Escopo
resource
Permissões
46
Role ID
roles/storage.legacyBucketOwnerEsta é uma role privilegiada — concede capacidades de controle elevado. Aplique o princípio do menor privilégio e monitore atribuições via Cloud Audit Logs.
Admin
Administrative control over a service, may include IAM
Descrição
Grants permission to create, overwrite, and delete objects; list objects in a bucket and read object metadata, excluding allow policies, when listing; and read and edit bucket metadata, including allow policies. Use of this role is also reflected in the bucket's ACLs. For more information, see IAM relation to ACLs.
Recursos de menor nível onde esta role pode ser concedida
Lowest-level resources — documentação do Google
Bucket
Permissions(46)
Carregando permissões…
Role Definition (JSON)
{
"name": "roles/storage.legacyBucketOwner",
"title": "Storage Legacy Bucket Owner",
"description": "Grants permission to create, overwrite, and delete objects; list objects in a bucket and read object metadata, excluding allow policies, when listing; and read and edit bucket metadata, including allow policies. Use of this role is also reflected in the bucket's ACLs. For more information, see IAM relation to ACLs.",
"stage": "GA",
"includedPermissions": []
}Roles relacionadasStorage
File Admin Beta
Admin role for file
Cloud Filestore Editor Beta
Read-write access to Filestore instances and related resources.
Cloud Filestore Service Agent
Gives Cloud Filestore service account access to managed resources.
Cloud Filestore Viewer Beta
Read-only access to Filestore instances and related resources.
Storage Admin
Grants full control of objects and buckets. When applied to an individual bucket, control applies only to the specified bucket and objects within the bucket.