Halaman ini mencantumkan izin yang diperlukan oleh Google Distributed Cloud connected dan peran Identity and Access Management (IAM) yang mencakupnya.
Peran dan izin Distributed Cloud Edge Container API
Tabel berikut mencantumkan Google Cloud peran project untuk Distributed Cloud Edge Container API dan izin yang terhubung ke Distributed Cloud yang dienkapsulasi oleh peran tersebut.
| Role | Permissions |
|---|---|
Edge Container Admin( Full access to Edge Container all resources. |
|
Edgecontainer Editor( Editor role for edgecontainer |
|
Edge Container Viewer( Read-only access to Edge Container all resources. |
|
Edge Container API Key Admin( Access to manage API Keys. |
|
Edge Container API Key Viewer( Read-only access to API Keys. |
|
Edge Container Identity Provider Admin( Access to manage Identity Providers. |
|
Edge Container Identity Provider Viewer( Read-only access to Identity Providers. |
|
Edge Container Machine User( Access to use Edge Container Machine resources. |
|
Edge Container Cluster offline Credential User( Access to get Edge Container cluster offline credentials |
|
Edge Container Service Account Admin( Access to manage Service Accounts. |
|
Edge Container Service Account Key Admin( Access to manage Service Account Keys. |
|
Edge Container Service Account Key Viewer( Access to view Service Account Keys. |
|
Edge Container Service Account Viewer( Read-only access to Service Accounts. |
|
Edge Container Zonal Project Admin( Access to manage zonal projects. |
|
Edge Container Zonal Project Viewer( Read-only access to zonal projects. |
|
Edge Container Zonal Service Admin( Access to mutate zonal service. |
|
Edge Container Zonal Service Viewer( Read-only access to zonal services. |
|
Edge Container Zone Iam Policy Admin( Access to manage Iam Policy in the zone. |
|
Edge Container Zone Iam Policy Viewer( Read-only access to Iam Policy in the zone. |
|
Edge Container Roles Viewer( Read-only access to Roles in the zone. |
|
Edge Container Zone Viewer( Read-only access to zones. |
|
Service agent roles
Service agent roles should only be granted to service agents.
| Role | Permissions |
|---|---|
Edge Container Cluster Service Agent( Grants the Edge Container Cluster Service Account access to manage resources. |
|
Edge Container Service Agent( Grants the Edge Container Service Account access to manage resources. |
|
Peran dan izin Distributed Cloud Edge Network API
Tabel berikut mencantumkan Google Cloud peran project untuk Distributed Cloud Edge Network API dan izin yang terhubung ke Distributed Cloud yang dienkapsulasi oleh peran tersebut.
| Role | Permissions |
|---|---|
Edge Network Admin( Full access to Edge Network all resources. |
|
Edge Network Editor( Editor role for Edge Network |
|
Edge Network Viewer( Read-only access to Edge Network all resources. |
|
Peran dan izin GDC Hardware Management API
Tabel berikut mencantumkan Google Cloud peran project untuk GDC Hardware Management API dan izin yang terhubung ke Distributed Cloud yang dienkapsulasi oleh peran tersebut.
| Role | Permissions |
|---|---|
GDC Hardware Management Admin Beta( Full access to GDC Hardware Management resources. |
|
Gdchardwaremanagement Viewer Beta( Viewer role for gdchardwaremanagement |
|
GDC Hardware Management Operator Beta( Create, read, and update access to GDC Hardware Management resources that support those operations. Also grants delete access to HardwareGroup resource. |
|
GDC Hardware Management Reader Beta( Readonly access to GDC Hardware Management resources. |
|
Peran dan izin gateway koneksi
Daftar berikut menjelaskan Google Cloud peran project yang diperlukan agar gateway penghubung dapat mengakses cluster Anda.
- Connect Gateway Admin (
roles/gkehub.gatewayAdmin): memberikan akses ke Connect Gateway API. Peran ini memungkinkan penggunaan alat command linekubectluntuk mengelola cluster. - Connect Gateway Editor (
roles/gkehub.gatewayEditor): memberikan akses baca dan tulis ke cluster. - Connect Gateway Reader (
roles/gkehub.gatewayReader): memberikan akses hanya baca ke cluster. - GKE Hub Viewer (
roles/gkehub.viewer): memberikan kemampuan untuk mengambil file kubeconfig dari cluster.
Peran dan izin paket armada Config Sync
Daftar berikut menjelaskan peran project Google Cloud yang diperlukan untuk membuat dan mengelola paket armada.
- Admin Penayangan Konfigurasi (
roles/configdelivery.admin): diperlukan untuk membuat dan mengelola paket serta peluncuran armada. - Admin Koneksi Developer (
roles/developerconnect.admin): diperlukan untuk membuat dan mengelola koneksi repositori. - Project IAM Admin (
roles/resourcemanager.projectIamAdmin): diperlukan untuk memberikan peran yang diperlukan ke akun layanan.
Peran akun layanan paket armada
- Penerbit Paket Resource Pengiriman Konfigurasi
(
roles/configdelivery.resourceBundlePublisher): memungkinkan akun layanan membuat dan mengelola paket dan rilis resource. - Pengguna Koneksi Cloud Build (
roles/cloudbuild.connectionUser): memungkinkan akun layanan menggunakan koneksi repositori Cloud Build. - Logging Log Writer (
roles/logging.logWriter): memungkinkan akun layanan menulis log build. - Penulis Artifact Registry (
roles/artifactregistry.writer): memungkinkan akun layanan untuk mengirimkan paket versi ke Artifact Registry. - Pengguna Koneksi Developer Connect
(
roles/developerconnect.connectionUser): memungkinkan akun layanan menggunakan koneksi Developer Connect.