This page lists the IAM roles and permissions for Binary Authorization. To search through all roles and permissions, see the role and permission index .
Binary Authorization roles
Binary Authorization Admin
( roles/
)
Admin role for Binary Authorization
binaryauthorization.*
-
binaryauthorization.attestors. create -
binaryauthorization.attestors. delete -
binaryauthorization.attestors. get -
binaryauthorization.attestors. getIamPolicy -
binaryauthorization.attestors. list -
binaryauthorization.attestors. setIamPolicy -
binaryauthorization.attestors. update -
binaryauthorization.attestors. verifyImageAttested -
binaryauthorization.continuousValidationConfig. get -
binaryauthorization.continuousValidationConfig. getIamPolicy -
binaryauthorization.continuousValidationConfig. setIamPolicy -
binaryauthorization.continuousValidationConfig. update -
binaryauthorization.platformPolicies. create -
binaryauthorization.platformPolicies. delete -
binaryauthorization.platformPolicies. evaluatePolicy -
binaryauthorization.platformPolicies. get -
binaryauthorization.platformPolicies. list -
binaryauthorization.platformPolicies. replace -
binaryauthorization.policy. evaluatePolicy -
binaryauthorization.policy.get -
binaryauthorization.policy. getIamPolicy -
binaryauthorization.policy. setIamPolicy -
binaryauthorization.policy. update
resourcemanager.projects.get
resourcemanager.projects.list
Binary Authorization Editor
( roles/
)
Editor role for Binary Authorization
binaryauthorization.
binaryauthorization.
binaryauthorization.
binaryauthorization.
binaryauthorization.
binaryauthorization.
binaryauthorization.
binaryauthorization.
binaryauthorization.
binaryauthorization.
binaryauthorization.
-
binaryauthorization.platformPolicies. create -
binaryauthorization.platformPolicies. delete -
binaryauthorization.platformPolicies. evaluatePolicy -
binaryauthorization.platformPolicies. get -
binaryauthorization.platformPolicies. list -
binaryauthorization.platformPolicies. replace
binaryauthorization.
binaryauthorization.policy.get
binaryauthorization.
binaryauthorization.
resourcemanager.projects.get
resourcemanager.projects.list
Binary Authorization Viewer
( roles/
)
Viewer role for Binary Authorization
binaryauthorization.
binaryauthorization.
binaryauthorization.
binaryauthorization.
binaryauthorization.
binaryauthorization.
binaryauthorization.
binaryauthorization.
binaryauthorization.
binaryauthorization.
binaryauthorization.policy.get
binaryauthorization.
resourcemanager.projects.get
resourcemanager.projects.list
Binary Authorization Attestor Admin
( roles/
)
Administrator of Binary Authorization Attestors
binaryauthorization.
-
binaryauthorization.attestors. create -
binaryauthorization.attestors. delete -
binaryauthorization.attestors. get -
binaryauthorization.attestors. getIamPolicy -
binaryauthorization.attestors. list -
binaryauthorization.attestors. setIamPolicy -
binaryauthorization.attestors. update -
binaryauthorization.attestors. verifyImageAttested
resourcemanager.projects.get
resourcemanager.projects.list
Binary Authorization Attestor Editor
( roles/
)
Editor of Binary Authorization Attestors
binaryauthorization.
binaryauthorization.
binaryauthorization.
binaryauthorization.
binaryauthorization.
binaryauthorization.
resourcemanager.projects.get
resourcemanager.projects.list
Binary Authorization Attestor Image Verifier
( roles/
)
Caller of Binary Authorization Attestors VerifyImageAttested
binaryauthorization.
binaryauthorization.
binaryauthorization.
resourcemanager.projects.get
resourcemanager.projects.list
Binary Authorization Attestor Viewer
( roles/
)
Viewer of Binary Authorization Attestors
binaryauthorization.
binaryauthorization.
resourcemanager.projects.get
resourcemanager.projects.list
Binary Authorization Policy Administrator
( roles/
)
Administrator of Binary Authorization Policy
binaryauthorization.
-
binaryauthorization.continuousValidationConfig. get -
binaryauthorization.continuousValidationConfig. getIamPolicy -
binaryauthorization.continuousValidationConfig. setIamPolicy -
binaryauthorization.continuousValidationConfig. update
binaryauthorization.
