This page lists the IAM roles and permissions for Cloud DNS. To search through all roles and permissions, see the role and permission index .
Cloud DNS roles
DNS Administrator
( roles/  
)
Provides read-write access to all Cloud DNS resources.
Lowest-level resources where you can grant this role:
- Managed zone
 compute.networks.get 
 compute.networks.list 
  dns.changes.* 
 
-  dns.changes.create
-  dns.changes.get
-  dns.changes.list
  dns.dnsKeys.* 
 
-  dns.dnsKeys.get
-  dns.dnsKeys.list
  dns.gkeClusters.* 
 
-  dns.gkeClusters. bindDNSResponsePolicy 
-  dns.gkeClusters. bindPrivateDNSZone 
  dns.managedZoneOperations.* 
 
-  dns.managedZoneOperations.get
-  dns.managedZoneOperations.list
 dns.managedZones.create 
 dns.managedZones.delete 
 dns.managedZones.get 
 dns.managedZones.getIamPolicy 
 dns.managedZones.list 
 dns.managedZones.update 
  dns.networks.* 
 
-  dns.networks. bindDNSResponsePolicy 
-  dns.networks. bindPrivateDNSPolicy 
-  dns.networks. bindPrivateDNSZone 
-  dns.networks. targetWithPeeringZone 
-  dns.networks.useHealthSignals
  dns.policies.* 
 
-  dns.policies.create
-  dns.policies.delete
-  dns.policies.get
-  dns.policies.list
-  dns.policies.update
 dns.projects.get 
  dns.resourceRecordSets.* 
 
-  dns.resourceRecordSets.create
-  dns.resourceRecordSets.delete
-  dns.resourceRecordSets.get
-  dns.resourceRecordSets.list
-  dns.resourceRecordSets.update
  dns.responsePolicies.* 
 
-  dns.responsePolicies.create
-  dns.responsePolicies.delete
-  dns.responsePolicies.get
-  dns.responsePolicies.list
-  dns.responsePolicies.update
  dns.responsePolicyRules.* 
 
-  dns.responsePolicyRules.create
-  dns.responsePolicyRules.delete
-  dns.responsePolicyRules.get
-  dns.responsePolicyRules.list
-  dns.responsePolicyRules.update
 resourcemanager.projects.get 
 resourcemanager.projects.list 
DNS Peer
( roles/  
)
Access to target networks with DNS peering zones
 dns.  
DNS Reader
( roles/  
)
Provides read-only access to all Cloud DNS resources.
Lowest-level resources where you can grant this role:
- Managed zone
 compute.networks.get 
 dns.changes.get 
 dns.changes.list 
  dns.dnsKeys.* 
 
-  dns.dnsKeys.get
-  dns.dnsKeys.list
  dns.managedZoneOperations.* 
 
-  dns.managedZoneOperations.get
-  dns.managedZoneOperations.list
 dns.managedZones.get 
 dns.managedZones.list 
 dns.policies.get 
 dns.policies.list 
 dns.projects.get 
 dns.resourceRecordSets.get 
 dns.resourceRecordSets.list 
 dns.responsePolicies.get 
 dns.responsePolicies.list 
 dns.responsePolicyRules.get 
 dns.responsePolicyRules.list 
 resourcemanager.projects.get 
 resourcemanager.projects.list 
Cloud DNS Service Agent
( roles/  
)
Gives Cloud DNS Service Agent access to Cloud Platform resources.
 compute.  
 compute.  
 compute.  
 compute.  
 compute.  
 compute.globalOperations.get 
 compute.healthChecks.get 
Cloud DNS permissions
 dns.changes.create 
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 DNS Administrator 
( roles/  
)
 Network Administrator 
( roles/  
)
Service agent roles
-  Kubernetes Engine Service Agent 
( roles/)container.serviceAgent 
-  Cloud Managed Identities Service Agent 
( roles/)managedidentities.serviceAgent 
-  Managed Kafka Service Agent 
( roles/)managedkafka.serviceAgent 
-  Dataproc Metastore Service Agent 
( roles/)metastore.serviceAgent 
-  Multi-Cluster Service Discovery Service Agent 
( roles/)multiclusterservicediscovery.serviceAgent 
-  Oracle Database@Google Cloud Service Agent 
( roles/)oci.serviceAgent 
-  Service Networking Service Agent 
( roles/)servicenetworking.serviceAgent 
-  VMware Engine Service Agent 
( roles/)vmwareengine.serviceAgent 
-  Cloud Deployment Manager Service Agent 
( roles/)clouddeploymentmanager.serviceAgent 
 dns.changes.get 
