This page lists the IAM roles and permissions for Service Networking. To search through all roles and permissions, see the role and permission index .
Service Networking roles
Service Networking Admin Beta
( roles/
)
Full control of service networking with projects.
servicenetworking.*
-
servicenetworking.
operations. cancel -
servicenetworking.
operations. delete -
servicenetworking.
operations. get -
servicenetworking.
operations. list -
servicenetworking.
services. addDnsRecordSet -
servicenetworking.
services. addDnsZone -
servicenetworking.
services. addPeering -
servicenetworking.
services. addSubnetwork -
servicenetworking.
services. createPeeredDnsDomain -
servicenetworking.
services. deleteConnection -
servicenetworking.
services. deletePeeredDnsDomain -
servicenetworking.
services. disableVpcServiceControls -
servicenetworking.
services. enableVpcServiceControls -
servicenetworking.services.get
-
servicenetworking.
services. getConsumerConfig -
servicenetworking.
services. listPeeredDnsDomains -
servicenetworking.
services. removeDnsRecordSet -
servicenetworking.
services. removeDnsZone -
servicenetworking.
services. updateConsumerConfig -
servicenetworking.
services. updateDnsRecordSet -
servicenetworking.services.use
Service Networking Service Agent
( roles/
)
Gives permission to manage network configuration, such as establishing network peering, necessary for service producers
compute.globalAddresses.get
compute.globalAddresses.list
compute.globalOperations.get
compute.networks.addPeering
compute.networks.create
compute.networks.delete
compute.networks.get
compute.networks.list
compute.
compute.networks.removePeering
compute.networks.update
compute.networks.updatePeering
compute.networks.updatePolicy
compute.projects.get
compute.regionOperations.get
compute.routers.get
compute.routers.list
compute.routes.list
compute.subnetworks.create
compute.subnetworks.delete
compute.subnetworks.get
compute.subnetworks.list
dns.changes.*
-
dns.changes.create
-
dns.changes.get
-
dns.changes.list
dns.dnsKeys.*
-
dns.dnsKeys.get
-
dns.dnsKeys.list
dns.gkeClusters.*
-
dns.
gkeClusters. bindDNSResponsePolicy -
dns.
gkeClusters. bindPrivateDNSZone
dns.managedZoneOperations.*
-
dns.managedZoneOperations.get
-
dns.managedZoneOperations.list
dns.managedZones.create
dns.managedZones.delete
dns.managedZones.get
dns.managedZones.getIamPolicy
dns.managedZones.list
dns.managedZones.update
dns.networks.*
-
dns.
networks. bindDNSResponsePolicy -
dns.
networks. bindPrivateDNSPolicy -
dns.
networks. bindPrivateDNSZone -
dns.
networks. targetWithPeeringZone -
dns.networks.useHealthSignals
dns.policies.*
-
dns.policies.create
-
dns.policies.delete
-
dns.policies.get
-
dns.policies.list
-
dns.policies.update
dns.projects.get
dns.resourceRecordSets.*
-
dns.resourceRecordSets.create
-
dns.resourceRecordSets.delete
-
dns.resourceRecordSets.get
-
dns.resourceRecordSets.list
-
dns.resourceRecordSets.update
dns.responsePolicies.*
-
dns.responsePolicies.create
-
dns.responsePolicies.delete
-
dns.responsePolicies.get
-
dns.responsePolicies.list
-
dns.responsePolicies.update
dns.responsePolicyRules.*
-
dns.responsePolicyRules.create
-
dns.responsePolicyRules.delete
-
dns.responsePolicyRules.get
-
dns.responsePolicyRules.list
-
dns.responsePolicyRules.update
networkconnectivity.
resourcemanager.projects.get
resourcemanager.projects.list
Service Networking permissions
servicenetworking.
operations.
cancel
Owner
( roles/
)
Editor
( roles/
)
Service Networking Admin
( roles/
)
servicenetworking.
operations.
delete
Owner
( roles/
)
Editor
( roles/
)
Service Networking Admin
( roles/
)
servicenetworking.
