This page lists the IAM roles and permissions for GKE Hub. To search through all roles and permissions, see the role and permission index .
GKE Hub roles
Fleet Admin (formerly GKE Hub Admin)
( roles/
)
Full access to Fleet resources.
gkehub.features.*
-
gkehub.features.create -
gkehub.features.delete -
gkehub.features.get -
gkehub.features.getIamPolicy -
gkehub.features.list -
gkehub.features.setIamPolicy -
gkehub.features.update
gkehub.fleet.*
-
gkehub.fleet.create -
gkehub.fleet.createFreeTrial -
gkehub.fleet.delete -
gkehub.fleet.get -
gkehub.fleet.getFreeTrial -
gkehub.fleet.update -
gkehub.fleet.updateFreeTrial
gkehub.locations.*
-
gkehub.locations.get -
gkehub.locations.list
gkehub.membershipbindings.*
-
gkehub.membershipbindings. create -
gkehub.membershipbindings. delete -
gkehub.membershipbindings.get -
gkehub.membershipbindings.list -
gkehub.membershipbindings. update
gkehub.membershipfeatures.*
-
gkehub.membershipfeatures. create -
gkehub.membershipfeatures. delete -
gkehub.membershipfeatures.get -
gkehub.membershipfeatures.list -
gkehub.membershipfeatures. update
gkehub.memberships.*
-
gkehub.memberships.create -
gkehub.memberships.delete -
gkehub.memberships. generateConnectManifest -
gkehub.memberships.get -
gkehub.memberships. getIamPolicy -
gkehub.memberships.list -
gkehub.memberships. setIamPolicy -
gkehub.memberships.update
gkehub.namespaces.*
-
gkehub.namespaces.create -
gkehub.namespaces.delete -
gkehub.namespaces.get -
gkehub.namespaces.list -
gkehub.namespaces.update
gkehub.operations.*
-
gkehub.operations.cancel -
gkehub.operations.delete -
gkehub.operations.get -
gkehub.operations.list
gkehub.rbacrolebindings.*
-
gkehub.rbacrolebindings.create -
gkehub.rbacrolebindings.delete -
gkehub.rbacrolebindings.get -
gkehub.rbacrolebindings.list -
gkehub.rbacrolebindings.update
gkehub.scopes.*
-
gkehub.scopes.create -
gkehub.scopes.delete -
gkehub.scopes.get -
gkehub.scopes.getIamPolicy -
gkehub.scopes.list -
gkehub.scopes. listBoundMemberships -
gkehub.scopes.setIamPolicy -
gkehub.scopes.update
resourcemanager.projects.get
resourcemanager.projects.list
GKE Connect Agent
( roles/
)
Ability to set up GKE Connect between external clusters and Google.
gkehub.endpoints.connect
GKE Hub Cross Project Service Agent
( roles/
)
Gives the GKE Hub service agent permission to manage the project for cross-project fleet registration.
resourcemanager.
resourcemanager.
Fleet Editor (formerly GKE Hub Editor)
( roles/
)
Edit access to Fleet resources.
gkehub.features.create
gkehub.features.delete
gkehub.features.get
gkehub.features.getIamPolicy
gkehub.features.list
gkehub.features.update
gkehub.fleet.*
-
gkehub.fleet.create -
gkehub.fleet.createFreeTrial -
gkehub.fleet.delete -
gkehub.fleet.get -
gkehub.fleet.getFreeTrial -
gkehub.fleet.update -
gkehub.fleet.updateFreeTrial
gkehub.locations.*
-
gkehub.locations.get -
gkehub.locations.list
gkehub.membershipbindings.*
-
gkehub.membershipbindings. create -
gkehub.membershipbindings. delete -
gkehub.membershipbindings.get -
gkehub.membershipbindings.list -
gkehub.membershipbindings. update
gkehub.membershipfeatures.*
-
gkehub.membershipfeatures. create -
gkehub.membershipfeatures. delete -
gkehub.membershipfeatures.get -
gkehub.membershipfeatures.list -
gkehub.membershipfeatures. update
gkehub.memberships.create
gkehub.memberships.delete
gkehub.
gkehub.memberships.get
gkehub.
gkehub.memberships.list
gkehub.memberships.update
gkehub.namespaces.*
-
gkehub.namespaces.create -
gkehub.namespaces.delete -
gkehub.namespaces.get -
gkehub.namespaces.list -
gkehub.namespaces.update
gkehub.operations.*
-
gkehub.operations.cancel -
gkehub.operations.delete -
gkehub.operations.get -
gkehub.operations.list
gkehub.rbacrolebindings.*
-
gkehub.rbacrolebindings.create -
gkehub.rbacrolebindings.delete -
gkehub.rbacrolebindings.get -
gkehub.rbacrolebindings.list -
gkehub.rbacrolebindings.update
gkehub.scopes.create
gkehub.scopes.delete
gkehub.scopes.get
gkehub.scopes.getIamPolicy
gkehub.scopes.list
gkehub.
gkehub.scopes.update
resourcemanager.projects.get
resourcemanager.projects.list
Connect Gateway Admin
( roles/
)
Full access to Connect Gateway.
gkehub.gateway.*
-
gkehub.gateway.delete -
gkehub.gateway. generateCredentials -
gkehub.gateway.get -
gkehub.gateway.patch -
gkehub.gateway.post -
gkehub.gateway.put -
gkehub.gateway.stream
gkehub.memberships.get
serviceusage.
serviceusage.
serviceusage.
serviceusage.groups.*
-
serviceusage.groups.list -
serviceusage.groups. listExpandedMembers -
serviceusage.groups. listMembers
serviceusage.services.get
serviceusage.values.test
Connect Gateway Editor
( roles/
)
Edit access to Connect Gateway.
gkehub.gateway.delete
gkehub.
gkehub.gateway.get
gkehub.gateway.patch
gkehub.gateway.post
gkehub.gateway.put
gkehub.memberships.get
serviceusage.
serviceusage.
serviceusage.
serviceusage.groups.*
-
serviceusage.groups.list -
serviceusage.groups. listExpandedMembers -
serviceusage.groups. listMembers
serviceusage.services.get
serviceusage.values.test
Connect Gateway Reader
( roles/
)
Read-only access to Connect Gateway.
gkehub.
gkehub.gateway.get
gkehub.memberships.get
serviceusage.
serviceusage.
serviceusage.
serviceusage.groups.*
-
serviceusage.groups.list -
serviceusage.groups. listExpandedMembers -
serviceusage.groups. listMembers
serviceusage.services.get
serviceusage.values.test
Fleet Scope Admin
( roles/
)
Admin access to Fleet Scopes to set IAM Bindings and RBACRoleBindings.
gkehub.namespaces.create
gkehub.namespaces.delete
gkehub.namespaces.get
gkehub.namespaces.list
gkehub.rbacrolebindings.*
-
gkehub.rbacrolebindings.create -
gkehub.rbacrolebindings.delete -
gkehub.rbacrolebindings.get -
gkehub.rbacrolebindings.list -
gkehub.rbacrolebindings.update
gkehub.scopes.get
gkehub.scopes.getIamPolicy
gkehub.
gkehub.scopes.setIamPolicy
Fleet Scope Editor
( roles/
)
Edit access to Namespaces under Fleet Scopes.
gkehub.namespaces.create
gkehub.namespaces.delete
gkehub.namespaces.get
gkehub.namespaces.list
gkehub.rbacrolebindings.get
gkehub.rbacrolebindings.list
gkehub.scopes.get
gkehub.scopes.getIamPolicy
gkehub.
Fleet Project-level Scope Editor
( roles/
)
Role for project-level permissions for editor of Fleet Scopes.
gkehub.gateway.delete
gkehub.
gkehub.gateway.get
gkehub.gateway.patch
gkehub.gateway.post
gkehub.gateway.put
gkehub.memberships.get
gkehub.operations.get
monitoring.timeSeries.list
resourcemanager.projects.get
resourcemanager.projects.list
serviceusage.
serviceusage.
serviceusage.
serviceusage.groups.*
-
serviceusage.groups.list -
serviceusage.groups. listExpandedMembers -
serviceusage.groups. listMembers
serviceusage.services.get
serviceusage.values.test
Fleet Scope Viewer
( roles/
)
Viewer of Fleet Scopes and associated resources.
gkehub.namespaces.get
gkehub.namespaces.list
gkehub.rbacrolebindings.get
gkehub.rbacrolebindings.list
gkehub.scopes.get
gkehub.scopes.getIamPolicy
gkehub.
Fleet Project-level Scope Viewer
( roles/
)
Role for project-level permissions for viewer of Fleet Scopes.
gkehub.
gkehub.gateway.get
gkehub.memberships.get
monitoring.timeSeries.list
resourcemanager.projects.get
resourcemanager.projects.list
serviceusage.
serviceusage.
serviceusage.
serviceusage.groups.*
-
serviceusage.groups.list -
serviceusage.groups. listExpandedMembers -
serviceusage.groups. listMembers
serviceusage.services.get
serviceusage.values.test
GKE Hub Service Agent
( roles/
)
Gives the GKE Hub service agent access to Cloud Platform resources.
container.
