Escopo
project
Permissões
434
Role ID
roles/container.adminAdmin
Administrative control over a service, may include IAM
Descrição
Provides access to full management of clusters and their Kubernetes API objects. To set a service account on nodes, you must also have the Service Account User role (roles/iam.serviceAccountUser) on the user-managed service account that your nodes will use.
Recursos de menor nível onde esta role pode ser concedida
Lowest-level resources — documentação do Google
Project
Permissions(434)
Carregando permissões…
Role Definition (JSON)
{
"name": "roles/container.admin",
"title": "Kubernetes Engine Admin",
"description": "Provides access to full management of clusters and their Kubernetes API objects. To set a service account on nodes, you must also have the Service Account User role (roles/iam.serviceAccountUser) on the user-managed service account that your nodes will use.",
"stage": "GA",
"includedPermissions": []
}Roles relacionadasKubernetes
Kubernetes Engine KMS Crypto Key User
Allow the Kubernetes Engine service agent in the cluster project to call KMS with user provided crypto keys to sign payloads.
Kubernetes Engine Cluster Admin
Provides access to management of clusters. To set a service account on nodes, you must also have the Service Account User role (roles/iam.serviceAccountUser) on the user-managed service account that your nodes will use.
Kubernetes Engine Cluster Viewer
Provides access to get and list GKE clusters.
Kubernetes Engine Default Node Service Account
Least privilege role to use as the default service account for GKE Nodes.
Kubernetes Engine Default Node Service Agent
Minimal set of permissions required by a GKE node to support standard capabilities such as logging and monitoring. Replaces the container.nodeServiceAgent role with a reduced permission set.