תפקידים והרשאות

בדף הזה מפורטות ההרשאות שנדרשות ל-Google Distributed Cloud והתפקידים בניהול הזהויות והרשאות הגישה (IAM) שכוללים אותן.

תפקידים

בקטע הזה מפורטים תפקידי IAM שכוללים הרשאות ל-Distributed Cloud.

Google Cloud תפקידים בפרויקט ל-Distributed Cloud

בטבלה הבאה מפורטים תפקידי הפרויקט וההרשאות של Distributed Cloud שכלולים בהם. Google Cloud

תפקיד משאבים הרשאות
Edge Container Viewer

roles/edgecontainer.viewer
אזורים, צמתים, מאגרי צמתים, אשכולות, חיבורי VPN
  • edgecontainer.clusters.list
  • edgecontainer.clusters.get
  • edgecontainer.clusters.generateAccessToken
  • edgecontainer.clusters.getIamPolicy
  • edgecontainer.nodePools.list
  • edgecontainer.nodePools.get
  • edgecontainer.nodePools.getIamPolicy
  • edgecontainer.machines.list
  • edgecontainer.machines.get
  • edgecontainer.machines.getIamPolicy
  • edgecontainer.vpnConnections.list
  • edgecontainer.vpnConnections.get
  • edgecontainer.vpnConnections.getIamPolicy
  • edgecontainer.locations.list
  • edgecontainer.locations.get
  • edgecontainer.operations.list
  • edgecontainer.operations.get
  • edgecontainer.serverconfig.get
אדמין של מאגר Edge

roles/edgecontainer.admin
אזורים, צמתים, מאגרי צמתים, אשכולות, חיבורי VPN כולל את כל ההרשאות מהתפקיד Edge Container Viewer, בנוסף להרשאות הבאות:
  • edgecontainer.clusters.create
  • edgecontainer.clusters.update
  • edgecontainer.clusters.upgrade
  • edgecontainer.clusters.delete
  • edgecontainer.clusters.setIamPolicy
  • edgecontainer.clusters.generateOfflineCredential
  • edgecontainer.nodePools.create
  • edgecontainer.nodePools.update
  • edgecontainer.nodePools.delete
  • edgecontainer.nodePools.setIamPolicy
  • edgecontainer.machines.create
  • edgecontainer.machines.update
  • edgecontainer.machines.delete
  • edgecontainer.machines.use
  • edgecontainer.machines.setIamPolicy
  • edgecontainer.vpnConnections.create
  • edgecontainer.vpnConnections.update
  • edgecontainer.vpnConnections.delete
  • edgecontainer.vpnConnections.setIamPolicy
  • edgecontainer.operations.cancel
  • edgecontainer.operations.delete
משתמש במכונת Edge Container

roles/edgecontainer.machineUser
מכונות
  • edgecontainer.machines.use
Edge Container Offline Credential User

roles/edgecontainer.offlineCredentialUser
אשכולות
  • edgecontainer.clusters.generateOfflineCredential
Edge Network Viewer

roles/edgenetwork.viewer
אזורים, רשתות, רשתות משנה, חיבורים, קבצים מצורפים של חיבורים, נתבים, מיקומים, פעולות
  • edgenetwork.networks.list
  • edgenetwork.networks.get
  • edgenetwork.networks.getStatus
  • edgenetwork.networks.getIamPolicy
  • edgenetwork.subnetworks.list
  • edgenetwork.subnetworks.get
  • edgenetwork.subnetworks.getIamPolicy
  • edgenetwork.interconnects.list
  • edgenetwork.interconnects.get
  • edgenetwork.interconnects.getDiagnostics
  • edgenetwork.interconnects.getIamPolicy
  • edgenetwork.interconnectAttachments.list
  • edgenetwork.interconnectAttachments.get
  • edgenetwork.interconnectAttachments.getIamPolicy
  • edgenetwork.routers.list
  • edgenetwork.routers.get
  • edgenetwork.routers.getRouterStatus
  • edgenetwork.routers.getIamPolicy
  • edgenetwork.zones.list
  • edgenetwork.zones.get
  • edgenetwork.locations.list
  • edgenetwork.locations.get
  • edgenetwork.operations.list
  • edgenetwork.operations.get
אדמין של רשת Edge