-
binaryauthorization.platformPolicies. create -
binaryauthorization.platformPolicies. delete -
binaryauthorization.platformPolicies. evaluatePolicy -
binaryauthorization.platformPolicies. get -
binaryauthorization.platformPolicies. list -
binaryauthorization.platformPolicies. replace
binaryauthorization.policy.*
-
binaryauthorization.policy. evaluatePolicy -
binaryauthorization.policy.get -
binaryauthorization.policy. getIamPolicy -
binaryauthorization.policy. setIamPolicy -
binaryauthorization.policy. update
resourcemanager.projects.get
resourcemanager.projects.list
Binary Authorization Policy Editor
( roles/
)
Editor of Binary Authorization Policy
binaryauthorization.
binaryauthorization.
binaryauthorization.
-
binaryauthorization.platformPolicies. create -
binaryauthorization.platformPolicies. delete -
binaryauthorization.platformPolicies. evaluatePolicy -
binaryauthorization.platformPolicies. get -
binaryauthorization.platformPolicies. list -
binaryauthorization.platformPolicies. replace
binaryauthorization.
binaryauthorization.policy.get
binaryauthorization.
resourcemanager.projects.get
resourcemanager.projects.list
Binary Authorization Policy Evaluator
( roles/
)
Evaluator of Binary Authorization Policy
binaryauthorization.
binaryauthorization.
binaryauthorization.
binaryauthorization.
binaryauthorization.policy.get
resourcemanager.projects.get
resourcemanager.projects.list
Binary Authorization Policy Viewer
( roles/
)
Viewer of Binary Authorization Policy
binaryauthorization.
binaryauthorization.
binaryauthorization.
binaryauthorization.policy.get
resourcemanager.projects.get
resourcemanager.projects.list
Service agent roles
Service agent roles should only be granted to service agents .
| Role | Permissions |
|---|---|
Binary Authorization Service Agent( Can read Notes and Occurrences from the Container Analysis Service to find and verify signatures. |
|
Binary Authorization permissions
binaryauthorization.
attestors.
create
Owner
( roles/
)
Editor
( roles/
)
Binary Authorization Admin
( roles/
)
Binary Authorization Editor
( roles/
)
Binary Authorization Attestor Admin
( roles/
)
Binary Authorization Attestor Editor
( roles/
)
Service agent roles
- Cloud Build Service Agent
(
roles/)cloudbuild.serviceAgent
binaryauthorization.
attestors.
delete
Owner
( roles/
)
Editor
( roles/
)
Binary Authorization Admin
( roles/
)
Binary Authorization Editor
( roles/
)
Binary Authorization Attestor Admin
( roles/
)
Binary Authorization Attestor Editor
( roles/
)
Service agent roles
- Cloud Build Service Agent
(
roles/)cloudbuild.serviceAgent
binaryauthorization.
attestors.
get
Owner
( roles/
)
Editor
( roles/
)
Viewer
( roles/
)
Binary Authorization Admin
( roles/
)
Binary Authorization Editor
( roles/
)
Binary Authorization Viewer
( roles/
)
Binary Authorization Attestor Admin
( roles/
)
Binary Authorization Attestor Editor
( roles/
)
Binary Authorization Attestor Image Verifier
( roles/
)
Binary Authorization Attestor Viewer
( roles/
)
Support User
( roles/
)
Service agent roles
- Binary Authorization Service Agent
(
roles/)binaryauthorization.serviceAgent - Cloud Build Service Agent
(
roles/)cloudbuild.serviceAgent
binaryauthorization.
attestors.
getIamPolicy
Owner
( roles/
)
Editor
( roles/
)
Viewer
( roles/
)
Binary Authorization Admin
( roles/
)
Binary Authorization Editor
( roles/
)
Binary Authorization Viewer
( roles/
)
Security Admin
( roles/
)
Security Reviewer
( roles/
)
Binary Authorization Attestor Admin
( roles/
)
Security Auditor
( roles/
)
Support User
( roles/
)
binaryauthorization.
attestors.
list
Owner
( roles/
)
Editor
( roles/
)
Viewer
( roles/
)
Binary Authorization Admin
( roles/
)
Binary Authorization Editor
( roles/
)
Binary Authorization Viewer
( roles/
)
Security Admin
( roles/
)
Security Reviewer
( roles/
)
Binary Authorization Attestor Admin
( roles/
)
Binary Authorization Attestor Editor
( roles/
)
Binary Authorization Attestor Image Verifier
( roles/
)
Binary Authorization Attestor Viewer
( roles/
)
Security Auditor
( roles/
)
Support User
( roles/
)
Service agent roles
- Binary Authorization Service Agent
(
roles/)binaryauthorization.serviceAgent - Cloud Build Service Agent
(
roles/)cloudbuild.serviceAgent
binaryauthorization.
attestors.
