A RetroSearch Logo

Home - News ( United States | United Kingdom | Italy | Germany ) - Football scores

Search Query:

Showing content from https://cloud.google.com/kubernetes-engine/docs/how-to/iam below:

Create IAM allow policies | GKE Documentation

Kubernetes Engine Admin

(roles/container.admin)

Provides access to full management of clusters and their Kubernetes API objects.

To set a service account on nodes, you must also have the Service Account User role (roles/iam.serviceAccountUser) on the user-managed service account that your nodes will use.

Lowest-level resources where you can grant this role:

container.*

recommender.containerDiagnosisInsights.*

recommender.containerDiagnosisRecommendations.*

recommender.locations.*

recommender.networkAnalyzerGkeConnectivityInsights.*

recommender.networkAnalyzerGkeIpAddressInsights.*

resourcemanager.projects.get

resourcemanager.projects.list

Kubernetes Engine KMS Crypto Key User

(roles/container.cloudKmsKeyUser)

Allow the Kubernetes Engine service agent in the cluster project to call KMS with user provided crypto keys to sign payloads.

cloudkms.cryptoKeyVersions.get

cloudkms.cryptoKeyVersions.useToSign

cloudkms.cryptoKeyVersions.useToVerify

cloudkms.cryptoKeyVersions.viewPublicKey

cloudkms.cryptoKeys.get

cloudkms.locations.get

cloudkms.locations.list

resourcemanager.projects.get

Kubernetes Engine Cluster Admin

(roles/container.clusterAdmin)

Provides access to management of clusters.

To set a service account on nodes, you must also have the Service Account User role (roles/iam.serviceAccountUser) on the user-managed service account that your nodes will use.

Lowest-level resources where you can grant this role:

container.clusters.connect

container.clusters.create

container.clusters.delete

container.clusters.get

container.clusters.list

container.clusters.update

container.operations.*

resourcemanager.projects.get

resourcemanager.projects.list

Kubernetes Engine Cluster Viewer

(roles/container.clusterViewer)

Provides access to get and list GKE clusters.

container.clusters.connect

container.clusters.get

container.clusters.list

resourcemanager.projects.get

resourcemanager.projects.list

Kubernetes Engine Default Node Service Account

(roles/container.defaultNodeServiceAccount)

Least privilege role to use as the default service account for GKE Nodes.

autoscaling.sites.writeMetrics

logging.logEntries.create

monitoring.metricDescriptors.create

monitoring.metricDescriptors.list

monitoring.timeSeries.*

Kubernetes Engine Default Node Service Agent

(roles/container.defaultNodeServiceAgent)

Minimal set of permissions required by a GKE node to support standard capabilities such as logging and monitoring. Replaces the container.nodeServiceAgent role with a reduced permission set.

Warning: Do not grant service agent roles to any principals except service agents.

autoscaling.sites.writeMetrics

logging.logEntries.create

monitoring.metricDescriptors.create

monitoring.metricDescriptors.list

monitoring.timeSeries.*

serviceusage.services.use

Kubernetes Engine Developer

(roles/container.developer)

Provides access to Kubernetes API objects inside clusters.

Lowest-level resources where you can grant this role:

container.apiServices.*

container.auditSinks.*

container.backendConfigs.*

container.bindings.*

container.certificateSigningRequests.create

container.certificateSigningRequests.delete

container.certificateSigningRequests.get

container.certificateSigningRequests.list

container.certificateSigningRequests.update

container.certificateSigningRequests.updateStatus

container.clusterRoleBindings.get

container.clusterRoleBindings.list

container.clusterRoles.get

container.clusterRoles.list

container.clusters.connect

container.clusters.get

container.clusters.list

container.componentStatuses.*

container.configMaps.*

container.controllerRevisions.get

container.controllerRevisions.list

container.cronJobs.*

container.csiDrivers.*

container.csiNodeInfos.*

container.csiNodes.*

container.customResourceDefinitions.*

container.daemonSets.*

container.deployments.*

container.endpointSlices.*

container.endpoints.*

container.events.*

container.frontendConfigs.*

container.horizontalPodAutoscalers.*

container.ingresses.*

container.initializerConfigurations.*

container.jobs.*

container.leases.*

container.limitRanges.*

container.localSubjectAccessReviews.*

container.managedCertificates.*

container.mutatingWebhookConfigurations.get

container.mutatingWebhookConfigurations.list

container.namespaces.*

container.networkPolicies.*

container.nodes.*

container.persistentVolumeClaims.*

container.persistentVolumes.*

container.petSets.*

container.podDisruptionBudgets.*

container.podPresets.*

container.podSecurityPolicies.get

container.podSecurityPolicies.list

container.podTemplates.*

container.pods.*

container.priorityClasses.*

container.replicaSets.*

container.replicationControllers.*

container.resourceQuotas.*

container.roleBindings.get

container.roleBindings.list

container.roles.get

container.roles.list

container.runtimeClasses.*

container.scheduledJobs.*

container.secrets.*

container.selfSubjectAccessReviews.*

container.selfSubjectRulesReviews.create

container.serviceAccounts.*

container.services.*

container.statefulSets.*

container.storageClasses.*

container.storageStates.*

container.storageVersionMigrations.*

container.subjectAccessReviews.*

container.thirdPartyObjects.*

container.thirdPartyResources.*

container.tokenReviews.create

container.updateInfos.*

container.validatingWebhookConfigurations.get

container.validatingWebhookConfigurations.list

container.volumeAttachments.*

container.volumeSnapshotClasses.*

container.volumeSnapshotContents.*

container.volumeSnapshots.*

recommender.containerDiagnosisInsights.*

recommender.containerDiagnosisRecommendations.*

recommender.locations.*

recommender.networkAnalyzerGkeConnectivityInsights.*

recommender.networkAnalyzerGkeIpAddressInsights.*

resourcemanager.projects.get

resourcemanager.projects.list

Kubernetes Engine Host Service Agent User

(roles/container.hostServiceAgentUser)

Allows the Kubernetes Engine service account in the host project to configure shared network resources for cluster management. Also gives access to inspect the firewall rules in the host project.

compute.firewalls.get

compute.networks.get

container.hostServiceAgent.use

dns.networks.bindDNSResponsePolicy

dns.networks.bindPrivateDNSPolicy

dns.networks.bindPrivateDNSZone

dns.responsePolicies.*

dns.responsePolicyRules.*

[Deprecated] Kubernetes Engine Node Service Agent

(roles/container.nodeServiceAgent)

Minimal set of permission required by a GKE node to support standard capabilities such as logging and monitoring export, and image pulls.

Warning: Do not grant service agent roles to any principals except service agents.

autoscaling.sites.writeMetrics

logging.logEntries.create

monitoring.metricDescriptors.create

monitoring.metricDescriptors.list

monitoring.timeSeries.*

resourcemanager.projects.get

resourcemanager.projects.list

serviceusage.services.use

storage.objects.get

storage.objects.list

Kubernetes Engine Service Agent

(roles/container.serviceAgent)

Gives Kubernetes Engine account access to manage cluster resources. Includes access to service accounts.

Warning: Do not grant service agent roles to any principals except service agents.