roles/edgenetwork.admin
אזורים, רשתות, רשתות משנה, חיבורים, חיבורי רשתות, נתבים, פעולות כולל את כל ההרשאות של התפקיד Edge Network Viewer, בנוסף להרשאות הבאות:
  • edgenetwork.networks.create
  • edgenetwork.networks.delete
  • edgenetwork.networks.setIamPolicy
  • edgenetwork.subnetworks.create
  • edgenetwork.subnetworks.delete
  • edgenetwork.subnetworks.setIamPolicy
  • edgenetwork.interconnects.setIamPolicy
  • edgenetwork.interconnectAttachments.create
  • edgenetwork.interconnectAttachments.delete
  • edgenetwork.interconnectAttachments.setIamPolicy
  • edgenetwork.routers.create
  • edgenetwork.routers.update
  • edgenetwork.routers.patch
  • edgenetwork.routers.delete
  • edgenetwork.routers.setIamPolicy
  • edgenetwork.zones.initialize
  • edgenetwork.operations.cancel
  • edgenetwork.operations.delete

תפקידים בהתאמה אישית

Google Cloud מאפשר גם ליצור תפקידים בהתאמה אישית שכוללים הרשאות ספציפיות לצרכים העסקיים שלכם, כמו העיקרון של הרשאות מינימליות. הוראות מופיעות במאמר בנושא יצירה וניהול של תפקידים בהתאמה אישית.

הרשאות

בקטע הזה מפורטות ההרשאות שנדרשות לביצוע פעולות ספציפיות במשאבי Distributed Cloud.

פעולה ושיטה משאב הרשאה
מציגים רשימה של אזורים ב Google Cloud פרויקט
.
locations.list
אזורים ‫edgecontainer.locations.list
בפרויקט Google Cloud היעד
קבלת מידע על אזור מסוים.

locations.get
אזורים ‫edgecontainer.locations.get
בפרויקט Google Cloud היעד
יוצרים אשכול.

clusters.create
אשכולות ‫edgecontainer.clusters.create
בפרויקט Google Cloud היעד
הצגת רשימה של אשכולות ב Google Cloud פרויקט

clusters.list
אשכולות ‫edgecontainer.clusters.list
בפרויקט Google Cloud היעד
מקבלים פרטי כניסה לאשכול.

clusters.get
אשכולות ‫edgecontainer.clusters.get
בפרויקט Google Cloud היעד
יוצרים אסימון גישה לאשכול.

clusters.generateAccessToken
אשכולות ‫edgecontainer.clusters.generateAccessToken
בפרויקט Google Cloud היעד
משנים אשכול.

clusters.update
אשכולות ‫edgecontainer.clusters.update
בפרויקט Google Cloud היעד
שדרוג, שדרוג לאחור או הצמדה של אשכול לגרסה ספציפית של חבילת תוכנה של Distributed Cloud.

clusters.upgrade
אשכולות ‫edgecontainer.clusters.upgrade
בפרויקט Google Cloud היעד
יוצרים פרטי כניסה לגישה אופליין לאשכול של מישור בקרה מקומי.

clusters.generateOfflineCredential
אשכולות ‫edgecontainer.clusters.generateOfflineCredential
בפרויקט Google Cloud היעד
מחיקת אשכול.

clusters.delete
אשכולות ‫edgecontainer.clusters.delete
בפרויקט Google Cloud היעד
יוצרים מאגר צמתים.

nodePools.create
מאגרי צמתים ‫edgecontainer.nodePools.create
בפרויקט Google Cloud היעד
הצגת רשימה של מאגרי הצמתים ב Google Cloud פרויקט

nodePools.list
מאגרי צמתים ‫edgecontainer.nodePools.list
בפרויקט Google Cloud היעד
קבלת מידע על מאגר צמתים.

nodePools.get
מאגרי צמתים ‫edgecontainer.nodePools.get
בפרויקט Google Cloud היעד
משנים מאגר צמתים.

nodePools.update
מאגרי צמתים ‫edgecontainer.nodePools.update
בפרויקט Google Cloud היעד
מחיקת מאגר צמתים.

