שליטה בגישה באמצעות IAM

כדי להשתמש ב-Monitoring, צריכות להיות לכם הרשאות מתאימות בניהול הזהויות והרשאות הגישה (IAM). באופן כללי, לכל method של REST ב-API יש הרשאה משויכת. כדי להשתמש בשיטה או בתכונה במסוף שמסתמכת על השיטה, צריכה להיות לכם הרשאה להשתמש בשיטה המתאימה. ההרשאות לא ניתנות ישירות למשתמשים, אלא באופן עקיף דרך תפקידים. התפקידים מקבצים כמה הרשאות כדי להקל על הניהול שלהן:

תפקידים לשילובים נפוצים של הרשאות מוגדרים מראש. עם זאת, אפשר גם ליצור שילובים משלכם של הרשאות על ידי יצירת תפקידים בהתאמה אישית ב-IAM.

שיטה מומלצת

מומלץ ליצור קבוצות Google כדי לנהל את הגישה לGoogle Cloud פרויקטים:

VPC Service Controls

כדי לשלוט בגישה לנתוני המעקב בצורה טובה יותר, אפשר להשתמש ב-VPC Service Controls בנוסף ל-IAM.

‫VPC Service Controls מספק אבטחה נוספת ל-Cloud Monitoring כדי לעזור בצמצום הסיכון לזליגת נתונים. בעזרת VPC Service Controls אפשר להוסיף היקף מדדים ל-Service Perimeter שמגן על המשאבים והשירותים של Cloud Monitoring מפני בקשות שמקורן מחוץ לגבולות הגזרה.

מידע נוסף על גבולות גזרה לשירות זמין במאמר הגדרת גבולות גזרה לשירות ב-VPC Service Controls.

מידע על התמיכה של Monitoring ב-VPC Service Controls, כולל מגבלות ידועות, זמין במסמכי התיעוד של Monitoring VPC Service Controls.

הענקת גישה ל-Cloud Monitoring

כדי לנהל תפקידים ב-IAM עבור חשבונות משתמשים, אפשר להשתמש בדף 'ניהול זהויות והרשאות גישה' במסוף Google Cloud או ב-Google Cloud CLI. עם זאת, Cloud Monitoring מספק ממשק פשוט שמאפשר לכם לנהל את התפקידים הספציפיים ל-Monitoring, את התפקידים ברמת הפרויקט ואת התפקידים הנפוצים ב-Cloud Logging וב-Cloud Trace.

כדי לתת לחשבונות ראשיים גישה ל-Monitoring, ל-Cloud Logging או ל-Cloud Trace, או כדי להקצות תפקיד ברמת הפרויקט, מבצעים את הפעולות הבאות:

המסוף

  1. נכנסים לדף  Permissions במסוף Google Cloud :

    עוברים אל הרשאות

    אם משתמשים בסרגל החיפוש כדי למצוא את הדף הזה, בוחרים בתוצאה שבה הכותרת המשנית היא Monitoring.

    בדף Principals with access לא מוצגים כל החשבונות הראשיים. הרשימה כוללת רק ישויות מורשות שיש להן תפקיד ברמת הפרויקט, או תפקיד שספציפי למעקב, לרישום ביומן או ליומן מעקב.

    בדף הזה אפשר לראות את כל החשבונות הראשיים שהתפקידים שלהם כוללים הרשאות ל-Monitoring.

  2. לוחצים על Grant access.

  3. לוחצים על New principals ומזינים את שם המשתמש של ה-principal. אפשר להוסיף כמה חשבונות משתמש.

  4. מרחיבים את Select a role, בוחרים ערך מהתפריט By product or service ואז בוחרים תפקיד מהתפריט Roles:

    בחירה לפי מוצר או שירות בחירת תפקידים תיאור
    מעקב צפייה בנתוני מעקב הצגת נתוני המעקב ופרטי ההגדרה. לדוגמה, חשבונות משתמשים עם התפקיד הזה יכולים לראות לוחות בקרה בהתאמה אישית ומדיניות התראות.
    מעקב עורך המעקב לצפות בנתוני המעקב, וגם ליצור ולערוך הגדרות. לדוגמה, גורמים ראשיים עם התפקיד הזה יכולים ליצור מרכזי בקרה בהתאמה אישית ומדיניות התראות.
    מעקב אדמין של Monitoring גישה מלאה ל-Monitoring ב Google Cloud מסוף וב-Cloud Monitoring API. אתם יכולים לראות את נתוני המעקב, ליצור ולערוך הגדרות ולשנות את היקף המדדים.
    Cloud Trace משתמש Cloud Trace גישה מלאה למסוף Trace, גישת קריאה למעקב וגישת קריאה וכתיבה למאגרי נתונים. מידע נוסף זמין במאמר בנושא תפקידים ב-Trace.
    Cloud Trace Cloud Trace Admin גישה מלאה למסוף Trace, גישת קריאה וכתיבה למעקבים וגישת קריאה וכתיבה למאגרי נתונים. מידע נוסף זמין במאמר בנושא תפקידים ב-Trace.
    רישום ביומן מציג היומנים צפייה בגישה ליומנים. מידע נוסף זמין במאמר בנושא תפקידים ביומן.
    רישום ביומן אדמין של Logging גישה מלאה לכל התכונות של Cloud Logging. מידע נוסף זמין במאמר בנושא תפקידים ביומן.
    פרויקט צופה גישת צפייה לרוב Google Cloud המשאבים.
    פרויקט עריכה צפייה ברוב Google Cloud המשאבים, יצירה, עדכון ומחיקה שלהם.
    פרויקט בעלים גישה מלאה לרוב Google Cloud המשאבים.
  5. אופציונלי: כדי להקצות עוד תפקיד לאותם חשבונות ראשיים, לוחצים על Add another role וחוזרים על השלב הקודם.

  6. לוחצים על Save.

בשלבים הקודמים מוסבר איך להעניק לחשבון משתמש תפקידים מסוימים באמצעות דפי Monitoring במסוף Google Cloud . לבעלי התפקידים האלה, הדף הזה תומך גם באפשרויות עריכה ומחיקה:

  • כדי להסיר תפקידים מחשבון ראשי, מסמנים את התיבה שליד החשבון הראשי ולוחצים על Remove access.

  • כדי לערוך את התפקידים של חשבון משתמש, לוחצים על Edit. אחרי שמעדכנים את ההגדרות, לוחצים על שמירה.

gcloud

משתמשים בפקודה gcloud projects add-iam-policy-binding כדי להקצות את התפקיד monitoring.viewer או monitoring.editor.

לדוגמה:

export PROJECT_ID="my-test-project"
export EMAIL_ADDRESS="myuser@gmail.com"
gcloud projects add-iam-policy-binding \
      $PROJECT_ID \
      --member="user:$EMAIL_ADDRESS" \
      --role="roles/monitoring.editor"

אפשר לוודא את התפקידים שהוקצו באמצעות הפקודה gcloud projects get-iam-policy:

export PROJECT_ID="my-test-project"
gcloud projects get-iam-policy $PROJECT_ID

תפקידים מוגדרים מראש

בקטע הזה מפורטים חלק מתפקידי ה-IAM שמוגדרים מראש על ידי Cloud Monitoring.

תפקידי מעקב

התפקידים הבאים מעניקים הרשאות כלליות ל-Monitoring:

שם
כותרת
כולל הרשאות
roles/monitoring.viewer
צופה במעקב
נותנת הרשאת קריאה בלבד ל-Monitoring במסוף Google Cloud וב-Cloud Monitoring API. ‫
roles/monitoring.editor
עורך המעקב
מעניקה גישת קריאה וכתיבה ל-Monitoring במסוף Google Cloud וב-Cloud Monitoring API. ‫
roles/monitoring.admin
אדמין בתפקיד מעקב
מעניקה גישה מלאה ל-Monitoring במסוף Google Cloud וב-Cloud Monitoring API.

התפקיד הבא משמש חשבונות שירות לגישת כתיבה בלבד:

שם
כותרת
תיאור
roles/monitoring.metricWriter
כתיבת מדדי מעקב

התפקיד הזה מיועד לחשבונות שירות ולסוכנים.
לא מאפשר גישה ל-Monitoring במסוף Google Cloud .
מאפשר לכתוב נתוני מעקב להיקף המדדים בפרויקט.

תפקידים במדיניות ההתראות

התפקידים הבאים מעניקים הרשאות לכללי מדיניות בנושא התראות:

שם
כותרת
תיאור
roles/monitoring.alertPolicyViewer
צפייה במדיניות ההתראות למעקב
התפקיד הזה מאפשר גישה לקריאה בלבד של מדיניות ההתראות.
roles/monitoring.alertPolicyEditor
מעקב אחרי עורך מדיניות ההתראות
התפקיד הזה מעניק גישת קריאה וכתיבה למדיניות התראות.