setIamPolicy
Owner
( roles/
)
Binary Authorization Admin
( roles/
)
Security Admin
( roles/
)
Binary Authorization Attestor Admin
( roles/
)
binaryauthorization.
attestors.
update
Owner
( roles/
)
Editor
( roles/
)
Binary Authorization Admin
( roles/
)
Binary Authorization Editor
( roles/
)
Binary Authorization Attestor Admin
( roles/
)
Binary Authorization Attestor Editor
( roles/
)
Service agent roles
- Cloud Build Service Agent
(
roles/)cloudbuild.serviceAgent
binaryauthorization.
attestors.
verifyImageAttested
Owner
( roles/
)
Editor
( roles/
)
Viewer
( roles/
)
Binary Authorization Admin
( roles/
)
Binary Authorization Editor
( roles/
)
Binary Authorization Viewer
( roles/
)
Binary Authorization Attestor Admin
( roles/
)
Binary Authorization Attestor Editor
( roles/
)
Binary Authorization Attestor Image Verifier
( roles/
)
Support User
( roles/
)
Service agent roles
- Binary Authorization Service Agent
(
roles/)binaryauthorization.serviceAgent - Cloud Build Service Agent
(
roles/)cloudbuild.serviceAgent
binaryauthorization.
continuousValidationConfig.
get
Owner
( roles/
)
Editor
( roles/
)
Viewer
( roles/
)
Binary Authorization Admin
( roles/
)
Binary Authorization Editor
( roles/
)
Binary Authorization Viewer
( roles/
)
Binary Authorization Policy Administrator
( roles/
)
Binary Authorization Policy Editor
( roles/
)
Binary Authorization Policy Viewer
( roles/
)
Dev Ops
( roles/
)
Support User
( roles/
)
binaryauthorization.
continuousValidationConfig.
getIamPolicy
Owner
( roles/
)
Editor
( roles/
)
Viewer
( roles/
)
Binary Authorization Admin
( roles/
)
Binary Authorization Editor
( roles/
)
Binary Authorization Viewer
( roles/
)
Security Admin
( roles/
)
Security Reviewer
( roles/
)
Binary Authorization Policy Administrator
( roles/
)
Dev Ops
( roles/
)
Security Auditor
( roles/
)
Support User
( roles/
)
binaryauthorization.
continuousValidationConfig.
setIamPolicy
Owner
( roles/
)
Binary Authorization Admin
( roles/
)
Security Admin
( roles/
)
Binary Authorization Policy Administrator
( roles/
)
Dev Ops
( roles/
)
binaryauthorization.
continuousValidationConfig.
update
Owner
( roles/
)
Editor
( roles/
)
Binary Authorization Admin
( roles/
)
Binary Authorization Editor
( roles/
)
Binary Authorization Policy Administrator
( roles/
)
Binary Authorization Policy Editor
( roles/
)
Dev Ops
( roles/
)
binaryauthorization.
platformPolicies.
create
Owner
( roles/
)
Editor
( roles/
)
Binary Authorization Admin
( roles/
)
Binary Authorization Editor
( roles/
)
Binary Authorization Policy Administrator
( roles/
)
Binary Authorization Policy Editor
( roles/
)
Dev Ops
( roles/
)
binaryauthorization.
platformPolicies.
delete
Owner
( roles/
)
Editor
( roles/
)
Binary Authorization Admin
( roles/
)
Binary Authorization Editor
( roles/
)
Binary Authorization Policy Administrator
( roles/
)
Binary Authorization Policy Editor
( roles/
)
Dev Ops
( roles/
)
binaryauthorization.
platformPolicies.
evaluatePolicy
Owner
( roles/
)
Editor
( roles/
)
Viewer
( roles/
)
Binary Authorization Admin
( roles/
)
Binary Authorization Editor
( roles/
)
Binary Authorization Viewer
( roles/
)
Binary Authorization Policy Administrator
( roles/
)
Binary Authorization Policy Editor
( roles/
)
Binary Authorization Policy Evaluator
( roles/
)
Dev Ops
( roles/
)
Support User
( roles/
)
Service agent roles
- Binary Authorization Service Agent
(
roles/)binaryauthorization.serviceAgent - Anthos Multi-Cloud Container Service Agent
(
roles/)gkemulticloud.containerServiceAgent - Cloud Run Service Agent
(
roles/)run.serviceAgent
binaryauthorization.
platformPolicies.