nodePools.delete
מאגרי צמתים ‫edgecontainer.nodePools.delete
בפרויקט Google Cloud היעד
יוצרים צומת (מכונה).

machines.create
צמתים ‫edgecontainer.machines.create
בפרויקט Google Cloud היעד
מציגים ברשימה את הצמתים (המכונות) ב Google Cloud פרויקט

machines.list.
צמתים ‫edgecontainer.machines.list
בפרויקט Google Cloud היעד
קבלת מידע על צומת (מכונה).

machines.get
צמתים ‫edgecontainer.machines.get
בפרויקט Google Cloud היעד
לשנות צומת (מכונה).

machines.update
צמתים ‫edgecontainer.machines.update
בפרויקט Google Cloud היעד
פריסת עומס עבודה (workload) לצומת (מכונה).

machines.use
צמתים ‫edgecontainer.machines.use
בפרויקט Google Cloud היעד
מחיקת צומת (מכונה).

machines.delete
צמתים ‫edgecontainer.machines.delete
בפרויקט Google Cloud היעד
הצגת רשימה של עומסי עבודה שפריסתם בוצעה באזור מסוים.

operations.list
operations ‫edgecontainer.operations.list
בפרויקט Google Cloud היעד
קבלת מידע על עומס עבודה.

operations.get
operations ‫edgecontainer.operations.get
בפרויקט Google Cloud היעד
ביטול של עומס עבודה בתהליך.

operations.cancel
operations ‫edgecontainer.operations.cancel
בפרויקט Google Cloud היעד
מחיקת עומס עבודה.

operations.delete
operations ‫edgecontainer.operations.delete
בפרויקט Google Cloud היעד
מקבלים את הגדרת השרת של אשכול.

serverconfig.get
serverconfig ‫edgecontainer.serverconfig.get
בפרויקט Google Cloud היעד
יוצרים חיבור VPN.

vpnConnections.create
חיבורי VPN ‫edgecontainer.vpnConnections.create
בפרויקט Google Cloud היעד
מציגים ברשימה את חיבורי ה-VPN ב Google Cloud פרויקט.

vpnConnections.list
חיבורי VPN ‫edgecontainer.vpnConnections.list
בפרויקט Google Cloud היעד
קבלת מידע על חיבור VPN.

vpnConnections.get
חיבורי VPN ‫edgecontainer.vpnConnections.get
בפרויקט Google Cloud היעד
שינוי חיבור VPN.

vpnConnections.update
חיבורי VPN ‫edgecontainer.vpnConnections.update
בפרויקט Google Cloud היעד
מחיקת חיבור VPN.

vpnConnections.delete
חיבורי VPN ‫edgecontainer.vpnConnections.delete
בפרויקט Google Cloud היעד
מציגים רשימה של אזורים ב Google Cloud פרויקט

zones.list.
אזורים ‫edgenetwork.zones.list
בפרויקט Google Cloud של מכונת היעד
קבלת מידע על אזור.

zones.get
אזורים ‫edgenetwork.zones.get
בפרויקט Google Cloud של מכונת היעד
מפעילים אזור.

zones.initialize
אזורים ‫edgenetwork.zones.initialize
בפרויקט Google Cloud של מכונת היעד
יוצרים רשת.

networks.create
רשתות ‫edgenetwork.networks.create
בפרויקט Google Cloud של מכונת היעד
הצגת רשימת הרשתות ב Google Cloud פרויקט

networks.list
רשתות ‫edgenetwork.networks.list
בפרויקט Google Cloud של מכונת היעד
קבלת מידע על רשת

networks.get
רשתות ‫edgenetwork.networks.get
בפרויקט Google Cloud של מכונת היעד
לקבל סטטוס לגבי רשת.

networks.getStatus
רשתות ‫edgenetwork.networks.getStatus
בפרויקט Google Cloud של מכונת היעד
מחיקת רשת.

networks.delete
רשתות ‫edgenetwork.networks.delete
בפרויקט Google Cloud של מכונת היעד
יוצרים רשת משנה.

subnetworks.create
רשתות משנה ‫edgenetwork.subnetworks.create
בפרויקט Google Cloud של מכונת היעד
מציגים ברשימה את רשתות המשנה ב Google Cloud פרויקט
.