תפקידים במרכז הבקרה

התפקידים הבאים מעניקים הרשאות רק ללוחות בקרה:

שם
כותרת
תיאור
roles/monitoring.dashboardViewer
כלי להגדרת לוח הבקרה של Monitoring
התפקיד הזה מאפשר גישה לקריאה בלבד של הגדרות לוחות הבקרה.
roles/monitoring.dashboardEditor
עורך ההגדרות של לוח הבקרה 'מעקב'
התפקיד הזה מאפשר גישת קריאה וכתיבה להגדרות של מרכז הבקרה.

תפקידים באירוע

התפקידים הבאים מעניקים הרשאות רק להתראות:

שם
כותרת
תיאור
roles/monitoring.cloudConsoleIncidentViewer
מעקב אחרי כלי הצגת תקריות ב-Cloud Console
ההרשאה מאפשרת גישה לצפייה בהתראות באמצעות מסוף Google Cloud .
roles/monitoring.cloudConsoleIncidentEditor
מעקב אחרי עורך התקריות ב-Cloud Console
ההרשאה מאפשרת לצפות בהתראות, לאשר אותן ולסגור אותן באמצעות מסוף Google Cloud .

מידע על פתרון שגיאות בהרשאות IAM כשמציגים התראות מופיע במאמר אי אפשר להציג את פרטי ההתראה בגלל שגיאת הרשאה.

תפקידים בערוץ ההתראות

התפקידים הבאים מעניקים הרשאות רק לערוצי התראות:

שם
כותרת
תיאור
roles/monitoring.notificationChannelViewer
כלי לצפייה בערוצי התראות של Monitoring
התפקיד הזה מאפשר גישה לקריאה בלבד של ערוצי התראות.
roles/monitoring.notificationChannelEditor
כלי לעריכת ערוצי התראות של Monitoring
התפקיד הזה מאפשר לקרוא ולכתוב בערוצי התראות.

השהיית התראות על הקצאת תפקידים

התפקידים הבאים מעניקים הרשאות להשהיית התראות:

שם
כותרת
תיאור
roles/monitoring.snoozeViewer
הכלי להצגת התראות מושהות
הרשאת קריאה בלבד של תזכורות.
roles/monitoring.snoozeEditor
הכלי לעריכת השהיות של מעקב
ההרשאה הזו מאפשרת לקרוא ולכתוב נתונים של תזכורות.

תפקידים לניטור שירותים

התפקידים הבאים מעניקים הרשאות לניהול שירותים:

שם
כותרת
תיאור
roles/monitoring.servicesViewer
תצוגה של שירותי ניטור
ההרשאה מעניקה גישת קריאה בלבד לשירותים.
roles/monitoring.servicesEditor
מעקב אחרי הכלי לעריכת שירותים
מעניק גישת קריאה וכתיבה לשירותים.

מידע נוסף על מעקב אחרי שירותים זמין במאמר מעקב אחרי SLO.

תפקידים בהגדרת בדיקת זמני פעילות

התפקידים הבאים מעניקים הרשאות רק להגדרות של בדיקות זמינות:

שם
כותרת
תיאור
roles/monitoring.uptimeCheckConfigViewer
כלי לצפייה בהגדרות של בדיקות זמינות
התפקיד הזה מאפשר גישה לקריאה בלבד של הגדרות בדיקת זמינות.
roles/monitoring.uptimeCheckConfigEditor
עורך ההגדרות של בדיקת זמני פעילות של מעקב
התפקיד הזה מאפשר גישת קריאה וכתיבה להגדרות של בדיקות זמינות.

תפקידים בהגדרת היקף המדדים

התפקידים הבאים מעניקים הרשאות כלליות להיקפי מדדים:

שם
כותרת
תיאור
roles/monitoring.metricsScopesViewer
מעקב אחר מדדים בהיקף הצופה
ההרשאה מאפשרת גישה לקריאה בלבד להיקפי מדדים.
roles/monitoring.metricsScopesAdmin
היקפי מדדים למעקב Admin
התפקיד הזה מעניק גישת קריאה וכתיבה להיקפי מדדים.

הרשאות לתפקידים מוגדרים מראש

בקטע הזה מפורטות ההרשאות שמוקצות לתפקידים מוגדרים מראש שמשויכים ל-Monitoring.