-
container.clusterRoleBindings. create -
container.clusterRoleBindings. delete -
container.clusterRoleBindings. get -
container.clusterRoleBindings. list -
container.clusterRoleBindings. update
container.clusterRoles.*
-
container.clusterRoles.bind -
container.clusterRoles.create -
container.clusterRoles.delete -
container.clusterRoles. escalate -
container.clusterRoles.get -
container.clusterRoles.list -
container.clusterRoles.update
container.clusters.connect
container.clusters.get
container.clusters.list
container.clusters.update
container.
container.
container.
container.
container.
container.namespaces.get
container.operations.get
container.thirdPartyObjects.*
-
container.thirdPartyObjects. create -
container.thirdPartyObjects. delete -
container.thirdPartyObjects. get -
container.thirdPartyObjects. list -
container.thirdPartyObjects. update
gkehub.features.create
gkehub.features.get
gkehub.features.list
gkehub.fleet.create
gkehub.fleet.get
gkehub.gateway.delete
gkehub.
gkehub.gateway.get
gkehub.gateway.patch
gkehub.gateway.post
gkehub.gateway.put
gkehub.locations.*
-
gkehub.locations.get -
gkehub.locations.list
gkehub.memberships.create
gkehub.
gkehub.memberships.get
gkehub.memberships.list
gkehub.operations.get
gkemulticloud.awsClusters.get
gkemulticloud.
gkeonprem.
gkeonprem.vmwareClusters.get
logging.buckets.create
logging.buckets.get
logging.buckets.list
logging.buckets.update
logging.exclusions.*
-
logging.exclusions.create -
logging.exclusions.delete -
logging.exclusions.get -
logging.exclusions.list -
logging.exclusions.update
logging.sinks.*
-
logging.sinks.create -
logging.sinks.delete -
logging.sinks.get -
logging.sinks.list -
logging.sinks.update
logging.views.create
logging.views.get
logging.views.list
logging.views.update
monitoring.metricsScopes.link
resourcemanager.projects.get
resourcemanager.projects.list
serviceusage.
serviceusage.
serviceusage.
serviceusage.groups.*
-
serviceusage.groups.list -
serviceusage.groups. listExpandedMembers -
serviceusage.groups. listMembers
serviceusage.services.get
serviceusage.services.list
serviceusage.values.test
Fleet Viewer (formerly GKE Hub Viewer)
( roles/
)
Read-only access to Fleets and related resources.
gkehub.features.get
gkehub.features.getIamPolicy
gkehub.features.list
gkehub.fleet.get
gkehub.fleet.getFreeTrial
gkehub.locations.*
-
gkehub.locations.get -
gkehub.locations.list
gkehub.membershipbindings.get
gkehub.membershipbindings.list
gkehub.membershipfeatures.get
gkehub.membershipfeatures.list
gkehub.
gkehub.memberships.get
gkehub.
gkehub.memberships.list
gkehub.namespaces.get
gkehub.namespaces.list
gkehub.operations.get
gkehub.operations.list
gkehub.rbacrolebindings.get
gkehub.rbacrolebindings.list
gkehub.scopes.get
gkehub.scopes.list
gkehub.
resourcemanager.projects.get
resourcemanager.projects.list
GKE Hub permissions
gkehub.endpoints.connect
Owner
( roles/
)
Velostrata Manager
( roles/
)
Velostrata Manager Connection Agent
( roles/
)
GKE Connect Agent
( roles/
)
Service agent roles
- Edge Container Cluster Service Agent
(
roles/)edgecontainer.clusterServiceAgent
gkehub.features.create
Owner
( roles/
)
Editor
( roles/
)
Fleet Admin (formerly GKE Hub Admin)
( roles/
)
Fleet Editor (formerly GKE Hub Editor)
( roles/
)
Service agent roles
- GKE Hub Service Agent
(
roles/)gkehub.serviceAgent - Anthos Multi-Cloud Service Agent
(
roles/)gkemulticloud.serviceAgent - KRM API Hosting AnthosApiEndpoint Service Agent
(
roles/)krmapihosting.anthosApiEndpointServiceAgent - Edge Container Cluster Service Agent
(
roles/)edgecontainer.clusterServiceAgent
gkehub.features.delete
Owner
( roles/
)
Editor
( roles/
)
Fleet Admin (formerly GKE Hub Admin)
( roles/
)
Fleet Editor (formerly GKE Hub Editor)
( roles/
)
Service agent roles
- KRM API Hosting AnthosApiEndpoint Service Agent
(
roles/)krmapihosting.anthosApiEndpointServiceAgent - Anthos Multi-Cloud Service Agent
(
roles/)gkemulticloud.serviceAgent
gkehub.features.get
Owner
( roles/
)
Editor
( roles/
)
Viewer
( roles/
)
Fleet Admin (formerly GKE Hub Admin)
( roles/
)
Fleet Editor (formerly GKE Hub Editor)
( roles/
)
Fleet Viewer (formerly GKE Hub Viewer)
( roles/
)
Support User
( roles/
)
Service agent roles
- Anthos Service Agent
(
roles/)anthos.serviceAgent - Anthos Audit Service Agent
(
roles/)anthosaudit.serviceAgent - Anthos Config Management Service Agent
(
roles/)anthosconfigmanagement.serviceAgent - Anthos Identity Service Agent
(
roles/)anthosidentityservice.serviceAgent - Anthos Policy Controller Service Agent
(
roles/)anthospolicycontroller.serviceAgent - Anthos Service Mesh Service Agent
(
roles/)anthosservicemesh.serviceAgent - Anthos Support Service Agent
(
roles/)anthossupport.serviceAgent - App Development Experience Service Agent
(
roles/)appdevelopmentexperience.serviceAgent - Edge Container Cluster Service Agent
(
roles/)edgecontainer.clusterServiceAgent - Game Services Service Agent
(
roles/)gameservices.serviceAgent - GKE Hub Service Agent
(
roles/)gkehub.serviceAgent - Anthos Multi-Cloud Service Agent
(
roles/)gkemulticloud.serviceAgent - KRM API Hosting AnthosApiEndpoint Service Agent
(
roles/)krmapihosting.anthosApiEndpointServiceAgent - Mesh Managed Control Plane Service Agent
(
roles/)meshcontrolplane.serviceAgent - Multi Cluster Ingress Service Agent
(
roles/)multiclusteringress.serviceAgent - Multi-cluster metering Service Agent
(
roles/)multiclustermetering.serviceAgent - Multi-Cluster Service Discovery Service Agent
(
roles/)multiclusterservicediscovery.serviceAgent - Service Directory Service Agent
(
roles/)servicedirectory.serviceAgent - Workload Certificate Service Agent
(
roles/)workloadcertificate.serviceAgent - Vertex AI Online Prediction Service Agent
(
roles/)aiplatform.onlinePredictionServiceAgent
gkehub.features.getIamPolicy
Owner
( roles/
)
Editor
( roles/
)
Viewer
( roles/
)
Fleet Admin (formerly GKE Hub Admin)
( roles/
)
Fleet Editor (formerly GKE Hub Editor)
( roles/
)
Fleet Viewer (formerly GKE Hub Viewer)
( roles/
)
Security Admin
( roles/
)
Security Auditor
( roles/
)
Security Reviewer
( roles/
)
Support User
( roles/
)
Service agent roles
- Anthos Support Service Agent
(
roles/)anthossupport.serviceAgent - Game Services Service Agent
(
roles/)gameservices.serviceAgent - Anthos Multi-Cloud Service Agent
(
roles/)gkemulticloud.serviceAgent - KRM API Hosting AnthosApiEndpoint Service Agent
(
roles/)krmapihosting.anthosApiEndpointServiceAgent - Mesh Managed Control Plane Service Agent
(
roles/)meshcontrolplane.serviceAgent - Vertex AI Online Prediction Service Agent
(
roles/)aiplatform.onlinePredictionServiceAgent
gkehub.features.list
Owner
( roles/
)
Editor
( roles/
)
Viewer
( roles/