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Viewer 
( roles/  
)
 DNS Administrator 
( roles/  
)
 DNS Reader 
( roles/  
)
 Network Administrator 
( roles/  
)
 Security Auditor 
( roles/  
)
 Support User 
( roles/  
)
Service agent roles
-  Kubernetes Engine Service Agent 
( roles/)container.serviceAgent 
-  Cloud Managed Identities Service Agent 
( roles/)managedidentities.serviceAgent 
-  Dataproc Metastore Service Agent 
( roles/)metastore.serviceAgent 
-  Multi-Cluster Service Discovery Service Agent 
( roles/)multiclusterservicediscovery.serviceAgent 
-  Oracle Database@Google Cloud Service Agent 
( roles/)oci.serviceAgent 
-  Service Networking Service Agent 
( roles/)servicenetworking.serviceAgent 
-  VMware Engine Service Agent 
( roles/)vmwareengine.serviceAgent 
-  Cloud Deployment Manager Service Agent 
( roles/)clouddeploymentmanager.serviceAgent 
 dns.changes.list 
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Viewer 
( roles/  
)
 DNS Administrator 
( roles/  
)
 DNS Reader 
( roles/  
)
 Network Administrator 
( roles/  
)
 Security Admin 
( roles/  
)
 Security Auditor 
( roles/  
)
 Security Reviewer 
( roles/  
)
 Support User 
( roles/  
)
Service agent roles
-  Kubernetes Engine Service Agent 
( roles/)container.serviceAgent 
-  Cloud Managed Identities Service Agent 
( roles/)managedidentities.serviceAgent 
-  Multi-Cluster Service Discovery Service Agent 
( roles/)multiclusterservicediscovery.serviceAgent 
-  Oracle Database@Google Cloud Service Agent 
( roles/)oci.serviceAgent 
-  Service Networking Service Agent 
( roles/)servicenetworking.serviceAgent 
-  VMware Engine Service Agent 
( roles/)vmwareengine.serviceAgent 
-  Cloud Deployment Manager Service Agent 
( roles/)clouddeploymentmanager.serviceAgent 
 dns.dnsKeys.get 
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Viewer 
( roles/  
)
 DNS Administrator 
( roles/  
)
 DNS Reader 
( roles/  
)
 Network Administrator 
( roles/  
)
 Security Auditor 
( roles/  
)
 Support User 
( roles/  
)
Service agent roles
-  Cloud Managed Identities Service Agent 
( roles/)managedidentities.serviceAgent 
-  Multi-Cluster Service Discovery Service Agent 
( roles/)multiclusterservicediscovery.serviceAgent 
-  Oracle Database@Google Cloud Service Agent 
( roles/)oci.serviceAgent 
-  Service Networking Service Agent 
( roles/)servicenetworking.serviceAgent 
-  VMware Engine Service Agent 
( roles/)vmwareengine.serviceAgent 
-  Kubernetes Engine Service Agent 
( roles/)container.serviceAgent 
 dns.dnsKeys.list 
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Viewer 
( roles/  
)
 DNS Administrator 
( roles/  
)
 DNS Reader 
( roles/  
)
 Network Administrator 
( roles/  
)
 Security Admin 
( roles/  
)
 Security Auditor 
( roles/  
)
 Security Reviewer 
( roles/  
)
 Support User 
( roles/  
)
Service agent roles
-  Cloud Managed Identities Service Agent 
( roles/)managedidentities.serviceAgent 
-  Multi-Cluster Service Discovery Service Agent 
( roles/)multiclusterservicediscovery.serviceAgent 
-  Oracle Database@Google Cloud Service Agent 
( roles/)oci.serviceAgent 
-  Service Networking Service Agent 
( roles/)servicenetworking.serviceAgent 
-  VMware Engine Service Agent 
( roles/)vmwareengine.serviceAgent 
-  Kubernetes Engine Service Agent 
( roles/)container.serviceAgent 
 dns.  
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 DNS Administrator 
( roles/  
)
 Network Administrator 
( roles/  
)
Service agent roles
-  Multi-Cluster Service Discovery Service Agent 
( roles/)multiclusterservicediscovery.serviceAgent 
-  Service Networking Service Agent 
( roles/)servicenetworking.serviceAgent 
-  VMware Engine Service Agent 
( roles/)vmwareengine.serviceAgent 
-  Kubernetes Engine Service Agent 
( roles/)container.serviceAgent 
 dns.  