מידע נוסף על תפקידים מוגדרים מראש זמין במאמר IAM: תפקידים והרשאות. לא בטוחים איזה תפקיד מוגדר מראש לתת? תוכלו להיעזר במאמר בחירת תפקידים מוגדרים מראש.

הרשאות לתפקידי ניהול

Role Permissions

(roles/monitoring.admin)

Provides full access to Cloud Monitoring.

Lowest-level resources where you can grant this role:

  • Project

cloudnotifications.activities.list

monitoring.*

  • monitoring.alertPolicies.create
  • monitoring.alertPolicies.createTagBinding
  • monitoring.alertPolicies.delete
  • monitoring.alertPolicies.deleteTagBinding
  • monitoring.alertPolicies.get
  • monitoring.alertPolicies.list
  • monitoring.alertPolicies.listEffectiveTags
  • monitoring.alertPolicies.listTagBindings
  • monitoring.alertPolicies.update
  • monitoring.alerts.get
  • monitoring.alerts.list
  • monitoring.dashboards.create
  • monitoring.dashboards.createTagBinding
  • monitoring.dashboards.delete
  • monitoring.dashboards.deleteTagBinding
  • monitoring.dashboards.get
  • monitoring.dashboards.list
  • monitoring.dashboards.listEffectiveTags
  • monitoring.dashboards.listTagBindings
  • monitoring.dashboards.update
  • monitoring.groups.create
  • monitoring.groups.delete
  • monitoring.groups.get
  • monitoring.groups.list
  • monitoring.groups.update
  • monitoring.metricDescriptors.create
  • monitoring.metricDescriptors.delete
  • monitoring.metricDescriptors.get
  • monitoring.metricDescriptors.list
  • monitoring.metricsScopes.link
  • monitoring.monitoredResourceDescriptors.get
  • monitoring.monitoredResourceDescriptors.list
  • monitoring.notificationChannelDescriptors.get
  • monitoring.notificationChannelDescriptors.list
  • monitoring.notificationChannels.create
  • monitoring.notificationChannels.delete
  • monitoring.notificationChannels.get
  • monitoring.notificationChannels.getVerificationCode
  • monitoring.notificationChannels.list
  • monitoring.notificationChannels.sendVerificationCode
  • monitoring.notificationChannels.update
  • monitoring.notificationChannels.verify
  • monitoring.services.create
  • monitoring.services.delete
  • monitoring.services.get
  • monitoring.services.list
  • monitoring.services.update
  • monitoring.slos.create
  • monitoring.slos.delete
  • monitoring.slos.get
  • monitoring.slos.list
  • monitoring.slos.update
  • monitoring.snoozes.create
  • monitoring.snoozes.get
  • monitoring.snoozes.list
  • monitoring.snoozes.update
  • monitoring.timeSeries.create
  • monitoring.timeSeries.list
  • monitoring.uptimeCheckConfigs.create
  • monitoring.uptimeCheckConfigs.delete
  • monitoring.uptimeCheckConfigs.get
  • monitoring.uptimeCheckConfigs.list
  • monitoring.uptimeCheckConfigs.update

opsconfigmonitoring.*

  • opsconfigmonitoring.resourceMetadata.list
  • opsconfigmonitoring.resourceMetadata.write

resourcemanager.projects.get

resourcemanager.projects.list

serviceusage.consumerpolicy.*

  • serviceusage.consumerpolicy.analyze
  • serviceusage.consumerpolicy.get
  • serviceusage.consumerpolicy.update

serviceusage.effectivepolicy.get

serviceusage.groups.*

  • serviceusage.groups.list
  • serviceusage.groups.listExpandedMembers
  • serviceusage.groups.listMembers

serviceusage.services.enable

serviceusage.services.get

serviceusage.values.test

stackdriver.*

  • stackdriver.projects.edit
  • stackdriver.projects.get
  • stackdriver.resourceMetadata.list
  • stackdriver.resourceMetadata.write

(roles/monitoring.editor)

Provides full access to information about all monitoring data and configurations.