autoscaling.sites.readRecommendations

autoscaling.sites.writeMetrics

autoscaling.sites.writeState

backupdr.backupPlanAssociations.createForComputeDisk

backupdr.backupPlanAssociations.createForComputeInstance

backupdr.backupPlanAssociations.deleteForComputeDisk

backupdr.backupPlanAssociations.deleteForComputeInstance

backupdr.backupPlanAssociations.getForComputeDisk

backupdr.backupPlanAssociations.list

backupdr.backupPlanAssociations.triggerBackupForComputeDisk

backupdr.backupPlanAssociations.triggerBackupForComputeInstance

backupdr.backupPlanAssociations.updateForComputeDisk

backupdr.backupPlanAssociations.updateForComputeInstance

backupdr.backupPlans.get

backupdr.backupPlans.list

backupdr.backupPlans.useForComputeDisk

backupdr.backupPlans.useForComputeInstance

backupdr.backupVaults.get

backupdr.backupVaults.list

backupdr.locations.list

backupdr.operations.get

backupdr.operations.list

backupdr.serviceConfig.initialize

bigquery.datasets.create

bigquery.datasets.get

bigquery.tables.create

bigquery.tables.get

bigquery.tables.update

bigquery.tables.updateData

binaryauthorization.policy.evaluatePolicy

certificatemanager.certissuanceconfigs.create

certificatemanager.certissuanceconfigs.delete

certificatemanager.certissuanceconfigs.get

certificatemanager.certissuanceconfigs.list

certificatemanager.certissuanceconfigs.listEffectiveTags

certificatemanager.certissuanceconfigs.listTagBindings

certificatemanager.certissuanceconfigs.update

certificatemanager.certissuanceconfigs.use

certificatemanager.certmapentries.create

certificatemanager.certmapentries.delete

certificatemanager.certmapentries.get

certificatemanager.certmapentries.list

certificatemanager.certmapentries.listEffectiveTags

certificatemanager.certmapentries.listTagBindings

certificatemanager.certmapentries.update

certificatemanager.certmaps.create

certificatemanager.certmaps.delete

certificatemanager.certmaps.get

certificatemanager.certmaps.list

certificatemanager.certmaps.listEffectiveTags

certificatemanager.certmaps.listTagBindings

certificatemanager.certmaps.update

certificatemanager.certmaps.use

certificatemanager.certs.create

certificatemanager.certs.delete

certificatemanager.certs.get

certificatemanager.certs.list

certificatemanager.certs.listEffectiveTags

certificatemanager.certs.listTagBindings

certificatemanager.certs.update

certificatemanager.certs.use

certificatemanager.dnsauthorizations.create

certificatemanager.dnsauthorizations.delete

certificatemanager.dnsauthorizations.get

certificatemanager.dnsauthorizations.list

certificatemanager.dnsauthorizations.listEffectiveTags

certificatemanager.dnsauthorizations.listTagBindings

certificatemanager.dnsauthorizations.update

certificatemanager.dnsauthorizations.use

compute.acceleratorTypes.*

compute.addresses.*

compute.autoscalers.*

compute.backendBuckets.*

compute.backendServices.*

compute.crossSiteNetworks.*

compute.diskSettings.*

compute.diskTypes.*

compute.disks.*

compute.externalVpnGateways.*

compute.firewallPolicies.*

compute.firewalls.*

compute.forwardingRules.*

compute.futureReservations.list

compute.globalAddresses.*

compute.globalForwardingRules.*

compute.globalNetworkEndpointGroups.*

compute.globalOperations.get

compute.globalOperations.list

compute.globalPublicDelegatedPrefixes.delete

compute.globalPublicDelegatedPrefixes.get

compute.globalPublicDelegatedPrefixes.list

compute.globalPublicDelegatedPrefixes.updatePolicy

compute.healthChecks.*

compute.httpHealthChecks.*

compute.httpsHealthChecks.*

compute.images.*

compute.instanceGroupManagers.*

compute.instanceGroups.*

compute.instanceSettings.*

compute.instanceTemplates.*

compute.instances.*

compute.instantSnapshots.*

compute.interconnectAttachmentGroups.*

compute.interconnectAttachments.*

compute.interconnectGroups.*

compute.interconnectLocations.*

compute.interconnectRemoteLocations.*

compute.interconnects.*

compute.licenseCodes.*

compute.licenses.*

compute.machineImages.*

compute.machineTypes.*

compute.multiMig.*

compute.networkAttachments.*

compute.networkEndpointGroups.*

compute.networkProfiles.*

compute.networks.*

compute.nodeGroups.get

compute.packetMirrorings.*

compute.projects.get

compute.projects.setCommonInstanceMetadata

compute.publicDelegatedPrefixes.delete

compute.publicDelegatedPrefixes.get

compute.publicDelegatedPrefixes.list

compute.publicDelegatedPrefixes.listEffectiveTags

compute.publicDelegatedPrefixes.listTagBindings

compute.publicDelegatedPrefixes.update

compute.publicDelegatedPrefixes.updatePolicy

compute.regionBackendServices.*

compute.regionFirewallPolicies.*

compute.regionHealthCheckServices.*