get
Owner
( roles/
)
Editor
( roles/
)
Viewer
( roles/
)
Binary Authorization Admin
( roles/
)
Binary Authorization Editor
( roles/
)
Binary Authorization Viewer
( roles/
)
Binary Authorization Policy Administrator
( roles/
)
Binary Authorization Policy Editor
( roles/
)
Binary Authorization Policy Evaluator
( roles/
)
Binary Authorization Policy Viewer
( roles/
)
Dev Ops
( roles/
)
Support User
( roles/
)
Service agent roles
- Anthos Multi-Cloud Container Service Agent
(
roles/)gkemulticloud.containerServiceAgent
binaryauthorization.
platformPolicies.
list
Owner
( roles/
)
Editor
( roles/
)
Viewer
( roles/
)
Binary Authorization Admin
( roles/
)
Binary Authorization Editor
( roles/
)
Binary Authorization Viewer
( roles/
)
Security Admin
( roles/
)
Security Reviewer
( roles/
)
Binary Authorization Policy Administrator
( roles/
)
Binary Authorization Policy Editor
( roles/
)
Binary Authorization Policy Evaluator
( roles/
)
Binary Authorization Policy Viewer
( roles/
)
Dev Ops
( roles/
)
Security Auditor
( roles/
)
Support User
( roles/
)
Service agent roles
- Anthos Multi-Cloud Container Service Agent
(
roles/)gkemulticloud.containerServiceAgent
binaryauthorization.
platformPolicies.
replace
Owner
( roles/
)
Editor
( roles/
)
Binary Authorization Admin
( roles/
)
Binary Authorization Editor
( roles/
)
Binary Authorization Policy Administrator
( roles/
)
Binary Authorization Policy Editor
( roles/
)
Dev Ops
( roles/
)
binaryauthorization.
policy.
evaluatePolicy
Owner
( roles/
)
Editor
( roles/
)
Viewer
( roles/
)
Binary Authorization Admin
( roles/
)
Binary Authorization Editor
( roles/
)
Binary Authorization Viewer
( roles/
)
Binary Authorization Policy Administrator
( roles/
)
Binary Authorization Policy Editor
( roles/
)
Binary Authorization Policy Evaluator
( roles/
)
Dev Ops
( roles/
)
Support User
( roles/
)
Service agent roles
- Vertex AI Service Agent
(
roles/)aiplatform.serviceAgent - Binary Authorization Service Agent
(
roles/)binaryauthorization.serviceAgent - Kubernetes Engine Service Agent
(
roles/)container.serviceAgent - Anthos Multi-Cloud Container Service Agent
(
roles/)gkemulticloud.containerServiceAgent - Cloud Run Service Agent
(
roles/)run.serviceAgent
binaryauthorization.policy.get
Owner
( roles/
)
Editor
( roles/
)
Viewer
( roles/
)
Binary Authorization Admin
( roles/
)
Binary Authorization Editor
( roles/
)
Binary Authorization Viewer
( roles/
)
Binary Authorization Policy Administrator
( roles/
)
Binary Authorization Policy Editor
( roles/
)
Binary Authorization Policy Evaluator
( roles/
)
Binary Authorization Policy Viewer
( roles/
)
Dev Ops
( roles/
)
Support User
( roles/
)
Service agent roles
- Audit Manager Auditing Service Agent
(
roles/)auditmanager.serviceAgent - Cloud Security Compliance Service Agent
(
roles/)cloudsecuritycompliance.serviceAgent - Anthos Multi-Cloud Container Service Agent
(
roles/)gkemulticloud.containerServiceAgent - Security Center Control Service Agent
(
roles/)securitycenter.controlServiceAgent - Security Health Analytics Service Agent
(
roles/)securitycenter.securityHealthAnalyticsServiceAgent - Security Center Service Agent
(
roles/)securitycenter.serviceAgent
binaryauthorization.
policy.
getIamPolicy
Owner
( roles/
)
Editor
( roles/
)
Viewer
( roles/
)
Binary Authorization Admin
( roles/
)
Binary Authorization Editor
( roles/
)
Binary Authorization Viewer
( roles/
)
Security Admin
( roles/
)
Security Reviewer
( roles/
)
Binary Authorization Policy Administrator
( roles/
)
Dev Ops
( roles/
)
Security Auditor
( roles/
)
Support User
( roles/
)
binaryauthorization.
policy.
setIamPolicy
Owner
( roles/
)
Binary Authorization Admin
( roles/
)
Security Admin
( roles/
)
Binary Authorization Policy Administrator
( roles/
)
Dev Ops
( roles/
)
binaryauthorization.
policy.
update
Owner
( roles/
)
Editor
( roles/
)
Binary Authorization Admin
( roles/
)
Binary Authorization Editor
( roles/
)
Binary Authorization Policy Administrator
( roles/
)
Binary Authorization Policy Editor
( roles/
)
Dev Ops
( roles/
)