)
Fleet Admin (formerly GKE Hub Admin)
( roles/
)
Fleet Editor (formerly GKE Hub Editor)
( roles/
)
Fleet Viewer (formerly GKE Hub Viewer)
( roles/
)
Security Admin
( roles/
)
Security Auditor
( roles/
)
Security Reviewer
( roles/
)
Support User
( roles/
)
Service agent roles
- Anthos Support Service Agent
(
roles/)anthossupport.serviceAgent - Edge Container Cluster Service Agent
(
roles/)edgecontainer.clusterServiceAgent - Game Services Service Agent
(
roles/)gameservices.serviceAgent - GKE Hub Service Agent
(
roles/)gkehub.serviceAgent - Anthos Multi-Cloud Service Agent
(
roles/)gkemulticloud.serviceAgent - KRM API Hosting AnthosApiEndpoint Service Agent
(
roles/)krmapihosting.anthosApiEndpointServiceAgent - Mesh Managed Control Plane Service Agent
(
roles/)meshcontrolplane.serviceAgent - Vertex AI Online Prediction Service Agent
(
roles/)aiplatform.onlinePredictionServiceAgent
gkehub.features.setIamPolicy
Owner
( roles/
)
Fleet Admin (formerly GKE Hub Admin)
( roles/
)
Security Admin
( roles/
)
Service agent roles
- KRM API Hosting AnthosApiEndpoint Service Agent
(
roles/)krmapihosting.anthosApiEndpointServiceAgent - Anthos Multi-Cloud Service Agent
(
roles/)gkemulticloud.serviceAgent
gkehub.features.update
Owner
( roles/
)
Editor
( roles/
)
Fleet Admin (formerly GKE Hub Admin)
( roles/
)
Fleet Editor (formerly GKE Hub Editor)
( roles/
)
Service agent roles
- Anthos Multi-Cloud Service Agent
(
roles/)gkemulticloud.serviceAgent - KRM API Hosting AnthosApiEndpoint Service Agent
(
roles/)krmapihosting.anthosApiEndpointServiceAgent - Edge Container Cluster Service Agent
(
roles/)edgecontainer.clusterServiceAgent
gkehub.fleet.create
Owner
( roles/
)
Editor
( roles/
)
Fleet Admin (formerly GKE Hub Admin)
( roles/
)
Fleet Editor (formerly GKE Hub Editor)
( roles/
)
Service agent roles
- GKE Hub Service Agent
(
roles/)gkehub.serviceAgent - Anthos Multi-Cloud Service Agent
(
roles/)gkemulticloud.serviceAgent - KRM API Hosting AnthosApiEndpoint Service Agent
(
roles/)krmapihosting.anthosApiEndpointServiceAgent - Workload Certificate Service Agent
(
roles/)workloadcertificate.serviceAgent - Edge Container Cluster Service Agent
(
roles/)edgecontainer.clusterServiceAgent
gkehub.fleet.createFreeTrial
Owner
( roles/
)
Editor
( roles/
)
Fleet Admin (formerly GKE Hub Admin)
( roles/
)
Fleet Editor (formerly GKE Hub Editor)
( roles/
)
Service agent roles
- KRM API Hosting AnthosApiEndpoint Service Agent
(
roles/)krmapihosting.anthosApiEndpointServiceAgent - Anthos Multi-Cloud Service Agent
(
roles/)gkemulticloud.serviceAgent
gkehub.fleet.delete
Owner
( roles/
)
Editor
( roles/
)
Fleet Admin (formerly GKE Hub Admin)
( roles/
)
Fleet Editor (formerly GKE Hub Editor)
( roles/
)
Service agent roles
- Anthos Multi-Cloud Service Agent
(
roles/)gkemulticloud.serviceAgent - KRM API Hosting AnthosApiEndpoint Service Agent
(
roles/)krmapihosting.anthosApiEndpointServiceAgent - Edge Container Cluster Service Agent
(
roles/)edgecontainer.clusterServiceAgent
gkehub.fleet.get
Owner
( roles/
)
Editor
( roles/
)
Viewer
( roles/
)
Fleet Admin (formerly GKE Hub Admin)
( roles/
)
Fleet Editor (formerly GKE Hub Editor)
( roles/
)
Fleet Viewer (formerly GKE Hub Viewer)
( roles/
)
Support User
( roles/
)
Service agent roles
- Anthos Support Service Agent
(
roles/)anthossupport.serviceAgent - Edge Container Cluster Service Agent
(
roles/)edgecontainer.clusterServiceAgent - Game Services Service Agent
(
roles/)gameservices.serviceAgent - GKE Hub Service Agent
(
roles/)gkehub.serviceAgent - Anthos Multi-Cloud Service Agent
(
roles/)gkemulticloud.serviceAgent - KRM API Hosting AnthosApiEndpoint Service Agent
(
roles/)krmapihosting.anthosApiEndpointServiceAgent - Mesh Managed Control Plane Service Agent
(
roles/)meshcontrolplane.serviceAgent - Workload Certificate Service Agent
(
roles/)workloadcertificate.serviceAgent - Vertex AI Online Prediction Service Agent
(
roles/)aiplatform.onlinePredictionServiceAgent
gkehub.fleet.getFreeTrial
Owner
( roles/
)
Editor
( roles/
)
Viewer
( roles/
)
Fleet Admin (formerly GKE Hub Admin)
( roles/
)
Fleet Editor (formerly GKE Hub Editor)
( roles/
)
Fleet Viewer (formerly GKE Hub Viewer)
( roles/
)
Support User
( roles/
)
Service agent roles
- Game Services Service Agent
(
roles/)gameservices.serviceAgent - Anthos Multi-Cloud Service Agent
(
roles/)gkemulticloud.serviceAgent - KRM API Hosting AnthosApiEndpoint Service Agent
(
roles/)krmapihosting.anthosApiEndpointServiceAgent - Mesh Managed Control Plane Service Agent
(
roles/)meshcontrolplane.serviceAgent - Anthos Support Service Agent
(
roles/)anthossupport.serviceAgent
gkehub.fleet.update
Owner
( roles/
)
Editor
( roles/
)
Fleet Admin (formerly GKE Hub Admin)
( roles/
)
Fleet Editor (formerly GKE Hub Editor)
( roles/
)
Service agent roles
- KRM API Hosting AnthosApiEndpoint Service Agent
(
roles/)krmapihosting.anthosApiEndpointServiceAgent - Anthos Multi-Cloud Service Agent
(
roles/)gkemulticloud.serviceAgent
gkehub.fleet.updateFreeTrial
Owner
( roles/
)
Editor
( roles/
)
Fleet Admin (formerly GKE Hub Admin)
( roles/
)
Fleet Editor (formerly GKE Hub Editor)
( roles/
)
Service agent roles
- KRM API Hosting AnthosApiEndpoint Service Agent
(
roles/)krmapihosting.anthosApiEndpointServiceAgent - Anthos Multi-Cloud Service Agent
(
roles/)gkemulticloud.serviceAgent
gkehub.gateway.delete
Owner
( roles/
)
Editor
( roles/
)
Connect Gateway Admin
( roles/
)
Connect Gateway Editor
( roles/
)
Fleet Project-level Scope Editor
( roles/
)
Service agent roles
- Anthos Config Management Service Agent
(
roles/)anthosconfigmanagement.serviceAgent - Anthos Identity Service Agent
(
roles/)anthosidentityservice.serviceAgent - Anthos Policy Controller Service Agent
(
roles/)anthospolicycontroller.serviceAgent - Anthos Service Mesh Service Agent
(
roles/)anthosservicemesh.serviceAgent - App Development Experience Service Agent
(
roles/)appdevelopmentexperience.serviceAgent - Config Delivery Service Agent
(
roles/)configdelivery.serviceAgent - GKE Hub Service Agent
(
roles/)gkehub.serviceAgent - KRM API Hosting AnthosApiEndpoint Service Agent
(
roles/)krmapihosting.anthosApiEndpointServiceAgent - Mesh Managed Control Plane Service Agent
(
roles/)meshcontrolplane.serviceAgent - Multi Cluster Ingress Service Agent
(
roles/)multiclusteringress.serviceAgent - Multi-cluster metering Service Agent
(
roles/)multiclustermetering.serviceAgent - Multi-Cluster Service Discovery Service Agent
(
roles/)multiclusterservicediscovery.serviceAgent - Service Directory Service Agent
(
roles/)servicedirectory.serviceAgent - Vertex AI Online Prediction Service Agent
(
roles/)aiplatform.onlinePredictionServiceAgent
gkehub.
gateway.