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 DNS Administrator 
( roles/  
)
 Network Administrator 
( roles/  
)
Service agent roles
-  Multi-Cluster Service Discovery Service Agent 
( roles/)multiclusterservicediscovery.serviceAgent 
-  Service Networking Service Agent 
( roles/)servicenetworking.serviceAgent 
-  VMware Engine Service Agent 
( roles/)vmwareengine.serviceAgent 
-  Kubernetes Engine Service Agent 
( roles/)container.serviceAgent 
 dns.managedZoneOperations.get 
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Viewer 
( roles/  
)
 DNS Administrator 
( roles/  
)
 DNS Reader 
( roles/  
)
 Network Administrator 
( roles/  
)
 Security Auditor 
( roles/  
)
 Support User 
( roles/  
)
Service agent roles
-  Cloud Managed Identities Service Agent 
( roles/)managedidentities.serviceAgent 
-  Multi-Cluster Service Discovery Service Agent 
( roles/)multiclusterservicediscovery.serviceAgent 
-  Oracle Database@Google Cloud Service Agent 
( roles/)oci.serviceAgent 
-  Service Networking Service Agent 
( roles/)servicenetworking.serviceAgent 
-  VMware Engine Service Agent 
( roles/)vmwareengine.serviceAgent 
-  Kubernetes Engine Service Agent 
( roles/)container.serviceAgent 
 dns.managedZoneOperations.list 
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Viewer 
( roles/  
)
 DNS Administrator 
( roles/  
)
 DNS Reader 
( roles/  
)
 Network Administrator 
( roles/  
)
 Security Admin 
( roles/  
)
 Security Auditor 
( roles/  
)
 Security Reviewer 
( roles/  
)
 Support User 
( roles/  
)
Service agent roles
-  Cloud Managed Identities Service Agent 
( roles/)managedidentities.serviceAgent 
-  Multi-Cluster Service Discovery Service Agent 
( roles/)multiclusterservicediscovery.serviceAgent 
-  Oracle Database@Google Cloud Service Agent 
( roles/)oci.serviceAgent 
-  Service Networking Service Agent 
( roles/)servicenetworking.serviceAgent 
-  VMware Engine Service Agent 
( roles/)vmwareengine.serviceAgent 
-  Kubernetes Engine Service Agent 
( roles/)container.serviceAgent 
 dns.managedZones.create 
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 DNS Administrator 
( roles/  
)
 Network Administrator 
( roles/  
)
Service agent roles
-  Kubernetes Engine Service Agent 
( roles/)container.serviceAgent 
-  Cloud Data Fusion API Service Agent 
( roles/)datafusion.serviceAgent 
-  Cloud Managed Identities Service Agent 
( roles/)managedidentities.serviceAgent 
-  Managed Kafka Service Agent 
( roles/)managedkafka.serviceAgent 
-  Dataproc Metastore Service Agent 
( roles/)metastore.serviceAgent 
-  Multi-Cluster Service Discovery Service Agent 
( roles/)multiclusterservicediscovery.serviceAgent 
-  Network Connectivity Service Agent 
( roles/)networkconnectivity.serviceAgent 
-  Oracle Database@Google Cloud Service Agent 
( roles/)oci.serviceAgent 
-  Service Networking Service Agent 
( roles/)servicenetworking.serviceAgent 
-  VMware Engine Service Agent 
( roles/)vmwareengine.serviceAgent 
-  Cloud Deployment Manager Service Agent 
( roles/)clouddeploymentmanager.serviceAgent 
 dns.managedZones.delete 
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 DNS Administrator 
( roles/  
)
 Network Administrator 
( roles/  
)
Service agent roles
-  Kubernetes Engine Service Agent 
( roles/)container.serviceAgent 
-  Cloud Data Fusion API Service Agent 
( roles/)datafusion.serviceAgent 
-  Cloud Managed Identities Service Agent 
( roles/)managedidentities.serviceAgent 
-  Managed Kafka Service Agent 
( roles/)managedkafka.serviceAgent 
-  Dataproc Metastore Service Agent 
( roles/)metastore.serviceAgent 
-  Multi-Cluster Service Discovery Service Agent 
( roles/)multiclusterservicediscovery.serviceAgent 
-  Oracle Database@Google Cloud Service Agent 
( roles/)oci.serviceAgent 
-  Service Networking Service Agent 
( roles/)servicenetworking.serviceAgent 
-  VMware Engine Service Agent 
( roles/)vmwareengine.serviceAgent 
-  Cloud Deployment Manager Service Agent 
( roles/)clouddeploymentmanager.serviceAgent 
 dns.managedZones.get 
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Viewer 
( roles/  
)
 Composer Shared VPC Agent 
( roles/  
)
 DNS Administrator 
( roles/  
)
 DNS Reader 
( roles/  
)
 Network Administrator 
( roles/  
)
 Security Auditor 
( roles/  
)
 Support User 
( roles/  
)
Service agent roles
-  Cloud Composer API Service Agent 
( roles/)composer.serviceAgent 
-  Kubernetes Engine Service Agent 
( roles/)container.serviceAgent 
-  Cloud Data Fusion API Service Agent 
( roles/)datafusion.serviceAgent 
-  Cloud Managed Identities Service Agent 
( roles/)managedidentities.serviceAgent 
-  Dataproc Metastore Service Agent 
( roles/)metastore.serviceAgent 
-  Multi-Cluster Service Discovery Service Agent 
( roles/)multiclusterservicediscovery.serviceAgent 
-  Oracle Database@Google Cloud Service Agent 
( roles/)oci.serviceAgent 
-  Service Networking Service Agent 
( roles/)servicenetworking.serviceAgent 
-  VMware Engine Service Agent 
( roles/)vmwareengine.serviceAgent 
-  Cloud Deployment Manager Service Agent 
( roles/)clouddeploymentmanager.serviceAgent 
 dns.managedZones.getIamPolicy 
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Viewer 
( roles/  
)
 DNS Administrator 
( roles/  
)
 Network Administrator 
( roles/  
)
 Security Admin 
( roles/  
)
 Security Auditor 