Lowest-level resources where you can grant this role:

  • Project

cloudnotifications.activities.list

monitoring.alertPolicies.*

  • monitoring.alertPolicies.create
  • monitoring.alertPolicies.createTagBinding
  • monitoring.alertPolicies.delete
  • monitoring.alertPolicies.deleteTagBinding
  • monitoring.alertPolicies.get
  • monitoring.alertPolicies.list
  • monitoring.alertPolicies.listEffectiveTags
  • monitoring.alertPolicies.listTagBindings
  • monitoring.alertPolicies.update

monitoring.alerts.*

  • monitoring.alerts.get
  • monitoring.alerts.list

monitoring.dashboards.*

  • monitoring.dashboards.create
  • monitoring.dashboards.createTagBinding
  • monitoring.dashboards.delete
  • monitoring.dashboards.deleteTagBinding
  • monitoring.dashboards.get
  • monitoring.dashboards.list
  • monitoring.dashboards.listEffectiveTags
  • monitoring.dashboards.listTagBindings
  • monitoring.dashboards.update

monitoring.groups.*

  • monitoring.groups.create
  • monitoring.groups.delete
  • monitoring.groups.get
  • monitoring.groups.list
  • monitoring.groups.update

monitoring.metricDescriptors.*

  • monitoring.metricDescriptors.create
  • monitoring.metricDescriptors.delete
  • monitoring.metricDescriptors.get
  • monitoring.metricDescriptors.list

monitoring.monitoredResourceDescriptors.*

  • monitoring.monitoredResourceDescriptors.get
  • monitoring.monitoredResourceDescriptors.list

monitoring.notificationChannelDescriptors.*

  • monitoring.notificationChannelDescriptors.get
  • monitoring.notificationChannelDescriptors.list

monitoring.notificationChannels.create

monitoring.notificationChannels.delete

monitoring.notificationChannels.get

monitoring.notificationChannels.list

monitoring.notificationChannels.sendVerificationCode

monitoring.notificationChannels.update

monitoring.notificationChannels.verify

monitoring.services.*

  • monitoring.services.create
  • monitoring.services.delete
  • monitoring.services.get
  • monitoring.services.list
  • monitoring.services.update

monitoring.slos.*

  • monitoring.slos.create
  • monitoring.slos.delete
  • monitoring.slos.get
  • monitoring.slos.list
  • monitoring.slos.update

monitoring.snoozes.*

  • monitoring.snoozes.create
  • monitoring.snoozes.get
  • monitoring.snoozes.list
  • monitoring.snoozes.update

monitoring.timeSeries.*

  • monitoring.timeSeries.create
  • monitoring.timeSeries.list

monitoring.uptimeCheckConfigs.*

  • monitoring.uptimeCheckConfigs.create
  • monitoring.uptimeCheckConfigs.delete
  • monitoring.uptimeCheckConfigs.get
  • monitoring.uptimeCheckConfigs.list
  • monitoring.uptimeCheckConfigs.update

opsconfigmonitoring.*

  • opsconfigmonitoring.resourceMetadata.list
  • opsconfigmonitoring.resourceMetadata.write

resourcemanager.projects.get

resourcemanager.projects.list

serviceusage.consumerpolicy.*

  • serviceusage.consumerpolicy.analyze
  • serviceusage.consumerpolicy.get
  • serviceusage.consumerpolicy.update

serviceusage.effectivepolicy.get

serviceusage.groups.*

  • serviceusage.groups.list
  • serviceusage.groups.listExpandedMembers
  • serviceusage.groups.listMembers

serviceusage.services.enable

serviceusage.services.get

serviceusage.values.test

stackdriver.*

  • stackdriver.projects.edit
  • stackdriver.projects.get
  • stackdriver.resourceMetadata.list
  • stackdriver.resourceMetadata.write

(roles/monitoring.metricWriter)

Provides write-only access to metrics. This provides exactly the permissions needed by the Cloud Monitoring agent and other systems that send metrics.

Lowest-level resources where you can grant this role:

  • Project

monitoring.metricDescriptors.create

monitoring.metricDescriptors.get

monitoring.metricDescriptors.list

monitoring.monitoredResourceDescriptors.*

  • monitoring.monitoredResourceDescriptors.get
  • monitoring.monitoredResourceDescriptors.list

monitoring.timeSeries.create

(roles/monitoring.viewer)

Provides read-only access to get and list information about all monitoring data and configurations.

