This page lists the IAM roles and permissions for Network Management API. To search through all roles and permissions, see the role and permission index .
Network Management API roles
Network Management Admin
( roles/
)
Full access to Network Management resources.
Lowest-level resources where you can grant this role:
- Project
networkmanagement.*
-
networkmanagement.
connectivitytests. create -
networkmanagement.
connectivitytests. delete -
networkmanagement.
connectivitytests. get -
networkmanagement.
connectivitytests. getIamPolicy -
networkmanagement.
connectivitytests. list -
networkmanagement.
connectivitytests. rerun -
networkmanagement.
connectivitytests. setIamPolicy -
networkmanagement.
connectivitytests. update -
networkmanagement.
locations. get -
networkmanagement.
locations. list -
networkmanagement.
operations. cancel -
networkmanagement.
operations. delete -
networkmanagement.
operations. get -
networkmanagement.
operations. list -
networkmanagement.
vpcflowlogsconfigs. create -
networkmanagement.
vpcflowlogsconfigs. delete -
networkmanagement.
vpcflowlogsconfigs. get -
networkmanagement.
vpcflowlogsconfigs. list -
networkmanagement.
vpcflowlogsconfigs. update
resourcemanager.
resourcemanager.projects.get
resourcemanager.projects.list
GCP Network Management Service Agent
( roles/
)
Grants the GCP Network Management API the authority to complete analysis based on network configurations from Compute Engine and Container Engine.
cloudsql.instances.get
cloudsql.instances.list
compute.addresses.get
compute.addresses.list
compute.backendServices.get
compute.backendServices.list
compute.
compute.
compute.firewalls.get
compute.firewalls.list
compute.forwardingRules.get
compute.forwardingRules.list
compute.globalAddresses.get
compute.globalAddresses.list
compute.
compute.
compute.
compute.
compute.healthChecks.get
compute.healthChecks.list
compute.httpHealthChecks.get
compute.httpHealthChecks.list
compute.httpsHealthChecks.get
compute.httpsHealthChecks.list
compute.instanceGroups.get
compute.instanceGroups.list
compute.instances.get
compute.instances.list
compute.
compute.
compute.networks.get
compute.
compute.networks.list
compute.
compute.packetMirrorings.get
compute.packetMirrorings.list
compute.
compute.
compute.regionHealthChecks.get
compute.
compute.
compute.
compute.
compute.
compute.
compute.
compute.
compute.
compute.regionUrlMaps.get
compute.regionUrlMaps.list
compute.routers.get
compute.routers.list
compute.routes.get
compute.routes.list
compute.subnetworks.get
compute.subnetworks.list
compute.targetGrpcProxies.get
compute.targetGrpcProxies.list
compute.targetHttpProxies.get
compute.targetHttpProxies.list
compute.targetHttpsProxies.get
compute.
compute.targetInstances.get
compute.targetInstances.list
compute.targetPools.get
compute.targetPools.list
compute.targetSslProxies.get
compute.targetSslProxies.list
compute.targetTcpProxies.get
compute.targetTcpProxies.list
compute.targetVpnGateways.get
compute.targetVpnGateways.list
compute.urlMaps.get
compute.urlMaps.list
compute.vpnGateways.get
compute.vpnGateways.list
compute.vpnTunnels.get
compute.vpnTunnels.list
container.clusters.get
container.clusters.list
container.nodes.get
container.nodes.list
Network Management Viewer
( roles/
)
Read-only access to Network Management resources.
Lowest-level resources where you can grant this role:
- Project
networkmanagement.
networkmanagement.
networkmanagement.
networkmanagement.locations.*
-
networkmanagement.
locations. get -
networkmanagement.
locations. list
networkmanagement.
networkmanagement.
networkmanagement.
networkmanagement.
resourcemanager.
resourcemanager.projects.get
resourcemanager.projects.list
Network Management API permissions
networkmanagement.
connectivitytests.
create
Owner
( roles/
)
Editor
( roles/
)
Network Administrator
( roles/
)
Network Management Admin
( roles/
)
networkmanagement.
connectivitytests.
delete
Owner
( roles/
)
Editor
( roles/
)
Network Administrator
( roles/
)
Network Management Admin
( roles/
)
networkmanagement.
connectivitytests.
get
Owner
( roles/
)
Editor
( roles/
)
Viewer
( roles/
)
Compute Network Admin
( roles/
)
Compute Network User
( roles/
)
Compute Network Viewer
( roles/
)
Infrastructure Administrator
( roles/
)
Network Administrator
( roles/
)
Security Auditor
( roles/
)
Support User
( roles/
)
Network Management Admin
( roles/
)
Network Management Viewer
( roles/
)
Service agent roles
- Cloud Composer API Service Agent
(
roles/
)composer.serviceAgent - Kubernetes Engine Service Agent
(
roles/
)container.serviceAgent - Cloud Dataflow Service Agent
(
roles/
)dataflow.serviceAgent - Cloud Data Fusion API Service Agent
(
roles/
)datafusion.serviceAgent - Cloud TPU V2 API Service Agent
(
roles/
)cloudtpu.serviceAgent
networkmanagement.