( roles/  
)
 Security Reviewer 
( roles/  
)
 Support User 
( roles/  
)
Service agent roles
-  Multi-Cluster Service Discovery Service Agent 
( roles/)multiclusterservicediscovery.serviceAgent 
-  Oracle Database@Google Cloud Service Agent 
( roles/)oci.serviceAgent 
-  Service Networking Service Agent 
( roles/)servicenetworking.serviceAgent 
-  VMware Engine Service Agent 
( roles/)vmwareengine.serviceAgent 
-  Kubernetes Engine Service Agent 
( roles/)container.serviceAgent 
 dns.managedZones.list 
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Viewer 
( roles/  
)
 Composer Shared VPC Agent 
( roles/  
)
 DNS Administrator 
( roles/  
)
 DNS Reader 
( roles/  
)
 Network Administrator 
( roles/  
)
 Security Admin 
( roles/  
)
 Security Auditor 
( roles/  
)
 Security Reviewer 
( roles/  
)
 Support User 
( roles/  
)
 Workload Manager Admin 
( roles/  
)
 Workload Manager Deployment Admin 
( roles/  
)
Service agent roles
-  Cloud Deployment Manager Service Agent 
( roles/)clouddeploymentmanager.serviceAgent 
-  Cloud Security Compliance Service Agent 
( roles/)cloudsecuritycompliance.serviceAgent 
-  Cloud Composer API Service Agent 
( roles/)composer.serviceAgent 
-  Kubernetes Engine Service Agent 
( roles/)container.serviceAgent 
-  Cloud Data Fusion API Service Agent 
( roles/)datafusion.serviceAgent 
-  Cloud Managed Identities Service Agent 
( roles/)managedidentities.serviceAgent 
-  Managed Kafka Service Agent 
( roles/)managedkafka.serviceAgent 
-  Dataproc Metastore Service Agent 
( roles/)metastore.serviceAgent 
-  Multi-Cluster Service Discovery Service Agent 
( roles/)multiclusterservicediscovery.serviceAgent 
-  Oracle Database@Google Cloud Service Agent 
( roles/)oci.serviceAgent 
-  Attack Surface Management Scanner Service Agent 
( roles/)securitycenter.attackSurfaceManagementScannerServiceAgent 
-  Service Networking Service Agent 
( roles/)servicenetworking.serviceAgent 
-  VMware Engine Service Agent 
( roles/)vmwareengine.serviceAgent 
-  Audit Manager Auditing Service Agent 
( roles/)auditmanager.serviceAgent 
 dns.managedZones.setIamPolicy 
 
 Owner 
( roles/  
)
 Security Admin 
( roles/  
)
 dns.managedZones.update 
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 DNS Administrator 
( roles/  
)
 Network Administrator 
( roles/  
)
Service agent roles
-  Kubernetes Engine Service Agent 
( roles/)container.serviceAgent 
-  Cloud Managed Identities Service Agent 
( roles/)managedidentities.serviceAgent 
-  Multi-Cluster Service Discovery Service Agent 
( roles/)multiclusterservicediscovery.serviceAgent 
-  Oracle Database@Google Cloud Service Agent 
( roles/)oci.serviceAgent 
-  Service Networking Service Agent 
( roles/)servicenetworking.serviceAgent 
-  VMware Engine Service Agent 
( roles/)vmwareengine.serviceAgent 
-  Cloud Deployment Manager Service Agent 
( roles/)clouddeploymentmanager.serviceAgent 
 dns.  
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Kubernetes Engine Host Service Agent User 
( roles/  
)
 DNS Administrator 
( roles/  
)
 Network Administrator 
( roles/  
)
Service agent roles
-  Multi-Cluster Service Discovery Service Agent 
( roles/)multiclusterservicediscovery.serviceAgent 
-  Oracle Database@Google Cloud Service Agent 
( roles/)oci.serviceAgent 
-  Service Networking Service Agent 
( roles/)servicenetworking.serviceAgent 
-  VMware Engine Service Agent 
( roles/)vmwareengine.serviceAgent 
-  Kubernetes Engine Service Agent 
( roles/)container.serviceAgent 
 dns.  
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Kubernetes Engine Host Service Agent User 
( roles/  
)
 DNS Administrator 
( roles/  
)
 Network Administrator 
( roles/  
)
Service agent roles
-  Cloud Managed Identities Service Agent 
( roles/)managedidentities.serviceAgent 
-  Multi-Cluster Service Discovery Service Agent 
( roles/)multiclusterservicediscovery.serviceAgent 
-  Oracle Database@Google Cloud Service Agent 
( roles/)oci.serviceAgent 
-  Service Networking Service Agent 
( roles/)servicenetworking.serviceAgent 
-  VMware Engine Service Agent 
( roles/)vmwareengine.serviceAgent 
-  Kubernetes Engine Service Agent 
( roles/)container.serviceAgent 
 dns.  
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Kubernetes Engine Host Service Agent User 
( roles/  
)
 DNS Administrator 
( roles/  
)
 Network Administrator 
( roles/  
)
Service agent roles
-  Kubernetes Engine Service Agent 
( roles/)container.serviceAgent 
-  Cloud Data Fusion API Service Agent 
( roles/)datafusion.serviceAgent 
-  Cloud Managed Identities Service Agent 
( roles/)managedidentities.serviceAgent 
-  Managed Kafka Service Agent 
( roles/)managedkafka.serviceAgent 
-  Dataproc Metastore Service Agent 
( roles/)metastore.serviceAgent 
-  Multi-Cluster Service Discovery Service Agent 
( roles/)multiclusterservicediscovery.serviceAgent 
-  Network Connectivity Service Agent 
( roles/)networkconnectivity.serviceAgent 
-  Oracle Database@Google Cloud Service Agent 
( roles/)oci.serviceAgent 
-  Service Networking Service Agent 
( roles/)servicenetworking.serviceAgent 
-  VMware Engine Service Agent 
( roles/)vmwareengine.serviceAgent 
-  Workstations Service Agent 
( roles/)workstations.serviceAgent 
-  Cloud Deployment Manager Service Agent 
( roles/)clouddeploymentmanager.serviceAgent 
 dns.  
