Compute Instance Admin (beta)

GCP IAM · Compute · Admin

Compute Instance Admin (beta)

Privilegiada
AdminIAM ScopeCompute

Dado verificado em · Fonte

Escopo
resource
Permissões
270
Role IDroles/compute.instanceAdmin

Esta é uma role privilegiada — concede capacidades de controle elevado. Aplique o princípio do menor privilégio e monitore atribuições via Cloud Audit Logs.

Admin

Administrative control over a service, may include IAM

Descrição

Permissions to create, modify, and delete virtual machine instances. This includes permissions to create, modify, and delete disks, and also to configure Shielded VM settings. If the user will be managing virtual machine instances that are configured to run as a service account, you must also grant the roles/iam.serviceAccountUser role. For example, if your company has someone who manages groups of virtual machine instances but does not manage network or security settings and does not manage instances that run as service accounts, you can grant this role on the organization, folder, or project that contains the instances, or you can grant it on individual instances.

Recursos de menor nível onde esta role pode ser concedida

Lowest-level resources — documentação do Google

Disk
Image
Instance
Instance template
Snapshot

Permissions(270)

Carregando permissões…

Role Definition (JSON)

{
  "name": "roles/compute.instanceAdmin",
  "title": "Compute Instance Admin (beta)",
  "description": "Permissions to create, modify, and delete virtual machine instances. This includes permissions to create, modify, and delete disks, and also to configure Shielded VM settings. If the user will be managing virtual machine instances that are configured to run as a service account, you must also grant the roles/iam.serviceAccountUser role. For example, if your company has someone who manages groups of virtual machine instances but does not manage network or security settings and does not manage instances that run as service accounts, you can grant this role on the organization, folder, or project that contains the instances, or you can grant it on individual instances.",
  "stage": "GA",
  "includedPermissions": []
}