Lowest-level resources where you can grant this role:

  • Project

cloudnotifications.activities.list

monitoring.alertPolicies.get

monitoring.alertPolicies.list

monitoring.alertPolicies.listEffectiveTags

monitoring.alertPolicies.listTagBindings

monitoring.alerts.*

  • monitoring.alerts.get
  • monitoring.alerts.list

monitoring.dashboards.get

monitoring.dashboards.list

monitoring.dashboards.listEffectiveTags

monitoring.dashboards.listTagBindings

monitoring.groups.get

monitoring.groups.list

monitoring.metricDescriptors.get

monitoring.metricDescriptors.list

monitoring.monitoredResourceDescriptors.*

  • monitoring.monitoredResourceDescriptors.get
  • monitoring.monitoredResourceDescriptors.list

monitoring.notificationChannelDescriptors.*

  • monitoring.notificationChannelDescriptors.get
  • monitoring.notificationChannelDescriptors.list

monitoring.notificationChannels.get

monitoring.notificationChannels.list

monitoring.services.get

monitoring.services.list

monitoring.slos.get

monitoring.slos.list

monitoring.snoozes.get

monitoring.snoozes.list

monitoring.timeSeries.list

monitoring.uptimeCheckConfigs.get

monitoring.uptimeCheckConfigs.list

opsconfigmonitoring.resourceMetadata.list

resourcemanager.projects.get

resourcemanager.projects.list

stackdriver.projects.get

stackdriver.resourceMetadata.list

(roles/opsconfigmonitoring.admin)

Admin role for opsconfigmonitoring

opsconfigmonitoring.*

  • opsconfigmonitoring.resourceMetadata.list
  • opsconfigmonitoring.resourceMetadata.write

resourcemanager.projects.get

resourcemanager.projects.list

(roles/opsconfigmonitoring.viewer)

Viewer role for opsconfigmonitoring

opsconfigmonitoring.resourceMetadata.list

resourcemanager.projects.get

resourcemanager.projects.list

(roles/stackdriver.admin)

Admin role for stackdriver

resourcemanager.projects.get

resourcemanager.projects.list

stackdriver.*

  • stackdriver.projects.edit
  • stackdriver.projects.get
  • stackdriver.resourceMetadata.list
  • stackdriver.resourceMetadata.write

(roles/stackdriver.resourceMetadata.writer)

Write-only access to resource metadata. This provides exactly the permissions needed by the Stackdriver metadata agent and other systems that send metadata.

stackdriver.resourceMetadata.write

(roles/stackdriver.viewer)

Viewer role for stackdriver

resourcemanager.projects.get

resourcemanager.projects.list

stackdriver.projects.get

stackdriver.resourceMetadata.list

(roles/monitoring.alertPolicyEditor)

Read/write access to alerting policies.

monitoring.alertPolicies.*

  • monitoring.alertPolicies.create
  • monitoring.alertPolicies.createTagBinding
  • monitoring.alertPolicies.delete
  • monitoring.alertPolicies.deleteTagBinding
  • monitoring.alertPolicies.get
  • monitoring.alertPolicies.list
  • monitoring.alertPolicies.listEffectiveTags
  • monitoring.alertPolicies.listTagBindings
  • monitoring.alertPolicies.update

(roles/monitoring.alertPolicyViewer)

Read-only access to alerting policies.

monitoring.alertPolicies.get

monitoring.alertPolicies.list

monitoring.alertPolicies.listEffectiveTags

monitoring.alertPolicies.listTagBindings

(roles/monitoring.alertViewer)

Read access to alerts.

monitoring.alerts.*

  • monitoring.alerts.get
  • monitoring.alerts.list

(roles/monitoring.cloudConsoleIncidentEditor)

Read/write access to incidents from Cloud Console.

monitoring.alerts.*

  • monitoring.alerts.get
  • monitoring.alerts.list

(roles/monitoring.cloudConsoleIncidentViewer)

Read access to incidents from Cloud Console.

monitoring.alerts.*

  • monitoring.alerts.get
  • monitoring.alerts.list

(roles/monitoring.dashboardEditor)

Read/write access to dashboard configurations.

monitoring.dashboards.*

  • monitoring.dashboards.create
  • monitoring.dashboards.createTagBinding
  • monitoring.dashboards.delete
  • monitoring.dashboards.deleteTagBinding
  • monitoring.dashboards.get
  • monitoring.dashboards.list
  • monitoring.dashboards.listEffectiveTags
  • monitoring.dashboards.listTagBindings
  • monitoring.dashboards.update

(roles/monitoring.dashboardViewer)

Read-only access to dashboard configurations.