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Composer Shared VPC Agent 
( roles/  
)
 DNS Administrator 
( roles/  
)
 DNS Peer 
( roles/  
)
 Network Administrator 
( roles/  
)
Service agent roles
-  Cloud Composer API Service Agent 
( roles/)composer.serviceAgent 
-  Kubernetes Engine Service Agent 
( roles/)container.serviceAgent 
-  Cloud Dataflow Service Agent 
( roles/)dataflow.serviceAgent 
-  Cloud Data Fusion API Service Agent 
( roles/)datafusion.serviceAgent 
-  Eventarc Service Agent 
( roles/)eventarc.serviceAgent 
-  Managed Flink Service Agent 
( roles/)managedflink.serviceAgent 
-  Managed Kafka Service Agent 
( roles/)managedkafka.serviceAgent 
-  Dataproc Metastore Service Agent 
( roles/)metastore.serviceAgent 
-  Multi-Cluster Service Discovery Service Agent 
( roles/)multiclusterservicediscovery.serviceAgent 
-  Oracle Database@Google Cloud Service Agent 
( roles/)oci.serviceAgent 
-  Service Networking Service Agent 
( roles/)servicenetworking.serviceAgent 
-  VMware Engine Service Agent 
( roles/)vmwareengine.serviceAgent 
-  Workstations Service Agent 
( roles/)workstations.serviceAgent 
-  Cloud Deployment Manager Service Agent 
( roles/)clouddeploymentmanager.serviceAgent 
 dns.networks.useHealthSignals 
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 DNS Administrator 
( roles/  
)
 Network Administrator 
( roles/  
)
Service agent roles
-  Multi-Cluster Service Discovery Service Agent 
( roles/)multiclusterservicediscovery.serviceAgent 
-  Oracle Database@Google Cloud Service Agent 
( roles/)oci.serviceAgent 
-  Service Networking Service Agent 
( roles/)servicenetworking.serviceAgent 
-  VMware Engine Service Agent 
( roles/)vmwareengine.serviceAgent 
-  Kubernetes Engine Service Agent 
( roles/)container.serviceAgent 
 dns.policies.create 
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 DNS Administrator 
( roles/  
)
 Network Administrator 
( roles/  
)
Service agent roles
-  Cloud Managed Identities Service Agent 
( roles/)managedidentities.serviceAgent 
-  Multi-Cluster Service Discovery Service Agent 
( roles/)multiclusterservicediscovery.serviceAgent 
-  Oracle Database@Google Cloud Service Agent 
( roles/)oci.serviceAgent 
-  Service Networking Service Agent 
( roles/)servicenetworking.serviceAgent 
-  VMware Engine Service Agent 
( roles/)vmwareengine.serviceAgent 
-  Kubernetes Engine Service Agent 
( roles/)container.serviceAgent 
 dns.policies.delete 
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 DNS Administrator 
( roles/  
)
 Network Administrator 
( roles/  
)
Service agent roles
-  Kubernetes Engine Service Agent 
( roles/)container.serviceAgent 
-  Cloud Managed Identities Service Agent 
( roles/)managedidentities.serviceAgent 
-  Multi-Cluster Service Discovery Service Agent 
( roles/)multiclusterservicediscovery.serviceAgent 
-  Oracle Database@Google Cloud Service Agent 
( roles/)oci.serviceAgent 
-  Service Networking Service Agent 
( roles/)servicenetworking.serviceAgent 
-  VMware Engine Service Agent 
( roles/)vmwareengine.serviceAgent 
-  Cloud Deployment Manager Service Agent 
( roles/)clouddeploymentmanager.serviceAgent 
 dns.policies.get 
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Viewer 
( roles/  
)
 DNS Administrator 
( roles/  
)
 DNS Reader 
( roles/  
)
 Network Administrator 
( roles/  
)
 Security Auditor 
( roles/  
)
 Support User 
( roles/  
)
Service agent roles
-  Kubernetes Engine Service Agent 
( roles/)container.serviceAgent 
-  Cloud Managed Identities Service Agent 
( roles/)managedidentities.serviceAgent 
-  Multi-Cluster Service Discovery Service Agent 
( roles/)multiclusterservicediscovery.serviceAgent 
-  Oracle Database@Google Cloud Service Agent 
( roles/)oci.serviceAgent 
-  Service Networking Service Agent 
( roles/)servicenetworking.serviceAgent 
-  VMware Engine Service Agent 
( roles/)vmwareengine.serviceAgent 
-  Cloud Deployment Manager Service Agent 
( roles/)clouddeploymentmanager.serviceAgent 
 dns.policies.list 
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Viewer 
( roles/  
)
 DNS Administrator 
( roles/  
)
 DNS Reader 
( roles/  
)
 Network Administrator 
( roles/  
)
 Security Admin 
( roles/  
)
 Security Auditor 
( roles/  
)
 Security Reviewer 
( roles/  
)
 Support User 
( roles/  
)
Service agent roles
-  Cloud Managed Identities Service Agent 
( roles/)managedidentities.serviceAgent 
-  Multi-Cluster Service Discovery Service Agent 
( roles/)multiclusterservicediscovery.serviceAgent 
-  Oracle Database@Google Cloud Service Agent 
( roles/)oci.serviceAgent 