generateCredentials
Owner
( roles/
)
Editor
( roles/
)
Viewer
( roles/
)
Connect Gateway Admin
( roles/
)
Connect Gateway Editor
( roles/
)
Connect Gateway Reader
( roles/
)
Fleet Project-level Scope Editor
( roles/
)
Fleet Project-level Scope Viewer
( roles/
)
Support User
( roles/
)
Service agent roles
- Anthos Config Management Service Agent
(
roles/)anthosconfigmanagement.serviceAgent - Anthos Identity Service Agent
(
roles/)anthosidentityservice.serviceAgent - Anthos Policy Controller Service Agent
(
roles/)anthospolicycontroller.serviceAgent - Anthos Service Mesh Service Agent
(
roles/)anthosservicemesh.serviceAgent - Anthos Support Service Agent
(
roles/)anthossupport.serviceAgent - App Development Experience Service Agent
(
roles/)appdevelopmentexperience.serviceAgent - Config Delivery Service Agent
(
roles/)configdelivery.serviceAgent - GKE Hub Service Agent
(
roles/)gkehub.serviceAgent - KRM API Hosting AnthosApiEndpoint Service Agent
(
roles/)krmapihosting.anthosApiEndpointServiceAgent - Mesh Managed Control Plane Service Agent
(
roles/)meshcontrolplane.serviceAgent - Multi Cluster Ingress Service Agent
(
roles/)multiclusteringress.serviceAgent - Multi-cluster metering Service Agent
(
roles/)multiclustermetering.serviceAgent - Multi-Cluster Service Discovery Service Agent
(
roles/)multiclusterservicediscovery.serviceAgent - Service Directory Service Agent
(
roles/)servicedirectory.serviceAgent - Vertex AI Online Prediction Service Agent
(
roles/)aiplatform.onlinePredictionServiceAgent
gkehub.gateway.get
Owner
( roles/
)
Editor
( roles/
)
Viewer
( roles/
)
Connect Gateway Admin
( roles/
)
Connect Gateway Editor
( roles/
)
Connect Gateway Reader
( roles/
)
Fleet Project-level Scope Editor
( roles/
)
Fleet Project-level Scope Viewer
( roles/
)
Support User
( roles/
)
Service agent roles
- Anthos Config Management Service Agent
(
roles/)anthosconfigmanagement.serviceAgent - Anthos Identity Service Agent
(
roles/)anthosidentityservice.serviceAgent - Anthos Policy Controller Service Agent
(
roles/)anthospolicycontroller.serviceAgent - Anthos Service Mesh Service Agent
(
roles/)anthosservicemesh.serviceAgent - Anthos Support Service Agent
(
roles/)anthossupport.serviceAgent - App Development Experience Service Agent
(
roles/)appdevelopmentexperience.serviceAgent - Config Delivery Service Agent
(
roles/)configdelivery.serviceAgent - GKE Hub Service Agent
(
roles/)gkehub.serviceAgent - KRM API Hosting AnthosApiEndpoint Service Agent
(
roles/)krmapihosting.anthosApiEndpointServiceAgent - Mesh Managed Control Plane Service Agent
(
roles/)meshcontrolplane.serviceAgent - Multi Cluster Ingress Service Agent
(
roles/)multiclusteringress.serviceAgent - Multi-cluster metering Service Agent
(
roles/)multiclustermetering.serviceAgent - Multi-Cluster Service Discovery Service Agent
(
roles/)multiclusterservicediscovery.serviceAgent - Service Directory Service Agent
(
roles/)servicedirectory.serviceAgent - Vertex AI Online Prediction Service Agent
(
roles/)aiplatform.onlinePredictionServiceAgent
gkehub.gateway.patch
Owner
( roles/
)
Editor
( roles/
)
Connect Gateway Admin
( roles/
)
Connect Gateway Editor
( roles/
)
Fleet Project-level Scope Editor
( roles/
)
Service agent roles
- Anthos Config Management Service Agent
(
roles/)anthosconfigmanagement.serviceAgent - Anthos Identity Service Agent
(
roles/)anthosidentityservice.serviceAgent - Anthos Policy Controller Service Agent
(
roles/)anthospolicycontroller.serviceAgent - Anthos Service Mesh Service Agent
(
roles/)anthosservicemesh.serviceAgent - App Development Experience Service Agent
(
roles/)appdevelopmentexperience.serviceAgent - Config Delivery Service Agent
(
roles/)configdelivery.serviceAgent - GKE Hub Service Agent
(
roles/)gkehub.serviceAgent - KRM API Hosting AnthosApiEndpoint Service Agent
(
roles/)krmapihosting.anthosApiEndpointServiceAgent - Mesh Managed Control Plane Service Agent
(
roles/)meshcontrolplane.serviceAgent - Multi Cluster Ingress Service Agent
(
roles/)multiclusteringress.serviceAgent - Multi-cluster metering Service Agent
(
roles/)multiclustermetering.serviceAgent - Multi-Cluster Service Discovery Service Agent
(
roles/)multiclusterservicediscovery.serviceAgent - Service Directory Service Agent
(
roles/)servicedirectory.serviceAgent - Vertex AI Online Prediction Service Agent
(
roles/)aiplatform.onlinePredictionServiceAgent
gkehub.gateway.post
Owner
( roles/
)
Editor
( roles/
)
Connect Gateway Admin
( roles/
)
Connect Gateway Editor
( roles/
)
Fleet Project-level Scope Editor
( roles/
)
Service agent roles
- Anthos Config Management Service Agent
(
roles/)anthosconfigmanagement.serviceAgent - Anthos Identity Service Agent
(
roles/)anthosidentityservice.serviceAgent - Anthos Policy Controller Service Agent
(
roles/)anthospolicycontroller.serviceAgent - Anthos Service Mesh Service Agent
(
roles/)anthosservicemesh.serviceAgent - App Development Experience Service Agent
(
roles/)appdevelopmentexperience.serviceAgent - Config Delivery Service Agent
(
roles/)configdelivery.serviceAgent - GKE Hub Service Agent
(
roles/)gkehub.serviceAgent - KRM API Hosting AnthosApiEndpoint Service Agent
(
roles/)krmapihosting.anthosApiEndpointServiceAgent - Mesh Managed Control Plane Service Agent
(
roles/)meshcontrolplane.serviceAgent - Multi Cluster Ingress Service Agent
(
roles/)multiclusteringress.serviceAgent - Multi-cluster metering Service Agent
(
roles/)multiclustermetering.serviceAgent - Multi-Cluster Service Discovery Service Agent
(
roles/)multiclusterservicediscovery.serviceAgent - Service Directory Service Agent
(
roles/)servicedirectory.serviceAgent - Vertex AI Online Prediction Service Agent
(
roles/)aiplatform.onlinePredictionServiceAgent
gkehub.gateway.put
Owner
( roles/
)
Editor
( roles/
)
Connect Gateway Admin
( roles/
)
Connect Gateway Editor
( roles/
)
Fleet Project-level Scope Editor
( roles/
)
Service agent roles
- Anthos Config Management Service Agent
(
roles/)anthosconfigmanagement.serviceAgent - Anthos Identity Service Agent
(
roles/)anthosidentityservice.serviceAgent - Anthos Policy Controller Service Agent
(
roles/)anthospolicycontroller.serviceAgent - Anthos Service Mesh Service Agent
(
roles/)anthosservicemesh.serviceAgent - App Development Experience Service Agent
(
roles/)appdevelopmentexperience.serviceAgent - Config Delivery Service Agent
(
roles/)configdelivery.serviceAgent - GKE Hub Service Agent
(
roles/)gkehub.serviceAgent - KRM API Hosting AnthosApiEndpoint Service Agent
(
roles/)krmapihosting.anthosApiEndpointServiceAgent - Mesh Managed Control Plane Service Agent
(
roles/)meshcontrolplane.serviceAgent - Multi Cluster Ingress Service Agent
(
roles/)multiclusteringress.serviceAgent - Multi-cluster metering Service Agent
(
roles/)multiclustermetering.serviceAgent - Multi-Cluster Service Discovery Service Agent
(
roles/)multiclusterservicediscovery.serviceAgent - Service Directory Service Agent
(
roles/)servicedirectory.serviceAgent - Vertex AI Online Prediction Service Agent
(
roles/)aiplatform.onlinePredictionServiceAgent
gkehub.gateway.stream
Owner
( roles/
)
Editor
( roles/
)
Connect Gateway Admin
( roles/
)
Service agent roles
- Mesh Managed Control Plane Service Agent
(
roles/)meshcontrolplane.serviceAgent - KRM API Hosting AnthosApiEndpoint Service Agent
(
roles/)krmapihosting.anthosApiEndpointServiceAgent
gkehub.locations.get
Owner
( roles/
)
Editor
( roles/
)
Viewer
( roles/
)
Fleet Admin (formerly GKE Hub Admin)
( roles/
)
Fleet Editor (formerly GKE Hub Editor)
( roles/
)
Fleet Viewer (formerly GKE Hub Viewer)
( roles/
)
Support User
( roles/
)
Service agent roles
- Anthos Service Agent
(
roles/)anthos.serviceAgent - Anthos Audit Service Agent
(
roles/)anthosaudit.serviceAgent - Anthos Config Management Service Agent
(
roles/)anthosconfigmanagement.serviceAgent - Anthos Identity Service Agent
(