monitoring.dashboards.get

monitoring.dashboards.list

monitoring.dashboards.listEffectiveTags

monitoring.dashboards.listTagBindings

(roles/monitoring.metricsScopesAdmin)

Access to add and remove monitored projects from metrics scopes.

monitoring.metricsScopes.link

resourcemanager.projects.get

resourcemanager.projects.list

(roles/monitoring.metricsScopesViewer)

Read-only access to metrics scopes and their monitored projects.

resourcemanager.projects.get

resourcemanager.projects.list

(roles/monitoring.notificationChannelEditor)

Read/write access to notification channels.

monitoring.notificationChannelDescriptors.*

  • monitoring.notificationChannelDescriptors.get
  • monitoring.notificationChannelDescriptors.list

monitoring.notificationChannels.create

monitoring.notificationChannels.delete

monitoring.notificationChannels.get

monitoring.notificationChannels.list

monitoring.notificationChannels.sendVerificationCode

monitoring.notificationChannels.update

monitoring.notificationChannels.verify

(roles/monitoring.notificationChannelViewer)

Read-only access to notification channels.

monitoring.notificationChannelDescriptors.*

  • monitoring.notificationChannelDescriptors.get
  • monitoring.notificationChannelDescriptors.list

monitoring.notificationChannels.get

monitoring.notificationChannels.list

(roles/monitoring.servicesEditor)

Read/write access to services.

monitoring.services.*

  • monitoring.services.create
  • monitoring.services.delete
  • monitoring.services.get
  • monitoring.services.list
  • monitoring.services.update

monitoring.slos.*

  • monitoring.slos.create
  • monitoring.slos.delete
  • monitoring.slos.get
  • monitoring.slos.list
  • monitoring.slos.update

(roles/monitoring.servicesViewer)

Read-only access to services.

monitoring.services.get

monitoring.services.list

monitoring.slos.get

monitoring.slos.list

(roles/monitoring.snoozeEditor)

monitoring.snoozes.*

  • monitoring.snoozes.create
  • monitoring.snoozes.get
  • monitoring.snoozes.list
  • monitoring.snoozes.update

(roles/monitoring.snoozeViewer)

monitoring.snoozes.get

monitoring.snoozes.list

(roles/monitoring.uptimeCheckConfigEditor)

Read/write access to uptime check configurations.

monitoring.uptimeCheckConfigs.*

  • monitoring.uptimeCheckConfigs.create
  • monitoring.uptimeCheckConfigs.delete
  • monitoring.uptimeCheckConfigs.get
  • monitoring.uptimeCheckConfigs.list
  • monitoring.uptimeCheckConfigs.update

(roles/monitoring.uptimeCheckConfigViewer)

Read-only access to uptime check configurations.

monitoring.uptimeCheckConfigs.get

monitoring.uptimeCheckConfigs.list

(roles/opsconfigmonitoring.resourceMetadata.viewer)

Read-only access to resource metadata.

opsconfigmonitoring.resourceMetadata.list

(roles/opsconfigmonitoring.resourceMetadata.writer)

Write-only access to resource metadata. This provides exactly the permissions needed by the Ops Config Monitoring metadata agent and other systems that send metadata.

opsconfigmonitoring.resourceMetadata.write

(roles/stackdriver.accounts.editor)

Read/write access to manage Stackdriver account structure.

resourcemanager.projects.get

resourcemanager.projects.list

serviceusage.consumerpolicy.*

  • serviceusage.consumerpolicy.analyze
  • serviceusage.consumerpolicy.get
  • serviceusage.consumerpolicy.update

serviceusage.effectivepolicy.get

serviceusage.groups.*

  • serviceusage.groups.list
  • serviceusage.groups.listExpandedMembers
  • serviceusage.groups.listMembers

serviceusage.services.enable

serviceusage.services.get

serviceusage.values.test

stackdriver.projects.*

  • stackdriver.projects.edit
  • stackdriver.projects.get

(roles/stackdriver.accounts.viewer)

Read-only access to get and list information about Stackdriver account structure.

resourcemanager.projects.get

resourcemanager.projects.list

stackdriver.projects.get

Service agent roles

Service agent roles should only be granted to service agents.

