.listmonitoring.dashboards.getmonitoring.dashboards.listmonitoring.monitoring.monitoring.groups.getmonitoring.groups.listmonitoring.monitoring.monitoring.monitoring.
monitoring.monitoring.monitoring.
monitoring.monitoring.monitoring.monitoring.monitoring.services.getmonitoring.services.listmonitoring.slos.getmonitoring.slos.listmonitoring.snoozes.getmonitoring.snoozes.listmonitoring.timeSeries.*
monitoring.timeSeries.createmonitoring.timeSeries.listmonitoring.monitoring.networkconnectivity.
networkconnectivity.networkconnectivity.networkconnectivity.networkconnectivity.networkconnectivity.networkconnectivity.networkconnectivity.networkconnectivity.
networkconnectivity.networkconnectivity.networkconnectivity.
networkconnectivity.networkconnectivity.networkconnectivity.networkconnectivity.networkconnectivity.
networkconnectivity.networkconnectivity.networkconnectivity.networkconnectivity.networkconnectivity.networkconnectivity.networkconnectivity.
networkconnectivity.networkconnectivity.networkconnectivity.networkconnectivity.networkconnectivity.
networkconnectivity.networkconnectivity.networkconnectivity.networkconnectivity.networkconnectivity.networkconnectivity.networkconnectivity.
networkconnectivity.networkconnectivity.networkconnectivity.networkconnectivity.networkconnectivity.networkconnectivity.
networkconnectivity.networkconnectivity.networkconnectivity.networkconnectivity.networkconnectivity.networkmanagement.networkmanagement.networksecurity.
networksecurity.networksecurity.networksecurity.networksecurity.networksecurity.networksecurity.networksecurity.networksecurity.networksecurity.
networksecurity.networksecurity.networksecurity.networksecurity.networksecurity.networksecurity.networksecurity.networksecurity.networksecurity.
networksecurity.networksecurity.networksecurity.networksecurity.networksecurity.networksecurity.networksecurity.networksecurity.
networksecurity.networksecurity.networksecurity.networksecurity.networksecurity.networksecurity.networksecurity.
networksecurity.networksecurity.networksecurity.networksecurity.networksecurity.networksecurity.networksecurity.networksecurity.networksecurity.
networksecurity.networksecurity.networksecurity.networksecurity.networksecurity.networksecurity.
networksecurity.networksecurity.networksecurity.networksecurity.networksecurity.networksecurity.networksecurity.
networksecurity.networksecurity.networksecurity.networksecurity.networksecurity.networksecurity.networksecurity.
networksecurity.networksecurity.networksecurity.networksecurity.networksecurity.networksecurity.networksecurity.locations.*
networksecurity.locations.getnetworksecurity.locations.listnetworksecurity.operations.*
networksecurity.networksecurity.networksecurity.operations.getnetworksecurity.networksecurity.
networksecurity.networksecurity.networksecurity.networksecurity.networksecurity.sacRealms.*
networksecurity.networksecurity.networksecurity.sacRealms.getnetworksecurity.sacRealms.listnetworksecurity.
networksecurity.networksecurity.networksecurity.networksecurity.networksecurity.networksecurity.networksecurity.
networksecurity.networksecurity.networksecurity.networksecurity.networksecurity.networksecurity.networksecurity.
networksecurity.networksecurity.networksecurity.networksecurity.networksecurity.networksecurity.networksecurity.networksecurity.networksecurity.