subnetworks.list
רשתות משנה ‫edgenetwork.subnetworks.list
בפרויקט Google Cloud של מכונת היעד
קבלת מידע על רשת משנה.

subnetworks.get
רשתות משנה ‫edgenetwork.subnetworks.get
בפרויקט Google Cloud של מכונת היעד
מחיקת תת-רשת.

subnetworks.delete
רשתות משנה ‫edgenetwork.subnetworks.delete
בפרויקט Google Cloud של מכונת היעד
הצגת רשימה של חיבורי Interconnect ב Google Cloud פרויקט

interconnects.list.
חיבורים בין רשתות ‫edgenetwork.interconnects.list
בפרויקט Google Cloud של מכונת היעד
קבלת מידע על קישוריות הדדית.

interconnects.get
חיבורים בין רשתות ‫edgenetwork.interconnects.get
בפרויקט Google Cloud של מכונת היעד
קבלת נתוני אבחון לגבי חיבור Interconnect.

interconnects.getDiagnostics
חיבורים בין רשתות ‫edgenetwork.interconnects.getDiagnostics
בפרויקט Google Cloud של מכונת היעד
יוצרים קובץ מצורף של חיבור בין-אזורי.

interconnectAttachments.create
צירופים ל-Interconnect ‫edgenetwork.interconnectAttachments.create
בפרויקט Google Cloud של מכונת היעד
הצגת רשימה של קבצים מצורפים לחיבורי Interconnect ב Google Cloud פרויקט

interconnectAttachments.list.
צירופים ל-Interconnect ‫edgenetwork.interconnectAttachments.list
בפרויקט Google Cloud של מכונת היעד
קבלת מידע על קובץ מצורף של קישוריות הדדית.

interconnectAttachments.get
צירופים ל-Interconnect ‫edgenetwork.interconnectAttachments.get
בפרויקט Google Cloud של מכונת היעד
מחיקת קובץ מצורף של קישוריות בין-אזורית.

interconnectAttachments.delete
צירופים ל-Interconnect ‫edgenetwork.interconnectAttachments.delete
בפרויקט Google Cloud של מכונת היעד
יוצרים נתב.

routers.create
נתבים ‫edgenetwork.routers.create
בפרויקט Google Cloud של מכונת היעד
הצגת רשימה של נתבים ב Google Cloud פרויקט

routers.list
נתבים ‫edgenetwork.routers.list
בפרויקט Google Cloud של מכונת היעד
קבלת סטטוס לגבי נתב.

routers.getRouterStatus
נתבים ‫edgenetwork.routers.getRouterStatus
בפרויקט Google Cloud של מכונת היעד
קבלת מידע על נתב.

routers.get
נתבים ‫edgenetwork.routers.get
בפרויקט Google Cloud של מכונת היעד
לשנות נתב.

routers.update
נתבים ‫edgenetwork.routers.update
בפרויקט Google Cloud של מכונת היעד
מחיקת נתב.

routers.delete
נתבים ‫edgenetwork.routers.delete
בפרויקט Google Cloud של מכונת היעד
הצגת רשימה של עומסי עבודה שפריסתם בוצעה באזור מסוים.

operations.list
operations ‫edgenetwork.operations.list
בפרויקט Google Cloud של מכונת היעד
קבלת מידע על עומס עבודה.

operations.get
operations ‫edgenetwork.operations.get
בפרויקט Google Cloud של מכונת היעד
ביטול של עומס עבודה בתהליך.

operations.cancel
operations ‫edgenetwork.operations.cancel
בפרויקט Google Cloud של מכונת היעד
מחיקת עומס עבודה.

operations.delete
operations ‫edgenetwork.operations.delete
בפרויקט Google Cloud של מכונת היעד
מציגים ברשימה את המיקומים בפרויקט של מכונה Google Cloud .

locations.list
מיקומים ‫edgenetwork.locations.list
בפרויקט Google Cloud של מכונת היעד
לקבל מידע על מיקום.

locations.get
מיקומים ‫edgenetwork.locations.get
בפרויקט Google Cloud של מכונת היעד