This page lists the IAM roles and permissions for Filestore. To search through all roles and permissions, see the role and permission index .
Filestore roles
Cloud Filestore Editor Beta
( roles/  
)
Read-write access to Filestore instances and related resources.
  file.* 
 
-  file.backups.create
-  file.backups.createTagBinding
-  file.backups.delete
-  file.backups.deleteTagBinding
-  file.backups.get
-  file.backups.list
-  file.backups.listEffectiveTags
-  file.backups.listTagBindings
-  file.backups.update
-  file.instances.create
-  file.instances. createTagBinding 
-  file.instances.delete
-  file.instances. deleteTagBinding 
-  file.instances.get
-  file.instances.list
-  file.instances. listEffectiveTags 
-  file.instances.listTagBindings
-  file.instances.restore
-  file.instances.revert
-  file.instances.update
-  file.locations.get
-  file.locations.list
-  file.operations.cancel
-  file.operations.delete
-  file.operations.get
-  file.operations.list
-  file.snapshots. createTagBinding 
-  file.snapshots. deleteTagBinding 
-  file.snapshots. listEffectiveTags 
-  file.snapshots.listTagBindings
Cloud Filestore Service Agent
( roles/  
)
Gives Cloud Filestore service account access to managed resources.
 compute.globalOperations.get 
 compute.networks.addPeering 
 compute.networks.get 
 compute.networks.removePeering 
 compute.networks.update 
 compute.networks.updatePeering 
 compute.routes.list 
 monitoring.  
 monitoring.  
 monitoring.  
  monitoring.  
 
-  monitoring.monitoredResourceDescriptors. get 
-  monitoring.monitoredResourceDescriptors. list 
 monitoring.timeSeries.create 
 resourcemanager.projects.get 
 resourcemanager.projects.list 
 telemetry.metrics.write 
Cloud Filestore Viewer Beta
( roles/  
)
Read-only access to Filestore instances and related resources.
 file.backups.get 
 file.backups.list 
 file.backups.listEffectiveTags 
 file.backups.listTagBindings 
 file.instances.get 
 file.instances.list 
 file.  
 file.instances.listTagBindings 
  file.locations.* 
 
-  file.locations.get
-  file.locations.list
 file.operations.get 
 file.operations.list 
 file.  
 file.snapshots.listTagBindings 
Filestore permissions
 file.backups.create 
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Cloud Filestore Editor 
( roles/  
)
Service agent roles
-  Kubernetes Engine Service Agent 
( roles/)container.serviceAgent 
-  Backup and DR Service Agent 
( roles/)backupdr.serviceAgent 
 file.backups.createTagBinding 
 
 Owner 
( roles/  
)
 DLP Organization Data Profiles Driver 
( roles/  
)
 DLP Project Data Profiles Driver 
( roles/  
)
 Cloud Filestore Editor 
( roles/  
)
 Tag User 
( roles/  
)
Service agent roles
-  Kubernetes Engine Service Agent 
( roles/)container.serviceAgent 
 file.backups.delete 
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Cloud Filestore Editor 
( roles/  
)
Service agent roles
-  Kubernetes Engine Service Agent 
( roles/)container.serviceAgent 
 file.backups.deleteTagBinding 
 
 Owner 
( roles/  
)
 DLP Organization Data Profiles Driver 
( roles/  
)
 DLP Project Data Profiles Driver 
( roles/  
)
 Cloud Filestore Editor 
( roles/  
)
 Tag User 
( roles/  
)
Service agent roles
-  Kubernetes Engine Service Agent 
( roles/)container.serviceAgent 
 file.backups.get 
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Viewer 
( roles/  
)
 Cloud Filestore Editor 
( roles/  
)
 Cloud Filestore Viewer 
( roles/  
)
 Support User 
( roles/  
)
Service agent roles
-  Kubernetes Engine Service Agent 
( roles/)container.serviceAgent 
 file.backups.list 
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Viewer 
( roles/  
)
 Cloud Filestore Editor 
( roles/  
)
 Cloud Filestore Viewer 
( roles/  
)
 Security Admin 
( roles/  
)
 Security Auditor 
( roles/  
)
 Security Reviewer 
( roles/  
)
 Support User 
( roles/  
)
Service agent roles
-  Kubernetes Engine Service Agent 
( roles/)container.serviceAgent 
 file.backups.listEffectiveTags 
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Viewer 
( roles/  
)
 DLP Organization Data Profiles Driver 
( roles/  
)
 DLP Project Data Profiles Driver 
( roles/  
)
 Cloud Filestore Editor 
( roles/  
)
 Cloud Filestore Viewer 
( roles/  
)
 Security Auditor 
( roles/  
)
 Support User 
( roles/  
)
 Tag User 
( roles/  
)
 Tag Viewer 
( roles/  
)
Service agent roles
-  Kubernetes Engine Service Agent 
( roles/)container.serviceAgent 
 file.backups.listTagBindings 
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Viewer 
( roles/  
)
 DLP Organization Data Profiles Driver 
( roles/  
)
 DLP Project Data Profiles Driver 
( roles/  
)
 Cloud Filestore Editor 
( roles/  
)
 Cloud Filestore Viewer 
( roles/  
)
 Security Auditor 
( roles/  
)
 Support User 
( roles/  
)
 Tag User 
( roles/  
)
 Tag Viewer 
( roles/  
)
Service agent roles
-  Kubernetes Engine Service Agent 
( roles/)container.serviceAgent 
 file.backups.update 
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Cloud Filestore Editor 
( roles/  
)
Service agent roles
-  Kubernetes Engine Service Agent 
( roles/)container.serviceAgent 
 file.instances.create 
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Cloud Filestore Editor 
( roles/  
)
Service agent roles
-  Kubernetes Engine Service Agent 
( roles/)container.serviceAgent 
-  Cloud Deployment Manager Service Agent 
( roles/)clouddeploymentmanager.serviceAgent 
 file.  
 