roles/)anthosidentityservice.serviceAgent - Anthos Policy Controller Service Agent
(
roles/)anthospolicycontroller.serviceAgent - Anthos Service Mesh Service Agent
(
roles/)anthosservicemesh.serviceAgent - Anthos Support Service Agent
(
roles/)anthossupport.serviceAgent - App Development Experience Service Agent
(
roles/)appdevelopmentexperience.serviceAgent - Edge Container Cluster Service Agent
(
roles/)edgecontainer.clusterServiceAgent - Game Services Service Agent
(
roles/)gameservices.serviceAgent - GKE Hub Service Agent
(
roles/)gkehub.serviceAgent - Anthos Multi-Cloud Service Agent
(
roles/)gkemulticloud.serviceAgent - KRM API Hosting AnthosApiEndpoint Service Agent
(
roles/)krmapihosting.anthosApiEndpointServiceAgent - Mesh Managed Control Plane Service Agent
(
roles/)meshcontrolplane.serviceAgent - Multi Cluster Ingress Service Agent
(
roles/)multiclusteringress.serviceAgent - Multi-cluster metering Service Agent
(
roles/)multiclustermetering.serviceAgent - Multi-Cluster Service Discovery Service Agent
(
roles/)multiclusterservicediscovery.serviceAgent - Service Directory Service Agent
(
roles/)servicedirectory.serviceAgent - Workload Certificate Service Agent
(
roles/)workloadcertificate.serviceAgent - Vertex AI Online Prediction Service Agent
(
roles/)aiplatform.onlinePredictionServiceAgent
gkehub.locations.list
Owner
( roles/
)
Editor
( roles/
)
Viewer
( roles/
)
Fleet Admin (formerly GKE Hub Admin)
( roles/
)
Fleet Editor (formerly GKE Hub Editor)
( roles/
)
Fleet Viewer (formerly GKE Hub Viewer)
( roles/
)
Security Admin
( roles/
)
Security Auditor
( roles/
)
Security Reviewer
( roles/
)
Support User
( roles/
)
Service agent roles
- Anthos Service Agent
(
roles/)anthos.serviceAgent - Anthos Audit Service Agent
(
roles/)anthosaudit.serviceAgent - Anthos Config Management Service Agent
(
roles/)anthosconfigmanagement.serviceAgent - Anthos Identity Service Agent
(
roles/)anthosidentityservice.serviceAgent - Anthos Policy Controller Service Agent
(
roles/)anthospolicycontroller.serviceAgent - Anthos Service Mesh Service Agent
(
roles/)anthosservicemesh.serviceAgent - Anthos Support Service Agent
(
roles/)anthossupport.serviceAgent - App Development Experience Service Agent
(
roles/)appdevelopmentexperience.serviceAgent - Edge Container Cluster Service Agent
(
roles/)edgecontainer.clusterServiceAgent - Game Services Service Agent
(
roles/)gameservices.serviceAgent - GKE Hub Service Agent
(
roles/)gkehub.serviceAgent - Anthos Multi-Cloud Service Agent
(
roles/)gkemulticloud.serviceAgent - KRM API Hosting AnthosApiEndpoint Service Agent
(
roles/)krmapihosting.anthosApiEndpointServiceAgent - Mesh Managed Control Plane Service Agent
(
roles/)meshcontrolplane.serviceAgent - Multi Cluster Ingress Service Agent
(
roles/)multiclusteringress.serviceAgent - Multi-cluster metering Service Agent
(
roles/)multiclustermetering.serviceAgent - Multi-Cluster Service Discovery Service Agent
(
roles/)multiclusterservicediscovery.serviceAgent - Service Directory Service Agent
(
roles/)servicedirectory.serviceAgent - Workload Certificate Service Agent
(
roles/)workloadcertificate.serviceAgent - Vertex AI Online Prediction Service Agent
(
roles/)aiplatform.onlinePredictionServiceAgent
gkehub.
membershipbindings.
create
Owner
( roles/
)
Editor
( roles/
)
Fleet Admin (formerly GKE Hub Admin)
( roles/
)
Fleet Editor (formerly GKE Hub Editor)
( roles/
)
Service agent roles
- KRM API Hosting AnthosApiEndpoint Service Agent
(
roles/)krmapihosting.anthosApiEndpointServiceAgent - Anthos Multi-Cloud Service Agent
(
roles/)gkemulticloud.serviceAgent
gkehub.
membershipbindings.
delete
Owner
( roles/
)
Editor
( roles/
)
Fleet Admin (formerly GKE Hub Admin)
( roles/
)
Fleet Editor (formerly GKE Hub Editor)
( roles/
)
Service agent roles
- KRM API Hosting AnthosApiEndpoint Service Agent
(
roles/)krmapihosting.anthosApiEndpointServiceAgent - Anthos Multi-Cloud Service Agent
(
roles/)gkemulticloud.serviceAgent
gkehub.membershipbindings.get
Owner
( roles/
)
Editor
( roles/
)
Viewer
( roles/
)
Fleet Admin (formerly GKE Hub Admin)
( roles/
)
Fleet Editor (formerly GKE Hub Editor)
( roles/
)
Fleet Viewer (formerly GKE Hub Viewer)
( roles/
)
Support User
( roles/
)
Service agent roles
- Game Services Service Agent
(
roles/)gameservices.serviceAgent - Anthos Multi-Cloud Service Agent
(
roles/)gkemulticloud.serviceAgent - KRM API Hosting AnthosApiEndpoint Service Agent
(
roles/)krmapihosting.anthosApiEndpointServiceAgent - Mesh Managed Control Plane Service Agent
(
roles/)meshcontrolplane.serviceAgent - Anthos Support Service Agent
(
roles/)anthossupport.serviceAgent
gkehub.membershipbindings.list
Owner
( roles/
)
Editor
( roles/
)
Viewer
( roles/
)
Fleet Admin (formerly GKE Hub Admin)
( roles/
)
Fleet Editor (formerly GKE Hub Editor)
( roles/
)
Fleet Viewer (formerly GKE Hub Viewer)
( roles/
)
Security Admin
( roles/
)
Security Auditor
( roles/
)
Security Reviewer
( roles/
)
Support User
( roles/
)
Service agent roles
- Game Services Service Agent
(
roles/)gameservices.serviceAgent - Anthos Multi-Cloud Service Agent
(
roles/)gkemulticloud.serviceAgent - KRM API Hosting AnthosApiEndpoint Service Agent
(
roles/)krmapihosting.anthosApiEndpointServiceAgent - Mesh Managed Control Plane Service Agent
(
roles/)meshcontrolplane.serviceAgent - Anthos Support Service Agent
(
roles/)anthossupport.serviceAgent
gkehub.
membershipbindings.
update
Owner
( roles/
)
Editor
( roles/
)
Fleet Admin (formerly GKE Hub Admin)
( roles/
)
Fleet Editor (formerly GKE Hub Editor)
( roles/
)
Service agent roles
- KRM API Hosting AnthosApiEndpoint Service Agent
(
roles/)krmapihosting.anthosApiEndpointServiceAgent - Anthos Multi-Cloud Service Agent
(
roles/)gkemulticloud.serviceAgent
gkehub.
membershipfeatures.
create
Owner
( roles/
)
Editor
( roles/
)
Fleet Admin (formerly GKE Hub Admin)
( roles/
)
Fleet Editor (formerly GKE Hub Editor)
( roles/
)
Service agent roles
- KRM API Hosting AnthosApiEndpoint Service Agent
(
roles/)krmapihosting.anthosApiEndpointServiceAgent - Anthos Multi-Cloud Service Agent
(
roles/)gkemulticloud.serviceAgent
gkehub.
membershipfeatures.
delete
Owner
( roles/
)
Editor
( roles/
)
Fleet Admin (formerly GKE Hub Admin)
( roles/
)
Fleet Editor (formerly GKE Hub Editor)
( roles/
)
Service agent roles
- KRM API Hosting AnthosApiEndpoint Service Agent
(
roles/)krmapihosting.anthosApiEndpointServiceAgent - Anthos Multi-Cloud Service Agent
(
roles/)gkemulticloud.serviceAgent
gkehub.membershipfeatures.get
Owner
( roles/
)
Editor
( roles/
)
Viewer
( roles/
)
Fleet Admin (formerly GKE Hub Admin)
( roles/
)
Fleet Editor (formerly GKE Hub Editor)
( roles/
)
Fleet Viewer (formerly GKE Hub Viewer)
( roles/
)
Support User
( roles/
)
Service agent roles
- Game Services Service Agent
(
roles/)gameservices.serviceAgent - Anthos Multi-Cloud Service Agent
(
roles/)gkemulticloud.serviceAgent - KRM API Hosting AnthosApiEndpoint Service Agent
(
roles/)krmapihosting.anthosApiEndpointServiceAgent - Mesh Managed Control Plane Service Agent
(
roles/)meshcontrolplane.serviceAgent - Anthos Support Service Agent
(
roles/)anthossupport.serviceAgent
gkehub.membershipfeatures.list
Owner
( roles/
)
Editor
( roles/
)
Viewer
( roles/
)
Fleet Admin (formerly GKE Hub Admin)
( roles/
)
Fleet Editor (formerly GKE Hub Editor)
( roles/
)
Fleet Viewer (formerly GKE Hub Viewer)
( roles/
)
Security Admin
( roles/
)
Security Auditor
( roles/
)
Security Reviewer
( roles/
)
Support User
( roles/
)
Service agent roles
- Game Services Service Agent
(
roles/)gameservices.serviceAgent - Anthos Multi-Cloud Service Agent
(
roles/)gkemulticloud.serviceAgent - KRM API Hosting AnthosApiEndpoint Service Agent
(
roles/)krmapihosting.anthosApiEndpointServiceAgent - Mesh Managed Control Plane Service Agent
(
roles/)meshcontrolplane.serviceAgent - Anthos Support Service Agent
(
roles/)anthossupport.serviceAgent
gkehub.