compute.regionHealthChecks.*

compute.regionNetworkEndpointGroups.*

compute.regionNotificationEndpoints.*

compute.regionOperations.get

compute.regionOperations.list

compute.regionSecurityPolicies.*

compute.regionSslCertificates.*

compute.regionSslPolicies.*

compute.regionTargetHttpProxies.*

compute.regionTargetHttpsProxies.*

compute.regionTargetTcpProxies.*

compute.regionUrlMaps.*

compute.regions.*

compute.reservationBlocks.get

compute.reservationBlocks.list

compute.reservationSubBlocks.*

compute.reservations.get

compute.reservations.list

compute.resourcePolicies.*

compute.routers.*

compute.routes.*

compute.securityPolicies.*

compute.serviceAttachments.*

compute.snapshots.*

compute.spotAssistants.get

compute.sslCertificates.*

compute.sslPolicies.*

compute.storagePools.*

compute.subnetworks.*

compute.targetGrpcProxies.*

compute.targetHttpProxies.*

compute.targetHttpsProxies.*

compute.targetInstances.*

compute.targetPools.*

compute.targetSslProxies.*

compute.targetTcpProxies.*

compute.targetVpnGateways.*

compute.urlMaps.*

compute.vpnGateways.*

compute.vpnTunnels.*

compute.wireGroups.*

compute.zoneOperations.get

compute.zoneOperations.list

compute.zones.*

container.*

dns.changes.*

dns.dnsKeys.*

dns.gkeClusters.*

dns.managedZoneOperations.*

dns.managedZones.create

dns.managedZones.delete

dns.managedZones.get

dns.managedZones.getIamPolicy

dns.managedZones.list

dns.managedZones.update

dns.networks.*

dns.policies.*

dns.projects.get

dns.resourceRecordSets.*

dns.responsePolicies.*

dns.responsePolicyRules.*

file.*

iam.serviceAccounts.actAs

iam.serviceAccounts.get

logging.logEntries.create

lustre.instances.create

lustre.instances.delete

lustre.instances.get

lustre.instances.importData

lustre.instances.list

lustre.instances.update

lustre.locations.*

lustre.operations.*

monitoring.metricDescriptors.create

monitoring.metricDescriptors.get

monitoring.metricDescriptors.list

monitoring.timeSeries.*

networkconnectivity.internalRanges.*

networkconnectivity.locations.*

networkconnectivity.operations.*

networkconnectivity.policyBasedRoutes.*

networkconnectivity.regionalEndpoints.*

networkconnectivity.serviceClasses.*

networkconnectivity.serviceConnectionMaps.*

networkconnectivity.serviceConnectionPolicies.*

networkmanagement.connectivitytests.get

networkmanagement.connectivitytests.list

networksecurity.addressGroups.*

networksecurity.authorizationPolicies.*

networksecurity.authzPolicies.*

networksecurity.backendAuthenticationConfigs.*

networksecurity.clientTlsPolicies.*

networksecurity.firewallEndpointAssociations.*

networksecurity.firewallEndpoints.*

networksecurity.gatewaySecurityPolicies.*

networksecurity.gatewaySecurityPolicyRules.*

networksecurity.locations.*

networksecurity.operations.*

networksecurity.sacAttachments.*

networksecurity.sacRealms.*

networksecurity.securityProfileGroups.*

networksecurity.securityProfiles.*

networksecurity.serverTlsPolicies.*

networksecurity.tlsInspectionPolicies.*

networksecurity.urlLists.*

networkservices.*

parallelstore.instances.create

parallelstore.instances.delete

parallelstore.instances.get

parallelstore.instances.importData

parallelstore.instances.list

parallelstore.instances.update

parallelstore.locations.*

parallelstore.operations.*

pubsub.topics.create

pubsub.topics.get

pubsub.topics.publish

recommender.containerDiagnosisInsights.*

recommender.containerDiagnosisRecommendations.*

recommender.locations.*

recommender.networkAnalyzerGkeConnectivityInsights.*

recommender.networkAnalyzerGkeIpAddressInsights.*

resourcemanager.projects.get

resourcemanager.projects.list

resourcemanager.tagValueBindings.create

servicedirectory.namespaces.create

servicedirectory.namespaces.delete

servicedirectory.services.create

servicedirectory.services.delete

servicenetworking.operations.get

servicenetworking.services.addPeering

servicenetworking.services.createPeeredDnsDomain

servicenetworking.services.deleteConnection

servicenetworking.services.deletePeeredDnsDomain

servicenetworking.services.disableVpcServiceControls

servicenetworking.services.enableVpcServiceControls

servicenetworking.services.get

servicenetworking.services.listPeeredDnsDomains

serviceusage.quotas.get

serviceusage.services.get

serviceusage.services.list

serviceusage.services.use

tpu.locations.*

tpu.nodes.create

tpu.nodes.delete

tpu.nodes.get

tpu.nodes.list

tpu.operations.*

trafficdirector.*

Kubernetes Engine Viewer

(roles/container.viewer)

Provides read-only access to resources within GKE clusters, such as nodes, pods, and GKE API objects.

Lowest-level resources where you can grant this role:

container.apiServices.get

container.apiServices.getStatus

container.apiServices.list

container.auditSinks.get

container.auditSinks.list

container.backendConfigs.get

container.backendConfigs.list

container.bindings.get

container.bindings.list

container.certificateSigningRequests.get

container.certificateSigningRequests.getStatus

container.certificateSigningRequests.list

container.clusterRoleBindings.get

container.clusterRoleBindings.list

container.clusterRoles.get

container.clusterRoles.list

container.clusters.connect

container.clusters.get

container.clusters.list

container.componentStatuses.*

container.configMaps.get

container.configMaps.list

container.controllerRevisions.get

container.controllerRevisions.list

container.cronJobs.get

container.cronJobs.getStatus

container.cronJobs.list

container.csiDrivers.get

container.csiDrivers.list

container.csiNodeInfos.get

container.csiNodeInfos.list

container.csiNodes.get

container.csiNodes.list

container.customResourceDefinitions.get

container.customResourceDefinitions.getStatus

container.customResourceDefinitions.list

container.daemonSets.get

container.daemonSets.getStatus

container.daemonSets.list

container.deployments.get

container.deployments.getScale

container.deployments.getStatus

container.deployments.list

container.endpointSlices.get

container.endpointSlices.list

container.endpoints.get

container.endpoints.list

container.events.get

container.events.list

container.frontendConfigs.get

container.frontendConfigs.list

container.horizontalPodAutoscalers.get

container.horizontalPodAutoscalers.getStatus

container.horizontalPodAutoscalers.list

container.ingresses.get

container.ingresses.getStatus

container.ingresses.list

container.initializerConfigurations.get

container.initializerConfigurations.list

container.jobs.get

container.jobs.getStatus

container.jobs.list

container.leases.get

container.leases.list

container.limitRanges.get

container.limitRanges.list

container.managedCertificates.get

container.managedCertificates.list

container.mutatingWebhookConfigurations.get

container.mutatingWebhookConfigurations.list

container.namespaces.get

container.namespaces.getStatus

container.namespaces.list

container.networkPolicies.get

container.networkPolicies.list

container.nodes.get

container.nodes.getStatus

container.nodes.list

container.operations.*

container.persistentVolumeClaims.get

container.persistentVolumeClaims.getStatus

container.persistentVolumeClaims.list

container.persistentVolumes.get

container.persistentVolumes.getStatus

container.persistentVolumes.list

container.petSets.get

container.petSets.list

container.podDisruptionBudgets.get

container.podDisruptionBudgets.getStatus

container.podDisruptionBudgets.list

container.podPresets.get

container.podPresets.list

container.podSecurityPolicies.get

container.podSecurityPolicies.list

container.podTemplates.get

container.podTemplates.list

container.pods.get

container.pods.getStatus

container.pods.list

container.priorityClasses.get

container.priorityClasses.list

container.replicaSets.get

container.replicaSets.getScale

container.replicaSets.getStatus

container.replicaSets.list

container.replicationControllers.get

container.replicationControllers.getScale

container.replicationControllers.getStatus

container.replicationControllers.list

container.resourceQuotas.get

container.resourceQuotas.getStatus

container.resourceQuotas.list

container.roleBindings.get

container.roleBindings.list

container.roles.get

container.roles.list

container.runtimeClasses.get

container.runtimeClasses.list

container.scheduledJobs.get

container.scheduledJobs.list

container.serviceAccounts.get

container.serviceAccounts.list

container.services.get

container.services.getStatus

container.services.list

container.statefulSets.get

container.statefulSets.getScale

container.statefulSets.getStatus

container.statefulSets.list

container.storageClasses.get

container.storageClasses.list

container.storageStates.get

container.storageStates.getStatus

container.storageStates.list

container.storageVersionMigrations.get

container.storageVersionMigrations.getStatus

container.storageVersionMigrations.list

container.thirdPartyObjects.get

container.thirdPartyObjects.list

container.thirdPartyResources.get

container.thirdPartyResources.list

container.tokenReviews.create

container.updateInfos.get

container.updateInfos.list

container.validatingWebhookConfigurations.get

container.validatingWebhookConfigurations.list

container.volumeAttachments.get

container.volumeAttachments.getStatus

container.volumeAttachments.list

container.volumeSnapshotClasses.get

container.volumeSnapshotClasses.list

container.volumeSnapshotContents.get

container.volumeSnapshotContents.getStatus

container.volumeSnapshotContents.list

container.volumeSnapshots.get

container.volumeSnapshots.list

recommender.containerDiagnosisInsights.get

recommender.containerDiagnosisInsights.list

recommender.containerDiagnosisRecommendations.get

recommender.containerDiagnosisRecommendations.list

recommender.locations.*

recommender.networkAnalyzerGkeConnectivityInsights.get

recommender.networkAnalyzerGkeConnectivityInsights.list

recommender.networkAnalyzerGkeIpAddressInsights.get

recommender.networkAnalyzerGkeIpAddressInsights.list

resourcemanager.projects.get

resourcemanager.projects.list


RetroSearch is an open source project built by @garambo | Open a GitHub Issue

Search and Browse the WWW like it's 1997 | Search results from DuckDuckGo

HTML: 3.2 | Encoding: UTF-8 | Version: 0.7.4