operations.
get
Owner
( roles/
)
Editor
( roles/
)
Viewer
( roles/
)
Compute Network Admin
( roles/
)
Infrastructure Administrator
( roles/
)
Network Administrator
( roles/
)
Support User
( roles/
)
Service Networking Admin
( roles/
)
Service agent roles
- Cloud TPU V2 API Service Agent
(
roles/
)cloudtpu.serviceAgent - Cloud Composer API Service Agent
(
roles/
)composer.serviceAgent - Kubernetes Engine Service Agent
(
roles/
)container.serviceAgent - Cloud Dataflow Service Agent
(
roles/
)dataflow.serviceAgent - Cloud Deployment Manager Service Agent
(
roles/
)clouddeploymentmanager.serviceAgent
servicenetworking.
operations.
list
Owner
( roles/
)
Editor
( roles/
)
Viewer
( roles/
)
Security Admin
( roles/
)
Security Auditor
( roles/
)
Security Reviewer
( roles/
)
Support User
( roles/
)
Service Networking Admin
( roles/
)
servicenetworking.
services.
addDnsRecordSet
Owner
( roles/
)
Editor
( roles/
)
Service Networking Admin
( roles/
)
servicenetworking.
services.
addDnsZone
Owner
( roles/
)
Editor
( roles/
)
Service Networking Admin
( roles/
)
servicenetworking.
services.
addPeering
Owner
( roles/
)
Compute Network Admin
( roles/
)
Infrastructure Administrator
( roles/
)
Network Administrator
( roles/
)
Service Networking Admin
( roles/
)
Service agent roles
- Cloud TPU V2 API Service Agent
(
roles/
)cloudtpu.serviceAgent - Cloud Composer API Service Agent
(
roles/
)composer.serviceAgent - Kubernetes Engine Service Agent
(
roles/
)container.serviceAgent - Cloud Dataflow Service Agent
(
roles/
)dataflow.serviceAgent - Cloud Deployment Manager Service Agent
(
roles/
)clouddeploymentmanager.serviceAgent
servicenetworking.
services.
addSubnetwork
Owner
( roles/
)
Editor
( roles/
)
Service Networking Admin
( roles/
)
servicenetworking.
services.
createPeeredDnsDomain
Owner
( roles/
)
Editor
( roles/
)
Compute Network Admin
( roles/
)
Infrastructure Administrator
( roles/
)
Network Administrator
( roles/
)
Service Networking Admin
( roles/
)
Service agent roles
- Cloud Composer API Service Agent
(
roles/
)composer.serviceAgent - Kubernetes Engine Service Agent
(
roles/
)container.serviceAgent - Cloud Dataflow Service Agent
(
roles/
)dataflow.serviceAgent - Cloud TPU V2 API Service Agent
(
roles/
)cloudtpu.serviceAgent
servicenetworking.
services.
deleteConnection
Owner
( roles/
)
Editor
( roles/
)
Compute Network Admin
( roles/
)
Infrastructure Administrator
( roles/
)
Network Administrator
( roles/
)
Service Networking Admin
( roles/
)
Service agent roles
- Cloud Composer API Service Agent
(
roles/
)composer.serviceAgent - Kubernetes Engine Service Agent
(
roles/
)container.serviceAgent - Cloud Dataflow Service Agent
(
roles/
)dataflow.serviceAgent - Cloud TPU V2 API Service Agent
(
roles/
)cloudtpu.serviceAgent
servicenetworking.
services.
deletePeeredDnsDomain
Owner
( roles/
)
Editor
( roles/
)
Compute Network Admin
( roles/
)
Infrastructure Administrator
( roles/
)
Network Administrator
( roles/
)
Service Networking Admin
( roles/
)
Service agent roles
- Cloud Composer API Service Agent
(
roles/
)composer.serviceAgent - Kubernetes Engine Service Agent
(
roles/
)container.serviceAgent - Cloud Dataflow Service Agent
(
roles/
)dataflow.serviceAgent - Cloud TPU V2 API Service Agent
(
roles/
)cloudtpu.serviceAgent
servicenetworking.