connectivitytests.
getIamPolicy
Owner
( roles/
)
Editor
( roles/
)
Viewer
( roles/
)
Network Administrator
( roles/
)
Security Admin
( roles/
)
Security Auditor
( roles/
)
Security Reviewer
( roles/
)
Support User
( roles/
)
Network Management Admin
( roles/
)
Network Management Viewer
( roles/
)
networkmanagement.
connectivitytests.
list
Owner
( roles/
)
Editor
( roles/
)
Viewer
( roles/
)
Compute Network Admin
( roles/
)
Compute Network User
( roles/
)
Compute Network Viewer
( roles/
)
Infrastructure Administrator
( roles/
)
Network Administrator
( roles/
)
Security Admin
( roles/
)
Security Auditor
( roles/
)
Security Reviewer
( roles/
)
Support User
( roles/
)
Network Management Admin
( roles/
)
Network Management Viewer
( roles/
)
Service agent roles
- Cloud Composer API Service Agent
(
roles/
)composer.serviceAgent - Kubernetes Engine Service Agent
(
roles/
)container.serviceAgent - Cloud Dataflow Service Agent
(
roles/
)dataflow.serviceAgent - Cloud Data Fusion API Service Agent
(
roles/
)datafusion.serviceAgent - Database Migration Service Agent
(
roles/
)datamigration.serviceAgent - Cloud TPU V2 API Service Agent
(
roles/
)cloudtpu.serviceAgent
networkmanagement.
connectivitytests.
rerun
Owner
( roles/
)
Editor
( roles/
)
Network Administrator
( roles/
)
Network Management Admin
( roles/
)
networkmanagement.
connectivitytests.
setIamPolicy
Owner
( roles/
)
Network Administrator
( roles/
)
Security Admin
( roles/
)
Network Management Admin
( roles/
)
networkmanagement.
connectivitytests.
update
Owner
( roles/
)
Editor
( roles/
)
Network Administrator
( roles/
)
Network Management Admin
( roles/
)
networkmanagement.
locations.
get
Owner
( roles/
)
Editor
( roles/
)
Viewer
( roles/
)
Network Administrator
( roles/
)
Support User
( roles/
)
Network Management Admin
( roles/
)
Network Management Viewer
( roles/
)
networkmanagement.
locations.
list
Owner
( roles/
)
Editor
( roles/
)
Viewer
( roles/
)
Network Administrator
( roles/
)
Security Admin
( roles/
)
Security Auditor
( roles/
)
Security Reviewer
( roles/
)
Support User
( roles/
)
Network Management Admin
( roles/
)
Network Management Viewer
( roles/
)
networkmanagement.
operations.
cancel
Owner
( roles/
)
Editor
( roles/
)
Network Administrator
( roles/
)
Network Management Admin
( roles/
)
networkmanagement.
operations.
delete
Owner
( roles/
)
Editor
( roles/
)
Network Administrator
( roles/
)
Network Management Admin
( roles/
)
networkmanagement.
operations.
get
Owner
( roles/
)
Editor
( roles/
)
Viewer
( roles/
)
Network Administrator
( roles/
)
Support User
( roles/
)
Network Management Admin
( roles/
)
Network Management Viewer
( roles/
)
networkmanagement.
operations.
list
Owner
( roles/
)
Editor
( roles/
)
Viewer
( roles/
)
Network Administrator
( roles/
)
Security Admin
( roles/
)
Security Auditor
( roles/
)
Security Reviewer
( roles/
)
Support User
( roles/
)
Network Management Admin
( roles/
)
Network Management Viewer
( roles/
)
networkmanagement.
vpcflowlogsconfigs.
create
Owner
( roles/
)
Editor
( roles/
)
Network Administrator
( roles/
)
Network Management Admin
( roles/
)
networkmanagement.
vpcflowlogsconfigs.
delete
Owner
( roles/
)
Editor
( roles/
)
Network Administrator
( roles/
)
Network Management Admin
( roles/
)
networkmanagement.
vpcflowlogsconfigs.
get
Owner
( roles/
)
Editor
( roles/
)
Viewer
( roles/
)
Network Administrator
( roles/
)
Support User
( roles/
)
Network Management Admin
( roles/
)
Network Management Viewer
( roles/
)
networkmanagement.
vpcflowlogsconfigs.
list
Owner
( roles/
)
Editor
( roles/
)
Viewer
( roles/
)
Network Administrator
( roles/
)
Security Admin
( roles/
)
Security Auditor
( roles/
)
Security Reviewer
( roles/
)
Support User
( roles/
)
Network Management Admin
( roles/
)
Network Management Viewer
( roles/
)
networkmanagement.
vpcflowlogsconfigs.
update
Owner
( roles/
)
Editor
( roles/
)
Network Administrator
( roles/
)
Network Management Admin
( roles/
)