networksecurity.networksecurity.networksecurity.networksecurity.networksecurity.networksecurity.networksecurity.urlLists.*
networksecurity.networksecurity.networksecurity.urlLists.getnetworksecurity.urlLists.listnetworksecurity.networksecurity.urlLists.usenetworkservices.*
networkservices.networkservices.networkservices.networkservices.networkservices.networkservices.networkservices.networkservices.networkservices.networkservices.networkservices.networkservices.networkservices.networkservices.gateways.getnetworkservices.gateways.listnetworkservices.networkservices.gateways.usenetworkservices.networkservices.networkservices.grpcRoutes.getnetworkservices.networkservices.networkservices.networkservices.networkservices.networkservices.networkservices.networkservices.networkservices.networkservices.httpRoutes.getnetworkservices.networkservices.networkservices.networkservices.networkservices.networkservices.networkservices.networkservices.networkservices.networkservices.networkservices.networkservices.networkservices.networkservices.networkservices.networkservices.networkservices.networkservices.networkservices.networkservices.networkservices.networkservices.networkservices.networkservices.networkservices.networkservices.networkservices.networkservices.networkservices.networkservices.networkservices.locations.getnetworkservices.locations.listnetworkservices.meshes.createnetworkservices.meshes.deletenetworkservices.meshes.getnetworkservices.meshes.listnetworkservices.meshes.updatenetworkservices.meshes.usenetworkservices.networkservices.networkservices.operations.getnetworkservices.networkservices.networkservices.networkservices.networkservices.networkservices.networkservices.networkservices.networkservices.networkservices.networkservices.networkservices.networkservices.networkservices.networkservices.networkservices.networkservices.networkservices.networkservices.networkservices.networkservices.tcpRoutes.getnetworkservices.tcpRoutes.listnetworkservices.networkservices.networkservices.networkservices.tlsRoutes.getnetworkservices.tlsRoutes.listnetworkservices.networkservices.networkservices.networkservices.networkservices.networkservices.networkservices.observability.scopes.getopsconfigmonitoring.orgpolicy.policy.getpubsub.*
pubsub.pubsub.schemas.attachpubsub.schemas.commitpubsub.schemas.createpubsub.schemas.deletepubsub.schemas.getpubsub.schemas.getIamPolicypubsub.schemas.listpubsub.schemas.listRevisionspubsub.schemas.rollbackpubsub.schemas.setIamPolicypubsub.schemas.validatepubsub.snapshots.createpubsub.pubsub.snapshots.deletepubsub.pubsub.snapshots.getpubsub.snapshots.getIamPolicypubsub.snapshots.listpubsub.pubsub.pubsub.snapshots.seekpubsub.snapshots.setIamPolicypubsub.snapshots.updatepubsub.subscriptions.consumepubsub.subscriptions.createpubsub.pubsub.subscriptions.deletepubsub.pubsub.subscriptions.getpubsub.pubsub.subscriptions.listpubsub.pubsub.pubsub.pubsub.subscriptions.updatepubsub.pubsub.topics.createpubsub.topics.createTagBindingpubsub.topics.deletepubsub.topics.deleteTagBindingpubsub.pubsub.topics.getpubsub.topics.getIamPolicypubsub.topics.listpubsub.pubsub.topics.listTagBindingspubsub.topics.publishpubsub.topics.setIamPolicypubsub.topics.updatepubsub.topics.updateTagrecommender.
recommender.recommender.recommender.recommender.
recommender.recommender.recommender.recommender.
recommender.recommender.recommender.recommender.
recommender.recommender.recommender.recommender.
recommender.recommender.recommender.resourcemanager.resourcemanager.projects.getresourcemanager.projects.listservicedirectory.servicedirectory.servicedirectory.servicedirectory.servicenetworking.servicenetworking.servicenetworking.servicenetworking.servicenetworking.servicenetworking.servicenetworking.servicenetworking.services.getservicenetworking.servicenetworking.serviceusage.serviceusage.serviceusage.serviceusage.groups.*
serviceusage.groups.listserviceusage.serviceusage.serviceusage.quotas.getserviceusage.services.getserviceusage.services.listserviceusage.services.useserviceusage.values.teststackdriver.projects.getstackdriver.storage.anywhereCaches.*
storage.anywhereCaches.createstorage.anywhereCaches.disablestorage.anywhereCaches.getstorage.anywhereCaches.liststorage.anywhereCaches.pausestorage.anywhereCaches.resumestorage.anywhereCaches.updatestorage.bucketOperations.*
storage.storage.bucketOperations.getstorage.bucketOperations.liststorage.buckets.*
storage.buckets.createstorage.storage.buckets.deletestorage.storage.storage.buckets.getstorage.buckets.getIamPolicystorage.buckets.getIpFilterstorage.storage.buckets.liststorage.storage.storage.buckets.relocatestorage.buckets.restorestorage.buckets.setIamPolicystorage.buckets.setIpFilterstorage.buckets.updatestorage.folders.*
storage.folders.createstorage.folders.deletestorage.folders.getstorage.folders.liststorage.folders.renamestorage.intelligenceConfigs.*
storage.storage.storage.managedFolders.*
storage.managedFolders.createstorage.managedFolders.deletestorage.managedFolders.getstorage.storage.managedFolders.liststorage.storage.multipartUploads.*
storage.multipartUploads.abortstorage.storage.multipartUploads.liststorage.storage.objects.*
storage.objects.createstorage.objects.createContextstorage.objects.deletestorage.objects.deleteContextstorage.objects.getstorage.objects.getIamPolicystorage.objects.liststorage.objects.movestorage.storage.objects.restorestorage.objects.setIamPolicystorage.objects.setRetentionstorage.objects.updatestorage.objects.updateContextstoragebatchoperations.*
storagebatchoperations.storagebatchoperations.storagebatchoperations.storagebatchoperations.storagebatchoperations.storagebatchoperations.storagebatchoperations.storagebatchoperations.storagebatchoperations.storagebatchoperations.storagebatchoperations.telemetry.metrics.writetrafficdirector.*
trafficdirector.trafficdirector.