services.
disableVpcServiceControls
Owner
( roles/
)
Editor
( roles/
)
Compute Network Admin
( roles/
)
Infrastructure Administrator
( roles/
)
Network Administrator
( roles/
)
Service Networking Admin
( roles/
)
Service agent roles
- Cloud Composer API Service Agent
(
roles/
)composer.serviceAgent - Kubernetes Engine Service Agent
(
roles/
)container.serviceAgent - Cloud Dataflow Service Agent
(
roles/
)dataflow.serviceAgent - Cloud TPU V2 API Service Agent
(
roles/
)cloudtpu.serviceAgent
servicenetworking.
services.
enableVpcServiceControls
Owner
( roles/
)
Editor
( roles/
)
Compute Network Admin
( roles/
)
Infrastructure Administrator
( roles/
)
Network Administrator
( roles/
)
Service Networking Admin
( roles/
)
Service agent roles
- Cloud Composer API Service Agent
(
roles/
)composer.serviceAgent - Kubernetes Engine Service Agent
(
roles/
)container.serviceAgent - Cloud Dataflow Service Agent
(
roles/
)dataflow.serviceAgent - Cloud TPU V2 API Service Agent
(
roles/
)cloudtpu.serviceAgent
servicenetworking.services.get
Owner
( roles/
)
Editor
( roles/
)
Viewer
( roles/
)
Compute Network Admin
( roles/
)
Compute Network User
( roles/
)
Compute Network Viewer
( roles/
)
Infrastructure Administrator
( roles/
)
Network Administrator
( roles/
)
Security Auditor
( roles/
)
Support User
( roles/
)
Service Networking Admin
( roles/
)
Service agent roles
- Cloud TPU V2 API Service Agent
(
roles/
)cloudtpu.serviceAgent - Cloud Composer API Service Agent
(
roles/
)composer.serviceAgent - Kubernetes Engine Service Agent
(
roles/
)container.serviceAgent - Cloud Dataflow Service Agent
(
roles/
)dataflow.serviceAgent - Cloud Data Fusion API Service Agent
(
roles/
)datafusion.serviceAgent - Cloud Deployment Manager Service Agent
(
roles/
)clouddeploymentmanager.serviceAgent
servicenetworking.
services.
getConsumerConfig
Owner
( roles/
)
Editor
( roles/
)
Viewer
( roles/
)
Support User
( roles/
)
Service Networking Admin
( roles/
)
servicenetworking.
services.
listPeeredDnsDomains
Owner
( roles/
)
Editor
( roles/
)
Viewer
( roles/
)
Compute Network Admin
( roles/
)
Infrastructure Administrator
( roles/
)
Network Administrator
( roles/
)
Support User
( roles/
)
Service Networking Admin
( roles/
)
Service agent roles
- Cloud Composer API Service Agent
(
roles/
)composer.serviceAgent - Kubernetes Engine Service Agent
(
roles/
)container.serviceAgent - Cloud Dataflow Service Agent
(
roles/
)dataflow.serviceAgent - Cloud TPU V2 API Service Agent
(
roles/
)cloudtpu.serviceAgent
servicenetworking.
services.
removeDnsRecordSet
Owner
( roles/
)
Editor
( roles/
)
Service Networking Admin
( roles/
)
servicenetworking.
services.
removeDnsZone
Owner
( roles/
)
Editor
( roles/
)
Service Networking Admin
( roles/
)
servicenetworking.
services.
updateConsumerConfig
Owner
( roles/
)
Editor
( roles/
)
Service Networking Admin
( roles/
)
servicenetworking.
services.
updateDnsRecordSet
Owner
( roles/
)
Editor
( roles/
)
Service Networking Admin
( roles/
)
servicenetworking.services.use
Owner
( roles/
)
Editor
( roles/
)
Viewer
( roles/
)
Support User
( roles/
)
Service Networking Admin
( roles/
)