-  Service Networking Service Agent 
( roles/)servicenetworking.serviceAgent 
-  VMware Engine Service Agent 
( roles/)vmwareengine.serviceAgent 
-  Kubernetes Engine Service Agent 
( roles/)container.serviceAgent 
 dns.policies.update 
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 DNS Administrator 
( roles/  
)
 Network Administrator 
( roles/  
)
Service agent roles
-  Cloud Managed Identities Service Agent 
( roles/)managedidentities.serviceAgent 
-  Multi-Cluster Service Discovery Service Agent 
( roles/)multiclusterservicediscovery.serviceAgent 
-  Oracle Database@Google Cloud Service Agent 
( roles/)oci.serviceAgent 
-  Service Networking Service Agent 
( roles/)servicenetworking.serviceAgent 
-  VMware Engine Service Agent 
( roles/)vmwareengine.serviceAgent 
-  Kubernetes Engine Service Agent 
( roles/)container.serviceAgent 
 dns.projects.get 
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Viewer 
( roles/  
)
 DNS Administrator 
( roles/  
)
 DNS Reader 
( roles/  
)
 Network Administrator 
( roles/  
)
 Security Auditor 
( roles/  
)
 Support User 
( roles/  
)
Service agent roles
-  Cloud Managed Identities Service Agent 
( roles/)managedidentities.serviceAgent 
-  Multi-Cluster Service Discovery Service Agent 
( roles/)multiclusterservicediscovery.serviceAgent 
-  Oracle Database@Google Cloud Service Agent 
( roles/)oci.serviceAgent 
-  Service Networking Service Agent 
( roles/)servicenetworking.serviceAgent 
-  VMware Engine Service Agent 
( roles/)vmwareengine.serviceAgent 
-  Kubernetes Engine Service Agent 
( roles/)container.serviceAgent 
 dns.resourceRecordSets.create 
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 DNS Administrator 
( roles/  
)
 Network Administrator 
( roles/  
)
Service agent roles
-  Kubernetes Engine Service Agent 
( roles/)container.serviceAgent 
-  Cloud Managed Identities Service Agent 
( roles/)managedidentities.serviceAgent 
-  Managed Kafka Service Agent 
( roles/)managedkafka.serviceAgent 
-  Dataproc Metastore Service Agent 
( roles/)metastore.serviceAgent 
-  Multi-Cluster Service Discovery Service Agent 
( roles/)multiclusterservicediscovery.serviceAgent 
-  Oracle Database@Google Cloud Service Agent 
( roles/)oci.serviceAgent 
-  Service Networking Service Agent 
( roles/)servicenetworking.serviceAgent 
-  VMware Engine Service Agent 
( roles/)vmwareengine.serviceAgent 
-  Cloud Deployment Manager Service Agent 
( roles/)clouddeploymentmanager.serviceAgent 
 dns.resourceRecordSets.delete 
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 DNS Administrator 
( roles/  
)
 Network Administrator 
( roles/  
)
Service agent roles
-  Kubernetes Engine Service Agent 
( roles/)container.serviceAgent 
-  Cloud Managed Identities Service Agent 
( roles/)managedidentities.serviceAgent 
-  Managed Kafka Service Agent 
( roles/)managedkafka.serviceAgent 
-  Dataproc Metastore Service Agent 
( roles/)metastore.serviceAgent 
-  Multi-Cluster Service Discovery Service Agent 
( roles/)multiclusterservicediscovery.serviceAgent 
-  Oracle Database@Google Cloud Service Agent 
( roles/)oci.serviceAgent 
-  Service Networking Service Agent 
( roles/)servicenetworking.serviceAgent 
-  VMware Engine Service Agent 
( roles/)vmwareengine.serviceAgent 
-  Cloud Deployment Manager Service Agent 
( roles/)clouddeploymentmanager.serviceAgent 
 dns.resourceRecordSets.get 
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Viewer 
( roles/  
)
 DNS Administrator 
( roles/  
)
 DNS Reader 
( roles/  
)
 Network Administrator 
( roles/  
)
 Security Auditor 
( roles/  
)
 Support User 
( roles/  
)
Service agent roles
-  Cloud Managed Identities Service Agent 
( roles/)managedidentities.serviceAgent 
-  Dataproc Metastore Service Agent 
( roles/)metastore.serviceAgent 
-  Multi-Cluster Service Discovery Service Agent 
( roles/)multiclusterservicediscovery.serviceAgent 
-  Oracle Database@Google Cloud Service Agent 
( roles/)oci.serviceAgent 
-  Service Networking Service Agent 
( roles/)servicenetworking.serviceAgent 
-  VMware Engine Service Agent 
( roles/)vmwareengine.serviceAgent 
-  Kubernetes Engine Service Agent 
( roles/)container.serviceAgent 
 dns.resourceRecordSets.list 
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Viewer 
( roles/  
)
 DNS Administrator 
( roles/  
)
 DNS Reader 
( roles/  
)
 Network Administrator 
( roles/  
)
 Security Admin 
( roles/  
)
 Security Auditor 
( roles/  
)
 Security Reviewer 
( roles/  
)
 Support User 
( roles/  
)
Service agent roles
-  Kubernetes Engine Service Agent 
( roles/)container.serviceAgent 
-  Cloud Managed Identities Service Agent 