membershipfeatures.
update
Owner
( roles/
)
Editor
( roles/
)
Fleet Admin (formerly GKE Hub Admin)
( roles/
)
Fleet Editor (formerly GKE Hub Editor)
( roles/
)
Service agent roles
- KRM API Hosting AnthosApiEndpoint Service Agent
(
roles/)krmapihosting.anthosApiEndpointServiceAgent - Anthos Multi-Cloud Service Agent
(
roles/)gkemulticloud.serviceAgent
gkehub.memberships.create
Owner
( roles/
)
Editor
( roles/
)
Fleet Admin (formerly GKE Hub Admin)
( roles/
)
Fleet Editor (formerly GKE Hub Editor)
( roles/
)
Service agent roles
- Edge Container Service Agent
(
roles/)edgecontainer.serviceAgent - GKE Hub Service Agent
(
roles/)gkehub.serviceAgent - Anthos Multi-Cloud Service Agent
(
roles/)gkemulticloud.serviceAgent - KRM API Hosting AnthosApiEndpoint Service Agent
(
roles/)krmapihosting.anthosApiEndpointServiceAgent - Edge Container Cluster Service Agent
(
roles/)edgecontainer.clusterServiceAgent
gkehub.memberships.delete
Owner
( roles/
)
Editor
( roles/
)
Fleet Admin (formerly GKE Hub Admin)
( roles/
)
Fleet Editor (formerly GKE Hub Editor)
( roles/
)
Service agent roles
- Edge Container Service Agent
(
roles/)edgecontainer.serviceAgent - Anthos Multi-Cloud Service Agent
(
roles/)gkemulticloud.serviceAgent - GKE On-Prem Service Agent
(
roles/)gkeonprem.serviceAgent - KRM API Hosting AnthosApiEndpoint Service Agent
(
roles/)krmapihosting.anthosApiEndpointServiceAgent - Edge Container Cluster Service Agent
(
roles/)edgecontainer.clusterServiceAgent
gkehub.
memberships.
generateConnectManifest
Owner
( roles/
)
Editor
( roles/
)
Viewer
( roles/
)
Fleet Admin (formerly GKE Hub Admin)
( roles/
)
Fleet Editor (formerly GKE Hub Editor)
( roles/
)
Fleet Viewer (formerly GKE Hub Viewer)
( roles/
)
Support User
( roles/
)
Service agent roles
- Edge Container Cluster Service Agent
(
roles/)edgecontainer.clusterServiceAgent - Edge Container Service Agent
(
roles/)edgecontainer.serviceAgent - Game Services Service Agent
(
roles/)gameservices.serviceAgent - GKE Hub Service Agent
(
roles/)gkehub.serviceAgent - Anthos Multi-Cloud Service Agent
(
roles/)gkemulticloud.serviceAgent - KRM API Hosting AnthosApiEndpoint Service Agent
(
roles/)krmapihosting.anthosApiEndpointServiceAgent - Mesh Managed Control Plane Service Agent
(
roles/)meshcontrolplane.serviceAgent - Anthos Support Service Agent
(
roles/)anthossupport.serviceAgent
gkehub.memberships.get
Owner
( roles/
)
Editor
( roles/
)
Viewer
( roles/
)
Fleet Admin (formerly GKE Hub Admin)
( roles/
)
Fleet Editor (formerly GKE Hub Editor)
( roles/
)
Connect Gateway Admin
( roles/
)
Connect Gateway Editor
( roles/
)
Connect Gateway Reader
( roles/
)
Fleet Project-level Scope Editor
( roles/
)
Fleet Project-level Scope Viewer
( roles/
)
Fleet Viewer (formerly GKE Hub Viewer)
( roles/
)
Support User
( roles/
)
Service agent roles
- Anthos Service Agent
(
roles/)anthos.serviceAgent - Anthos Audit Service Agent
(
roles/)anthosaudit.serviceAgent - Anthos Config Management Service Agent
(
roles/)anthosconfigmanagement.serviceAgent - Anthos Identity Service Agent
(
roles/)anthosidentityservice.serviceAgent - Anthos Policy Controller Service Agent
(
roles/)anthospolicycontroller.serviceAgent - Anthos Service Mesh Service Agent
(
roles/)anthosservicemesh.serviceAgent - Anthos Support Service Agent
(
roles/)anthossupport.serviceAgent - App Development Experience Service Agent
(
roles/)appdevelopmentexperience.serviceAgent - Config Delivery Service Agent
(
roles/)configdelivery.serviceAgent - Edge Container Cluster Service Agent
(
roles/)edgecontainer.clusterServiceAgent - Edge Container Service Agent
(
roles/)edgecontainer.serviceAgent - Game Services Service Agent
(
roles/)gameservices.serviceAgent - GKE Hub Service Agent
(
roles/)gkehub.serviceAgent - Anthos Multi-Cloud Service Agent
(
roles/)gkemulticloud.serviceAgent - GKE On-Prem Service Agent
(
roles/)gkeonprem.serviceAgent - KRM API Hosting AnthosApiEndpoint Service Agent
(
roles/)krmapihosting.anthosApiEndpointServiceAgent - Mesh Managed Control Plane Service Agent
(
roles/)meshcontrolplane.serviceAgent - Multi Cluster Ingress Service Agent
(
roles/)multiclusteringress.serviceAgent - Multi-cluster metering Service Agent
(
roles/)multiclustermetering.serviceAgent - Multi-Cluster Service Discovery Service Agent
(
roles/)multiclusterservicediscovery.serviceAgent - Service Directory Service Agent
(
roles/)servicedirectory.serviceAgent - Workload Certificate Service Agent
(
roles/)workloadcertificate.serviceAgent - Vertex AI Online Prediction Service Agent
(
roles/)aiplatform.onlinePredictionServiceAgent
gkehub.
memberships.
getIamPolicy
Owner
( roles/
)
Editor
( roles/
)
Viewer
( roles/
)
Fleet Admin (formerly GKE Hub Admin)
( roles/
)
Fleet Editor (formerly GKE Hub Editor)
( roles/
)
Fleet Viewer (formerly GKE Hub Viewer)
( roles/
)
Security Admin
( roles/
)
Security Auditor
( roles/
)
Security Reviewer
( roles/
)
Support User
( roles/
)
Service agent roles
- Anthos Support Service Agent
(
roles/)anthossupport.serviceAgent - Game Services Service Agent
(
roles/)gameservices.serviceAgent - Anthos Multi-Cloud Service Agent
(
roles/)gkemulticloud.serviceAgent - KRM API Hosting AnthosApiEndpoint Service Agent
(
roles/)krmapihosting.anthosApiEndpointServiceAgent - Mesh Managed Control Plane Service Agent
(
roles/)meshcontrolplane.serviceAgent - Vertex AI Online Prediction Service Agent
(
roles/)aiplatform.onlinePredictionServiceAgent
gkehub.memberships.list
Owner
( roles/
)
Editor
( roles/
)
Viewer
( roles/
)
Fleet Admin (formerly GKE Hub Admin)
( roles/
)
Fleet Editor (formerly GKE Hub Editor)
( roles/
)
Fleet Viewer (formerly GKE Hub Viewer)
( roles/
)
Security Admin
( roles/
)
Security Auditor
( roles/
)
Security Reviewer
( roles/
)
Support User
( roles/
)
Service agent roles
- Anthos Service Agent
(
roles/)anthos.serviceAgent - Anthos Audit Service Agent
(
roles/)anthosaudit.serviceAgent - Anthos Config Management Service Agent
(
roles/)anthosconfigmanagement.serviceAgent - Anthos Identity Service Agent
(
roles/)anthosidentityservice.serviceAgent - Anthos Policy Controller Service Agent
(
roles/)anthospolicycontroller.serviceAgent - Anthos Service Mesh Service Agent
(
roles/)anthosservicemesh.serviceAgent - Anthos Support Service Agent
(
roles/)anthossupport.serviceAgent - App Development Experience Service Agent
(
roles/)appdevelopmentexperience.serviceAgent - Edge Container Cluster Service Agent
(
roles/)edgecontainer.clusterServiceAgent - Edge Container Service Agent
(
roles/)edgecontainer.serviceAgent - Game Services Service Agent
(
roles/)gameservices.serviceAgent - GKE Hub Service Agent
(
roles/)gkehub.serviceAgent - Anthos Multi-Cloud Service Agent
(
roles/)gkemulticloud.serviceAgent - KRM API Hosting AnthosApiEndpoint Service Agent
(
roles/)krmapihosting.anthosApiEndpointServiceAgent - Mesh Managed Control Plane Service Agent
(
roles/)meshcontrolplane.serviceAgent - Multi Cluster Ingress Service Agent
(
roles/)multiclusteringress.serviceAgent - Multi-cluster metering Service Agent
(
roles/)multiclustermetering.serviceAgent - Multi-Cluster Service Discovery Service Agent
(
roles/)multiclusterservicediscovery.serviceAgent - Service Directory Service Agent
(
roles/)servicedirectory.serviceAgent - Workload Certificate Service Agent
(
roles/)workloadcertificate.serviceAgent - Vertex AI Online Prediction Service Agent
(
roles/)aiplatform.onlinePredictionServiceAgent
gkehub.