Dataflow Viewer
roles/)
dataflow.jobs.getdataflow.jobs.listdataflow.messages.listdataflow.metrics.getdataflow.snapshots.getdataflow.snapshots.listrecommender.recommender.resourcemanager.projects.getresourcemanager.projects.list
Dataflow Worker
roles/)
autoscaling.autoscaling.sites.writeMetricsautoscaling.sites.writeStatecompute.compute.instances.deletecompute.dataflow.jobs.getdataflow.shuffle.*
dataflow.shuffle.readdataflow.shuffle.writedataflow.streamingWorkItems.*
dataflow.dataflow.dataflow.dataflow.dataflow.dataflow.workItems.*
dataflow.workItems.leasedataflow.workItems.sendMessagedataflow.workItems.updatelogging.logEntries.createlogging.logEntries.routemonitoring.timeSeries.createstorage.buckets.getstorage.objects.createstorage.objects.get
El rol de trabajador de Dataflow (roles/dataflow.worker) proporciona los permisos necesarios para que una cuenta de servicio de Compute Engine ejecute unidades de trabajo de una canalización de Apache Beam. El rol de trabajador de Dataflow
debe asignarse a una cuenta de servicio que pueda solicitar
y actualizar el trabajo del servicio Dataflow.
El rol Agente de servicio de Dataflow (roles/dataflow.serviceAgent)
lo usa exclusivamente la cuenta de servicio de Dataflow. Proporciona a la cuenta de servicio acceso a los recursos gestionados de tu proyecto de Google Cloud para ejecutar trabajos de Dataflow. Se asigna automáticamente a la cuenta de servicio cuando habilitas la API de Dataflow en tu proyecto desde la página APIs de la consola de Google Cloud .
Crear tareas
Para crear un trabajo, el rol roles/dataflow.admin incluye el conjunto mínimo de permisos necesarios para ejecutar y examinar trabajos.
También se necesitan los siguientes permisos:
- El rol
roles/dataflow.developerpara crear una instancia de la tarea. - El rol
roles/compute.viewerpara acceder a la información del tipo de máquina y ver otros ajustes. - El rol
roles/storage.objectAdminpara proporcionar permiso para organizar archivos en Cloud Storage.
Ejemplo de asignación de roles
Para ilustrar la utilidad de los diferentes roles de Dataflow, considere el siguiente desglose:
- El desarrollador que crea y examina los trabajos necesita el rol
roles/iam.serviceAccountUser. - Para gestionar los permisos de forma más sofisticada, el desarrollador que interactúe con la tarea de Dataflow debe tener el rol
roles/dataflow.developer.- Necesitan el rol
roles/storage.objectAdminu otro rol relacionado para organizar los archivos necesarios. - Para depurar y comprobar las cuotas, necesitan el rol project
roles/compute.viewer. - Si no se asignan otros roles, este rol permite al desarrollador crear y cancelar trabajos de Dataflow, pero no interactuar con las máquinas virtuales individuales ni acceder a otros servicios de Cloud.
- Necesitan el rol
- La cuenta de servicio de trabajador necesita los roles
roles/dataflow.workeryroles/dataflow.adminpara procesar datos del servicio Dataflow.- Para acceder a los datos de los trabajos, la cuenta de servicio de trabajador necesita otros roles, como
roles/storage.objectAdmin. - Para escribir en tablas de BigQuery, la cuenta de servicio de trabajador necesita el rol
roles/bigquery.dataEditor. - Para leer de un tema o una suscripción de Pub/Sub, la cuenta de servicio de trabajador necesita el rol
roles/pubsub.editor.
- Para acceder a los datos de los trabajos, la cuenta de servicio de trabajador necesita otros roles, como
- Si usas una VPC compartida, la subred de la VPC compartida debe compartirse con la cuenta de servicio de Dataflow y debe tener asignado el rol Usuario de red de Compute en la subred especificada.
- Para comprobar si la subred de VPC compartida se ha compartido con la cuenta de servicio de Dataflow, en la Google Cloud consola, ve a la página VPC compartida y busca la subred. En la columna Compartido con, puedes ver si la subred de VPC se ha compartido con la cuenta de servicio de Dataflow. Para obtener más información, consulta las directrices para especificar un parámetro de subred en una VPC compartida.
- La cuenta de servicio de Compute Engine del proyecto host,
la cuenta de servicio de trabajador de Dataflow del proyecto de servicio
y la cuenta de servicio utilizada para enviar el trabajo deben tener los siguientes roles:
roles/dataflow.adminroles/compute.networkUserroles/storage.objectViewer
Asignar roles de Dataflow
Actualmente, los roles de Dataflow solo se pueden definir en organizaciones y proyectos.
Para gestionar roles a nivel de organización, consulta Control de acceso a organizaciones con gestión de identidades y accesos.
Para asignar roles a nivel de proyecto, consulta Conceder, cambiar y revocar el acceso a los recursos.