( roles/)managedidentities.serviceAgent 
-  Managed Kafka Service Agent 
( roles/)managedkafka.serviceAgent 
-  Dataproc Metastore Service Agent 
( roles/)metastore.serviceAgent 
-  Multi-Cluster Service Discovery Service Agent 
( roles/)multiclusterservicediscovery.serviceAgent 
-  Oracle Database@Google Cloud Service Agent 
( roles/)oci.serviceAgent 
-  Attack Surface Management Scanner Service Agent 
( roles/)securitycenter.attackSurfaceManagementScannerServiceAgent 
-  Service Networking Service Agent 
( roles/)servicenetworking.serviceAgent 
-  VMware Engine Service Agent 
( roles/)vmwareengine.serviceAgent 
-  Cloud Deployment Manager Service Agent 
( roles/)clouddeploymentmanager.serviceAgent 
 dns.resourceRecordSets.update 
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 DNS Administrator 
( roles/  
)
 Network Administrator 
( roles/  
)
Service agent roles
-  Kubernetes Engine Service Agent 
( roles/)container.serviceAgent 
-  Cloud Managed Identities Service Agent 
( roles/)managedidentities.serviceAgent 
-  Managed Kafka Service Agent 
( roles/)managedkafka.serviceAgent 
-  Dataproc Metastore Service Agent 
( roles/)metastore.serviceAgent 
-  Multi-Cluster Service Discovery Service Agent 
( roles/)multiclusterservicediscovery.serviceAgent 
-  Oracle Database@Google Cloud Service Agent 
( roles/)oci.serviceAgent 
-  Service Networking Service Agent 
( roles/)servicenetworking.serviceAgent 
-  VMware Engine Service Agent 
( roles/)vmwareengine.serviceAgent 
-  Cloud Deployment Manager Service Agent 
( roles/)clouddeploymentmanager.serviceAgent 
 dns.responsePolicies.create 
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Kubernetes Engine Host Service Agent User 
( roles/  
)
 DNS Administrator 
( roles/  
)
 Network Administrator 
( roles/  
)
Service agent roles
-  Cloud Managed Identities Service Agent 
( roles/)managedidentities.serviceAgent 
-  Multi-Cluster Service Discovery Service Agent 
( roles/)multiclusterservicediscovery.serviceAgent 
-  Oracle Database@Google Cloud Service Agent 
( roles/)oci.serviceAgent 
-  Service Networking Service Agent 
( roles/)servicenetworking.serviceAgent 
-  VMware Engine Service Agent 
( roles/)vmwareengine.serviceAgent 
-  Kubernetes Engine Service Agent 
( roles/)container.serviceAgent 
 dns.responsePolicies.delete 
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Kubernetes Engine Host Service Agent User 
( roles/  
)
 DNS Administrator 
( roles/  
)
 Network Administrator 
( roles/  
)
Service agent roles
-  Cloud Managed Identities Service Agent 
( roles/)managedidentities.serviceAgent 
-  Multi-Cluster Service Discovery Service Agent 
( roles/)multiclusterservicediscovery.serviceAgent 
-  Oracle Database@Google Cloud Service Agent 
( roles/)oci.serviceAgent 
-  Service Networking Service Agent 
( roles/)servicenetworking.serviceAgent 
-  VMware Engine Service Agent 
( roles/)vmwareengine.serviceAgent 
-  Kubernetes Engine Service Agent 
( roles/)container.serviceAgent 
 dns.responsePolicies.get 
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Viewer 
( roles/  
)
 Kubernetes Engine Host Service Agent User 
( roles/  
)
 DNS Administrator 
( roles/  
)
 DNS Reader 
( roles/  
)
 Network Administrator 
( roles/  
)
 Security Auditor 
( roles/  
)
 Support User 
( roles/  
)
Service agent roles
-  Cloud Managed Identities Service Agent 
( roles/)managedidentities.serviceAgent 
-  Multi-Cluster Service Discovery Service Agent 
( roles/)multiclusterservicediscovery.serviceAgent 
-  Oracle Database@Google Cloud Service Agent 
( roles/)oci.serviceAgent 
-  Service Networking Service Agent 
( roles/)servicenetworking.serviceAgent 
-  VMware Engine Service Agent 
( roles/)vmwareengine.serviceAgent 
-  Kubernetes Engine Service Agent 
( roles/)container.serviceAgent 
 dns.responsePolicies.list 
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Viewer 
( roles/  
)
 Kubernetes Engine Host Service Agent User 
( roles/  
)
 DNS Administrator 
( roles/  
)
 DNS Reader 
( roles/  
)
 Network Administrator 
( roles/  
)
 Security Admin 
( roles/  
)
 Security Auditor 
( roles/  
)
 Security Reviewer 
( roles/  
)
 Support User 
( roles/  
)
Service agent roles
-  Cloud Managed Identities Service Agent 
( roles/)managedidentities.serviceAgent 
-  Multi-Cluster Service Discovery Service Agent 
( roles/)multiclusterservicediscovery.serviceAgent 
-  Oracle Database@Google Cloud Service Agent 
( roles/)oci.serviceAgent 
-  Service Networking Service Agent 
( roles/)servicenetworking.serviceAgent 
-  VMware Engine Service Agent 