memberships.
setIamPolicy
Owner
( roles/
)
Fleet Admin (formerly GKE Hub Admin)
( roles/
)
Security Admin
( roles/
)
Service agent roles
- KRM API Hosting AnthosApiEndpoint Service Agent
(
roles/)krmapihosting.anthosApiEndpointServiceAgent - Anthos Multi-Cloud Service Agent
(
roles/)gkemulticloud.serviceAgent
gkehub.memberships.update
Owner
( roles/
)
Editor
( roles/
)
Fleet Admin (formerly GKE Hub Admin)
( roles/
)
Fleet Editor (formerly GKE Hub Editor)
( roles/
)
Service agent roles
- Edge Container Service Agent
(
roles/)edgecontainer.serviceAgent - Anthos Multi-Cloud Service Agent
(
roles/)gkemulticloud.serviceAgent - GKE On-Prem Service Agent
(
roles/)gkeonprem.serviceAgent - KRM API Hosting AnthosApiEndpoint Service Agent
(
roles/)krmapihosting.anthosApiEndpointServiceAgent - Edge Container Cluster Service Agent
(
roles/)edgecontainer.clusterServiceAgent
gkehub.namespaces.create
Owner
( roles/
)
Editor
( roles/
)
Fleet Admin (formerly GKE Hub Admin)
( roles/
)
Fleet Editor (formerly GKE Hub Editor)
( roles/
)
Fleet Scope Admin
( roles/
)
Fleet Scope Editor
( roles/
)
Service agent roles
- KRM API Hosting AnthosApiEndpoint Service Agent
(
roles/)krmapihosting.anthosApiEndpointServiceAgent - Anthos Multi-Cloud Service Agent
(
roles/)gkemulticloud.serviceAgent
gkehub.namespaces.delete
Owner
( roles/
)
Editor
( roles/
)
Fleet Admin (formerly GKE Hub Admin)
( roles/
)
Fleet Editor (formerly GKE Hub Editor)
( roles/
)
Fleet Scope Admin
( roles/
)
Fleet Scope Editor
( roles/
)
Service agent roles
- KRM API Hosting AnthosApiEndpoint Service Agent
(
roles/)krmapihosting.anthosApiEndpointServiceAgent - Anthos Multi-Cloud Service Agent
(
roles/)gkemulticloud.serviceAgent
gkehub.namespaces.get
Owner
( roles/
)
Editor
( roles/
)
Viewer
( roles/
)
Fleet Admin (formerly GKE Hub Admin)
( roles/
)
Fleet Editor (formerly GKE Hub Editor)
( roles/
)
Fleet Scope Admin
( roles/
)
Fleet Scope Editor
( roles/
)
Fleet Scope Viewer
( roles/
)
Fleet Viewer (formerly GKE Hub Viewer)
( roles/
)
Support User
( roles/
)
Service agent roles
- Game Services Service Agent
(
roles/)gameservices.serviceAgent - Anthos Multi-Cloud Service Agent
(
roles/)gkemulticloud.serviceAgent - KRM API Hosting AnthosApiEndpoint Service Agent
(
roles/)krmapihosting.anthosApiEndpointServiceAgent - Mesh Managed Control Plane Service Agent
(
roles/)meshcontrolplane.serviceAgent - Anthos Support Service Agent
(
roles/)anthossupport.serviceAgent
gkehub.namespaces.list
Owner
( roles/
)
Editor
( roles/
)
Viewer
( roles/
)
Fleet Admin (formerly GKE Hub Admin)
( roles/
)
Fleet Editor (formerly GKE Hub Editor)
( roles/
)
Fleet Scope Admin
( roles/
)
Fleet Scope Editor
( roles/
)
Fleet Scope Viewer
( roles/
)
Fleet Viewer (formerly GKE Hub Viewer)
( roles/
)
Security Admin
( roles/
)
Security Auditor
( roles/
)
Security Reviewer
( roles/
)
Support User
( roles/
)
Service agent roles
- Game Services Service Agent
(
roles/)gameservices.serviceAgent - Anthos Multi-Cloud Service Agent
(
roles/)gkemulticloud.serviceAgent - KRM API Hosting AnthosApiEndpoint Service Agent
(
roles/)krmapihosting.anthosApiEndpointServiceAgent - Mesh Managed Control Plane Service Agent
(
roles/)meshcontrolplane.serviceAgent - Anthos Support Service Agent
(
roles/)anthossupport.serviceAgent
gkehub.namespaces.update
Owner
( roles/
)
Editor
( roles/
)
Fleet Admin (formerly GKE Hub Admin)
( roles/
)
Fleet Editor (formerly GKE Hub Editor)
( roles/
)
Service agent roles
- KRM API Hosting AnthosApiEndpoint Service Agent
(
roles/)krmapihosting.anthosApiEndpointServiceAgent - Anthos Multi-Cloud Service Agent
(
roles/)gkemulticloud.serviceAgent
gkehub.operations.cancel
Owner
( roles/
)
Editor
( roles/
)
Fleet Admin (formerly GKE Hub Admin)
( roles/
)
Fleet Editor (formerly GKE Hub Editor)
( roles/
)
Service agent roles
- Edge Container Service Agent
(
roles/)edgecontainer.serviceAgent - Anthos Multi-Cloud Service Agent
(
roles/)gkemulticloud.serviceAgent - KRM API Hosting AnthosApiEndpoint Service Agent
(
roles/)krmapihosting.anthosApiEndpointServiceAgent - Edge Container Cluster Service Agent
(
roles/)edgecontainer.clusterServiceAgent
gkehub.operations.delete
Owner
( roles/
)
Editor
( roles/
)
Fleet Admin (formerly GKE Hub Admin)
( roles/
)
Fleet Editor (formerly GKE Hub Editor)
( roles/
)
Service agent roles
- Anthos Multi-Cloud Service Agent
(
roles/)gkemulticloud.serviceAgent - KRM API Hosting AnthosApiEndpoint Service Agent
(
roles/)krmapihosting.anthosApiEndpointServiceAgent - Edge Container Cluster Service Agent
(
roles/)edgecontainer.clusterServiceAgent
gkehub.operations.get
Owner
( roles/
)
Editor
( roles/
)
Viewer
( roles/
)
Fleet Admin (formerly GKE Hub Admin)
( roles/
)
Fleet Editor (formerly GKE Hub Editor)
( roles/
)
Fleet Project-level Scope Editor
( roles/
)
Fleet Viewer (formerly GKE Hub Viewer)
( roles/
)
Support User
( roles/
)
Service agent roles
- Edge Container Cluster Service Agent
(
roles/)edgecontainer.clusterServiceAgent - Edge Container Service Agent
(
roles/)edgecontainer.serviceAgent - Game Services Service Agent
(
roles/)gameservices.serviceAgent - GKE Hub Service Agent
(
roles/)gkehub.serviceAgent - Anthos Multi-Cloud Service Agent
(
roles/)gkemulticloud.serviceAgent - KRM API Hosting AnthosApiEndpoint Service Agent
(
roles/)krmapihosting.anthosApiEndpointServiceAgent - Mesh Managed Control Plane Service Agent
(
roles/)meshcontrolplane.serviceAgent - Workload Certificate Service Agent
(
roles/)workloadcertificate.serviceAgent - Anthos Support Service Agent
(
roles/)anthossupport.serviceAgent
gkehub.operations.list
Owner
( roles/
)
Editor
( roles/
)
Viewer
( roles/
)
Fleet Admin (formerly GKE Hub Admin)
( roles/
)
Fleet Editor (formerly GKE Hub Editor)
( roles/
)
Fleet Viewer (formerly GKE Hub Viewer)
( roles/
)
Security Admin
( roles/
)
Security Auditor
( roles/
)
Security Reviewer
( roles/
)
Support User
( roles/
)
Service agent roles
- Edge Container Cluster Service Agent
(
roles/)edgecontainer.clusterServiceAgent - Game Services Service Agent
(
roles/)gameservices.serviceAgent - Anthos Multi-Cloud Service Agent
(
roles/)gkemulticloud.serviceAgent - KRM API Hosting AnthosApiEndpoint Service Agent
(
roles/)krmapihosting.anthosApiEndpointServiceAgent - Mesh Managed Control Plane Service Agent
(
roles/)meshcontrolplane.serviceAgent - Anthos Support Service Agent
(
roles/)anthossupport.serviceAgent
gkehub.rbacrolebindings.create
Owner
( roles/
)
Editor
( roles/
)
Fleet Admin (formerly GKE Hub Admin)
( roles/
)
Fleet Editor (formerly GKE Hub Editor)
( roles/
)
Fleet Scope Admin
( roles/
