Compute Shared VPC Admin

GCP IAM · Compute · Admin

Compute Shared VPC Admin

Privilegiada
AdminIAM ScopeCompute

Dado verificado em · Fonte

Escopo
folder
Permissões
13
Role IDroles/compute.xpnAdmin

Esta é uma role privilegiada — concede capacidades de controle elevado. Aplique o princípio do menor privilégio e monitore atribuições via Cloud Audit Logs.

Admin

Administrative control over a service, may include IAM

Descrição

Permissions to administer shared VPC host projects, specifically enabling the host projects and associating shared VPC service projects to the host project's network. At the organization level, this role can only be granted by an organization admin. Google Cloud recommends that the Shared VPC Admin be the owner of the shared VPC host project. The Shared VPC Admin is responsible for granting the Compute Network User role (roles/compute.networkUser) to service owners, and the shared VPC host project owner controls the project itself. Managing the project is easier if a single principal (individual or group) can fulfill both roles.

Recursos de menor nível onde esta role pode ser concedida

Lowest-level resources — documentação do Google

Folder

Permissions(13)

Carregando permissões…

Role Definition (JSON)

{
  "name": "roles/compute.xpnAdmin",
  "title": "Compute Shared VPC Admin",
  "description": "Permissions to administer shared VPC host projects, specifically enabling the host projects and associating shared VPC service projects to the host project's network. At the organization level, this role can only be granted by an organization admin. Google Cloud recommends that the Shared VPC Admin be the owner of the shared VPC host project. The Shared VPC Admin is responsible for granting the Compute Network User role (roles/compute.networkUser) to service owners, and the shared VPC host project owner controls the project itself. Managing the project is easier if a single principal (individual or group) can fulfill both roles.",
  "stage": "GA",
  "includedPermissions": []
}