( roles/)vmwareengine.serviceAgent 
-  Kubernetes Engine Service Agent 
( roles/)container.serviceAgent 
 dns.responsePolicies.update 
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Kubernetes Engine Host Service Agent User 
( roles/  
)
 DNS Administrator 
( roles/  
)
 Network Administrator 
( roles/  
)
Service agent roles
-  Cloud Managed Identities Service Agent 
( roles/)managedidentities.serviceAgent 
-  Multi-Cluster Service Discovery Service Agent 
( roles/)multiclusterservicediscovery.serviceAgent 
-  Oracle Database@Google Cloud Service Agent 
( roles/)oci.serviceAgent 
-  Service Networking Service Agent 
( roles/)servicenetworking.serviceAgent 
-  VMware Engine Service Agent 
( roles/)vmwareengine.serviceAgent 
-  Kubernetes Engine Service Agent 
( roles/)container.serviceAgent 
 dns.responsePolicyRules.create 
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Kubernetes Engine Host Service Agent User 
( roles/  
)
 DNS Administrator 
( roles/  
)
 Network Administrator 
( roles/  
)
Service agent roles
-  Cloud Managed Identities Service Agent 
( roles/)managedidentities.serviceAgent 
-  Multi-Cluster Service Discovery Service Agent 
( roles/)multiclusterservicediscovery.serviceAgent 
-  Oracle Database@Google Cloud Service Agent 
( roles/)oci.serviceAgent 
-  Service Networking Service Agent 
( roles/)servicenetworking.serviceAgent 
-  VMware Engine Service Agent 
( roles/)vmwareengine.serviceAgent 
-  Kubernetes Engine Service Agent 
( roles/)container.serviceAgent 
 dns.responsePolicyRules.delete 
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Kubernetes Engine Host Service Agent User 
( roles/  
)
 DNS Administrator 
( roles/  
)
 Network Administrator 
( roles/  
)
Service agent roles
-  Cloud Managed Identities Service Agent 
( roles/)managedidentities.serviceAgent 
-  Multi-Cluster Service Discovery Service Agent 
( roles/)multiclusterservicediscovery.serviceAgent 
-  Oracle Database@Google Cloud Service Agent 
( roles/)oci.serviceAgent 
-  Service Networking Service Agent 
( roles/)servicenetworking.serviceAgent 
-  VMware Engine Service Agent 
( roles/)vmwareengine.serviceAgent 
-  Kubernetes Engine Service Agent 
( roles/)container.serviceAgent 
 dns.responsePolicyRules.get 
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Viewer 
( roles/  
)
 Kubernetes Engine Host Service Agent User 
( roles/  
)
 DNS Administrator 
( roles/  
)
 DNS Reader 
( roles/  
)
 Network Administrator 
( roles/  
)
 Security Auditor 
( roles/  
)
 Support User 
( roles/  
)
Service agent roles
-  Cloud Managed Identities Service Agent 
( roles/)managedidentities.serviceAgent 
-  Multi-Cluster Service Discovery Service Agent 
( roles/)multiclusterservicediscovery.serviceAgent 
-  Oracle Database@Google Cloud Service Agent 
( roles/)oci.serviceAgent 
-  Service Networking Service Agent 
( roles/)servicenetworking.serviceAgent 
-  VMware Engine Service Agent 
( roles/)vmwareengine.serviceAgent 
-  Kubernetes Engine Service Agent 
( roles/)container.serviceAgent 
 dns.responsePolicyRules.list 
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Viewer 
( roles/  
)
 Kubernetes Engine Host Service Agent User 
( roles/  
)
 DNS Administrator 
( roles/  
)
 DNS Reader 
( roles/  
)
 Network Administrator 
( roles/  
)
 Security Admin 
( roles/  
)
 Security Auditor 
( roles/  
)
 Security Reviewer 
( roles/  
)
 Support User 
( roles/  
)
Service agent roles
-  Cloud Managed Identities Service Agent 
( roles/)managedidentities.serviceAgent 
-  Multi-Cluster Service Discovery Service Agent 
( roles/)multiclusterservicediscovery.serviceAgent 
-  Oracle Database@Google Cloud Service Agent 
( roles/)oci.serviceAgent 
-  Service Networking Service Agent 
( roles/)servicenetworking.serviceAgent 
-  VMware Engine Service Agent 
( roles/)vmwareengine.serviceAgent 
-  Kubernetes Engine Service Agent 
( roles/)container.serviceAgent 
 dns.responsePolicyRules.update 
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Kubernetes Engine Host Service Agent User 
( roles/  
)
 DNS Administrator 
( roles/  
)
 Network Administrator 
( roles/  
)
Service agent roles
-  Cloud Managed Identities Service Agent 
( roles/)managedidentities.serviceAgent 
-  Multi-Cluster Service Discovery Service Agent 
( roles/)multiclusterservicediscovery.serviceAgent 
-  Oracle Database@Google Cloud Service Agent 
( roles/)oci.serviceAgent 
-  Service Networking Service Agent 
( roles/)servicenetworking.serviceAgent 
-  VMware Engine Service Agent 
( roles/)vmwareengine.serviceAgent 
-  Kubernetes Engine Service Agent 
( roles/)container.serviceAgent 