)
Service agent roles
- KRM API Hosting AnthosApiEndpoint Service Agent
(
roles/)krmapihosting.anthosApiEndpointServiceAgent - Anthos Multi-Cloud Service Agent
(
roles/)gkemulticloud.serviceAgent
gkehub.rbacrolebindings.delete
Owner
( roles/
)
Editor
( roles/
)
Fleet Admin (formerly GKE Hub Admin)
( roles/
)
Fleet Editor (formerly GKE Hub Editor)
( roles/
)
Fleet Scope Admin
( roles/
)
Service agent roles
- KRM API Hosting AnthosApiEndpoint Service Agent
(
roles/)krmapihosting.anthosApiEndpointServiceAgent - Anthos Multi-Cloud Service Agent
(
roles/)gkemulticloud.serviceAgent
gkehub.rbacrolebindings.get
Owner
( roles/
)
Editor
( roles/
)
Viewer
( roles/
)
Fleet Admin (formerly GKE Hub Admin)
( roles/
)
Fleet Editor (formerly GKE Hub Editor)
( roles/
)
Fleet Scope Admin
( roles/
)
Fleet Scope Editor
( roles/
)
Fleet Scope Viewer
( roles/
)
Fleet Viewer (formerly GKE Hub Viewer)
( roles/
)
Support User
( roles/
)
Service agent roles
- Game Services Service Agent
(
roles/)gameservices.serviceAgent - Anthos Multi-Cloud Service Agent
(
roles/)gkemulticloud.serviceAgent - KRM API Hosting AnthosApiEndpoint Service Agent
(
roles/)krmapihosting.anthosApiEndpointServiceAgent - Mesh Managed Control Plane Service Agent
(
roles/)meshcontrolplane.serviceAgent - Anthos Support Service Agent
(
roles/)anthossupport.serviceAgent
gkehub.rbacrolebindings.list
Owner
( roles/
)
Editor
( roles/
)
Viewer
( roles/
)
Fleet Admin (formerly GKE Hub Admin)
( roles/
)
Fleet Editor (formerly GKE Hub Editor)
( roles/
)
Fleet Scope Admin
( roles/
)
Fleet Scope Editor
( roles/
)
Fleet Scope Viewer
( roles/
)
Fleet Viewer (formerly GKE Hub Viewer)
( roles/
)
Security Admin
( roles/
)
Security Auditor
( roles/
)
Security Reviewer
( roles/
)
Support User
( roles/
)
Service agent roles
- Game Services Service Agent
(
roles/)gameservices.serviceAgent - Anthos Multi-Cloud Service Agent
(
roles/)gkemulticloud.serviceAgent - KRM API Hosting AnthosApiEndpoint Service Agent
(
roles/)krmapihosting.anthosApiEndpointServiceAgent - Mesh Managed Control Plane Service Agent
(
roles/)meshcontrolplane.serviceAgent - Anthos Support Service Agent
(
roles/)anthossupport.serviceAgent
gkehub.rbacrolebindings.update
Owner
( roles/
)
Editor
( roles/
)
Fleet Admin (formerly GKE Hub Admin)
( roles/
)
Fleet Editor (formerly GKE Hub Editor)
( roles/
)
Fleet Scope Admin
( roles/
)
Service agent roles
- KRM API Hosting AnthosApiEndpoint Service Agent
(
roles/)krmapihosting.anthosApiEndpointServiceAgent - Anthos Multi-Cloud Service Agent
(
roles/)gkemulticloud.serviceAgent
gkehub.scopes.create
Owner
( roles/
)
Editor
( roles/
)
Fleet Admin (formerly GKE Hub Admin)
( roles/
)
Fleet Editor (formerly GKE Hub Editor)
( roles/
)
Service agent roles
- KRM API Hosting AnthosApiEndpoint Service Agent
(
roles/)krmapihosting.anthosApiEndpointServiceAgent - Anthos Multi-Cloud Service Agent
(
roles/)gkemulticloud.serviceAgent
gkehub.scopes.delete
Owner
( roles/
)
Editor
( roles/
)
Fleet Admin (formerly GKE Hub Admin)
( roles/
)
Fleet Editor (formerly GKE Hub Editor)
( roles/
)
Service agent roles
- KRM API Hosting AnthosApiEndpoint Service Agent
(
roles/)krmapihosting.anthosApiEndpointServiceAgent - Anthos Multi-Cloud Service Agent
(
roles/)gkemulticloud.serviceAgent
gkehub.scopes.get
Owner
( roles/
)
Editor
( roles/
)
Viewer
( roles/
)
Fleet Admin (formerly GKE Hub Admin)
( roles/
)
Fleet Editor (formerly GKE Hub Editor)
( roles/
)
Fleet Scope Admin
( roles/
)
Fleet Scope Editor
( roles/
)
Fleet Scope Viewer
( roles/
)
Fleet Viewer (formerly GKE Hub Viewer)
( roles/
)
Support User
( roles/
)
Service agent roles
- Game Services Service Agent
(
roles/)gameservices.serviceAgent - Anthos Multi-Cloud Service Agent
(
roles/)gkemulticloud.serviceAgent - KRM API Hosting AnthosApiEndpoint Service Agent
(
roles/)krmapihosting.anthosApiEndpointServiceAgent - Mesh Managed Control Plane Service Agent
(
roles/)meshcontrolplane.serviceAgent - Anthos Support Service Agent
(
roles/)anthossupport.serviceAgent
gkehub.scopes.getIamPolicy
Owner
( roles/
)
Editor
( roles/
)
Viewer
( roles/
)
Fleet Admin (formerly GKE Hub Admin)
( roles/
)
Fleet Editor (formerly GKE Hub Editor)
( roles/
)
Fleet Scope Admin
( roles/
)
Fleet Scope Editor
( roles/
)
Fleet Scope Viewer
( roles/
)
Security Admin
( roles/
)
Security Auditor
( roles/
)
Security Reviewer
( roles/
)
Support User
( roles/
)
Service agent roles
- KRM API Hosting AnthosApiEndpoint Service Agent
(
roles/)krmapihosting.anthosApiEndpointServiceAgent - Anthos Multi-Cloud Service Agent
(
roles/)gkemulticloud.serviceAgent
gkehub.scopes.list
Owner
( roles/
)
Editor
( roles/
)
Viewer
( roles/
)
Fleet Admin (formerly GKE Hub Admin)
( roles/
)
Fleet Editor (formerly GKE Hub Editor)
( roles/
)
Fleet Viewer (formerly GKE Hub Viewer)
( roles/
)
Security Admin
( roles/
)
Security Auditor
( roles/
)
Security Reviewer
( roles/
)
Support User
( roles/
)
Service agent roles
- Game Services Service Agent
(
roles/)gameservices.serviceAgent - Anthos Multi-Cloud Service Agent
(
roles/)gkemulticloud.serviceAgent - KRM API Hosting AnthosApiEndpoint Service Agent
(
roles/)krmapihosting.anthosApiEndpointServiceAgent - Mesh Managed Control Plane Service Agent
(
roles/)meshcontrolplane.serviceAgent - Anthos Support Service Agent
(
roles/)anthossupport.serviceAgent
gkehub.
scopes.
listBoundMemberships
Owner
( roles/
)
Editor
( roles/
)
Viewer
( roles/
)
Fleet Admin (formerly GKE Hub Admin)
( roles/
)
Fleet Editor (formerly GKE Hub Editor)
( roles/
)
Fleet Scope Admin
( roles/
)
Fleet Scope Editor
( roles/
)
Fleet Scope Viewer
( roles/
)
Fleet Viewer (formerly GKE Hub Viewer)
( roles/
)
Support User
( roles/
)
Service agent roles
- Game Services Service Agent
(
roles/)gameservices.serviceAgent - Anthos Multi-Cloud Service Agent
(
roles/)gkemulticloud.serviceAgent - KRM API Hosting AnthosApiEndpoint Service Agent
(
roles/)krmapihosting.anthosApiEndpointServiceAgent - Mesh Managed Control Plane Service Agent
(
roles/)meshcontrolplane.serviceAgent - Anthos Support Service Agent
(
roles/)anthossupport.serviceAgent
gkehub.scopes.setIamPolicy
Owner
( roles/
)
Fleet Admin (formerly GKE Hub Admin)
( roles/
)
Fleet Scope Admin
( roles/
)
Security Admin
( roles/
)
gkehub.scopes.update
Owner
( roles/
)
Editor
( roles/
)
Fleet Admin (formerly GKE Hub Admin)
( roles/
)
Fleet Editor (formerly GKE Hub Editor)
( roles/
)
Service agent roles
- KRM API Hosting AnthosApiEndpoint Service Agent
(
roles/)krmapihosting.anthosApiEndpointServiceAgent - Anthos Multi-Cloud Service Agent
(
roles/)gkemulticloud.serviceAgent