Role Permissions

(roles/monitoring.notificationServiceAgent)

Grants permissions to deliver notifications directly to resources within the target project, such as delivering to Pub/Sub topics within the project.

bigquery.jobs.create

cloudfunctions.functions.get

cloudtrace.traces.patch

logging.links.list

monitoring.metricDescriptors.get

monitoring.metricDescriptors.list

monitoring.monitoredResourceDescriptors.*

  • monitoring.monitoredResourceDescriptors.get
  • monitoring.monitoredResourceDescriptors.list

monitoring.notificationChannels.get

monitoring.notificationChannels.list

monitoring.notificationChannels.update

monitoring.timeSeries.list

observability.links.list

run.routes.invoke

servicedirectory.networks.access

servicedirectory.services.resolve

serviceusage.services.use

הרשאות מעקב שכלולות בתפקידים Google Cloud בסיסיים

Google Cloud תפקידים בסיסיים כוללים את ההרשאות הבאות:

שם
כותרת
כולל הרשאות
roles/viewer
צופה
ההרשאות של המעקב זהות לאלה של roles/monitoring.viewer.
roles/editor
עריכה

ההרשאות של 'מעקב' זהות לאלה של roles/monitoring.editor, למעט ההרשאה stackdriver.projects.edit. התפקיד roles/editor לא כולל את ההרשאה stackdriver.projects.edit.

התפקיד הזה לא מעניק הרשאה לשנות היקף המדדים בפרויקט. כדי לשנות את היקף המדדים כשמשתמשים ב-API, התפקיד צריך לכלול את ההרשאה monitoring.metricsScopes.link. כדי לשנות את היקף המדדים בפרויקט כשמשתמשים במסוף Google Cloud , התפקיד שלכם צריך לכלול את ההרשאה monitoring.metricsScopes.link או שיוקצה לכם התפקיד roles/monitoring.editor.

roles/owner
בעלים
ההרשאות של 'מעקב' זהות לאלה שמופיעות ב-roles/monitoring.admin.

תפקידים בהתאמה אישית

יכול להיות שתרצו ליצור תפקיד בהתאמה אישית אם אתם רוצים להעניק לחשבון משתמש קבוצה מוגבלת יותר של הרשאות מאלה שמוענקות עם תפקידים מוגדרים מראש. לדוגמה, אם הגדרתם את Assured Workloads כי יש לכם דרישות לגבי מיקום הנתונים או רמת ההשפעה 4 (IL4), אל תשתמשו בבדיקות זמני פעילות כי אין ערובה לכך שנתוני בדיקות זמני פעילות יישמרו במיקום גיאוגרפי ספציפי. כדי למנוע שימוש בבדיקות זמני פעילות, צריך ליצור תפקיד שלא כולל הרשאות עם הקידומת monitoring.uptimeCheckConfigs.

כדי ליצור תפקיד בהתאמה אישית עם הרשאות ל-Monitoring:

מידע נוסף על תפקידים בהתאמה אישית זמין במאמר הסבר על תפקידים בהתאמה אישית ב-IAM.

שימוש בתגים כדי לשלוט בגישה למשאבים

אתם יכולים להשתמש בתגים כדי לשלוט בגישת העריכה והמחיקה של לוחות בקרה ומדיניות התראות. לדוגמה, אפשר להשתמש בתגים כדי:

  • למנוע גישת עריכה מכל המשתמשים, למעט חשבון שירות ספציפי.
  • הגבלת גישת עריכה לחברים בצוותים ספציפיים.

מידע נוסף זמין במאמר שליטה בגישה באמצעות תגים.

היקפי גישה ב-Compute Engine

היקפי גישה הם השיטה הקודמת להגדרת הרשאות למכונות וירטואליות של Compute Engine. היקפי הגישה הבאים חלים על מעקב:

היקף גישה ההרשאות ניתנו
https://www.googleapis.com/auth/monitoring.read אותן הרשאות כמו ב-roles/monitoring.viewer.
https://www.googleapis.com/auth/monitoring.write אותן הרשאות כמו ב-roles/monitoring.metricWriter.
https://www.googleapis.com/auth/monitoring גישה מלאה ל-Monitoring.
https://www.googleapis.com/auth/cloud-platform גישה מלאה לכל ממשקי ה-API המופעלים ב-Cloud.

פרטים נוספים זמינים במאמר בנושא היקפי גישה.

שיטה מומלצת. מומלץ להגדיר למכונות הווירטואליות את היקף הגישה הכי רחב (cloud-platform) ואז להשתמש בתפקידי IAM כדי להגביל את הגישה לממשקי API ולפעולות ספציפיות. פרטים נוספים מופיעים במאמר הרשאות לחשבון שירות.