This page lists the IAM roles and permissions for Container Threat Detection. To search through all roles and permissions, see the role and permission index .
Container Threat Detection roles
Container Threat Detection Service Agent
( roles/  
)
Gives Container Threat Detection service account access to enable/disable Container Threat Detection and manage the Container Threat Detection Agent on Google Kubernetes Engine clusters.
 container.apiServices.get 
 container.  
 container.apiServices.list 
 container.auditSinks.get 
 container.auditSinks.list 
 container.backendConfigs.get 
 container.backendConfigs.list 
 container.bindings.get 
 container.bindings.list 
 container.  
 container.  
 container.  
  container.  
 
-  container.clusterRoleBindings. create 
-  container.clusterRoleBindings. delete 
-  container.clusterRoleBindings. get 
-  container.clusterRoleBindings. list 
-  container.clusterRoleBindings. update 
  container.clusterRoles.* 
 
-  container.clusterRoles.bind
-  container.clusterRoles.create
-  container.clusterRoles.delete
-  container.clusterRoles. escalate 
-  container.clusterRoles.get
-  container.clusterRoles.list
-  container.clusterRoles.update
 container.clusters.connect 
 container.clusters.get 
 container.clusters.list 
  container.componentStatuses.* 
 
-  container.componentStatuses. get 
-  container.componentStatuses. list 
 container.configMaps.get 
 container.configMaps.list 
 container.  
 container.  
 container.cronJobs.get 
 container.cronJobs.getStatus 
 container.cronJobs.list 
 container.csiDrivers.get 
 container.csiDrivers.list 
 container.csiNodeInfos.get 
 container.csiNodeInfos.list 
 container.csiNodes.get 
 container.csiNodes.list 
 container.  
 container.  
 container.  
 container.  
 container.  
 container.  
  container.daemonSets.* 
 
-  container.daemonSets.create
-  container.daemonSets.delete
-  container.daemonSets.get
-  container.daemonSets.getStatus
-  container.daemonSets.list
-  container.daemonSets.update
-  container.daemonSets. updateStatus 
 container.deployments.get 
 container.deployments.getScale 
 container.  
 container.deployments.list 
 container.endpointSlices.get 
 container.endpointSlices.list 
 container.endpoints.get 
 container.endpoints.list 
 container.events.get 
 container.events.list 
 container.frontendConfigs.get 
 container.frontendConfigs.list 
 container.  
 container.  
 container.  
 container.ingresses.get 
 container.ingresses.getStatus 
 container.ingresses.list 
 container.  
 container.  
 container.jobs.get 
 container.jobs.getStatus 
 container.jobs.list 
 container.leases.get 
 container.leases.list 
 container.limitRanges.get 
 container.limitRanges.list 
 container.  
 container.  
 container.  
 container.  
 container.namespaces.get 
 container.namespaces.getStatus 
 container.namespaces.list 
 container.networkPolicies.get 
 container.networkPolicies.list 
 container.  
 container.nodes.get 
 container.nodes.getStatus 
 container.nodes.list 
  container.operations.* 
 
-  container.operations.get
-  container.operations.list
 container.  
 container.  
 container.  
 container.  
 container.  
 container.  
 container.petSets.get 
 container.petSets.list 
 container.  
 container.  
 container.  
 container.podPresets.get 
 container.podPresets.list 
 container.  
 container.  
 container.podTemplates.get 
 container.podTemplates.list 
 container.pods.attach 
 container.pods.create 
 container.pods.delete 
 container.pods.exec 
 container.pods.get 
 container.pods.getLogs 
 container.pods.getStatus 
 container.pods.list 
 container.pods.portForward 
 container.pods.update 
 container.priorityClasses.get 
 container.priorityClasses.list 
 container.replicaSets.get 
 container.replicaSets.getScale 
 container.  
 container.replicaSets.list 
 container.  
 container.  
 container.  
 container.  
 container.resourceQuotas.get 
 container.  
 container.resourceQuotas.list 
  container.roleBindings.* 
 
-  container.roleBindings.create
-  container.roleBindings.delete
-  container.roleBindings.get
-  container.roleBindings.list
-  container.roleBindings.update
  container.roles.* 
 
-  container.roles.bind
-  container.roles.create
-  container.roles.delete
-  container.roles.escalate
-  container.roles.get
-  container.roles.list
-  container.roles.update
 container.runtimeClasses.get 
 container.runtimeClasses.list 
 container.scheduledJobs.get 
 container.scheduledJobs.list 
 container.secrets.create 
 container.secrets.delete 
 container.secrets.list 
 container.secrets.update 
 container.  
 container.  
 container.serviceAccounts.get 
 container.serviceAccounts.list 
 container.  
 container.services.get 
 container.services.getStatus 
 container.services.list 
 container.statefulSets.get 
 container.  
 container.  
 container.statefulSets.list 
 container.storageClasses.get 
 container.storageClasses.list 
 container.storageStates.get 
 container.  
 container.storageStates.list 
 container.  
 container.  
 container.  
 container.  
 container.  
 container.  
 container.  
 container.tokenReviews.create 
 container.updateInfos.get 
 container.updateInfos.list 
 container.  
 container.  
 container.  
 container.  
 container.  
 container.  
 container.  
 container.  
 container.  
 container.  
 container.volumeSnapshots.get 
 container.volumeSnapshots.list 
 recommender.  
 recommender.  
 recommender.  
 recommender.  
  recommender.locations.* 
 
-  recommender.locations.get
-  recommender.locations.list
 recommender.  
 recommender.  
 recommender.  
 recommender.  
 resourcemanager.projects.get 
 resourcemanager.projects.list 
Container Threat Detection permissions
There are no IAM permissions for this service.