 Owner 
( roles/  
)
 DLP Organization Data Profiles Driver 
( roles/  
)
 DLP Project Data Profiles Driver 
( roles/  
)
 Cloud Filestore Editor 
( roles/  
)
 Tag User 
( roles/  
)
Service agent roles
-  Kubernetes Engine Service Agent 
( roles/)container.serviceAgent 
 file.instances.delete 
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Cloud Filestore Editor 
( roles/  
)
Service agent roles
-  Kubernetes Engine Service Agent 
( roles/)container.serviceAgent 
-  Cloud Deployment Manager Service Agent 
( roles/)clouddeploymentmanager.serviceAgent 
 file.  
 
 Owner 
( roles/  
)
 DLP Organization Data Profiles Driver 
( roles/  
)
 DLP Project Data Profiles Driver 
( roles/  
)
 Cloud Filestore Editor 
( roles/  
)
 Tag User 
( roles/  
)
Service agent roles
-  Kubernetes Engine Service Agent 
( roles/)container.serviceAgent 
 file.instances.get 
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Viewer 
( roles/  
)
 Cloud Filestore Editor 
( roles/  
)
 Cloud Filestore Viewer 
( roles/  
)
 Support User 
( roles/  
)
Service agent roles
-  Cloud Deployment Manager Service Agent 
( roles/)clouddeploymentmanager.serviceAgent 
-  Kubernetes Engine Service Agent 
( roles/)container.serviceAgent 
-  Backup and DR Service Agent 
( roles/)backupdr.serviceAgent 
 file.instances.list 
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Viewer 
( roles/  
)
 Cloud Filestore Editor 
( roles/  
)
 Cloud Filestore Viewer 
( roles/  
)
 Security Admin 
( roles/  
)
 Security Auditor 
( roles/  
)
 Security Reviewer 
( roles/  
)
 Support User 
( roles/  
)
Service agent roles
-  Kubernetes Engine Service Agent 
( roles/)container.serviceAgent 
 file.  
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Viewer 
( roles/  
)
 DLP Organization Data Profiles Driver 
( roles/  
)
 DLP Project Data Profiles Driver 
( roles/  
)
 Cloud Filestore Editor 
( roles/  
)
 Cloud Filestore Viewer 
( roles/  
)
 Security Auditor 
( roles/  
)
 Support User 
( roles/  
)
 Tag User 
( roles/  
)
 Tag Viewer 
( roles/  
)
Service agent roles
-  Kubernetes Engine Service Agent 
( roles/)container.serviceAgent 
 file.instances.listTagBindings 
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Viewer 
( roles/  
)
 DLP Organization Data Profiles Driver 
( roles/  
)
 DLP Project Data Profiles Driver 
( roles/  
)
 Cloud Filestore Editor 
( roles/  
)
 Cloud Filestore Viewer 
( roles/  
)
 Security Auditor 
( roles/  
)
 Support User 
( roles/  
)
 Tag User 
( roles/  
)
 Tag Viewer 
( roles/  
)
Service agent roles
-  Kubernetes Engine Service Agent 
( roles/)container.serviceAgent 
 file.instances.restore 
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Cloud Filestore Editor 
( roles/  
)
Service agent roles
-  Kubernetes Engine Service Agent 
( roles/)container.serviceAgent 
 file.instances.revert 
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Cloud Filestore Editor 
( roles/  
)
Service agent roles
-  Kubernetes Engine Service Agent 
( roles/)container.serviceAgent 
 file.instances.update 
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Cloud Filestore Editor 
( roles/  
)
Service agent roles
-  Kubernetes Engine Service Agent 
( roles/)container.serviceAgent 
-  Cloud Deployment Manager Service Agent 
( roles/)clouddeploymentmanager.serviceAgent 
 file.locations.get 
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Viewer 
( roles/  
)
 Cloud Filestore Editor 
( roles/  
)
 Cloud Filestore Viewer 
( roles/  
)
 Support User 
( roles/  
)
Service agent roles
-  Kubernetes Engine Service Agent 
( roles/)container.serviceAgent 
 file.locations.list 
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Viewer 
( roles/  
)
 Cloud Filestore Editor 
( roles/  
)
 Cloud Filestore Viewer 
( roles/  
)
 Security Admin 
( roles/  
)
 Security Auditor 
( roles/  
)
 Security Reviewer 
( roles/  
)
 Support User 
( roles/  
)
Service agent roles
-  Kubernetes Engine Service Agent 
( roles/)container.serviceAgent 
 file.operations.cancel 
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Cloud Filestore Editor 
( roles/  
)
Service agent roles
-  Kubernetes Engine Service Agent 
( roles/)container.serviceAgent 
 file.operations.delete 
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Cloud Filestore Editor 
( roles/  
)
Service agent roles
-  Kubernetes Engine Service Agent 
( roles/)container.serviceAgent 
 file.operations.get 
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Viewer 
( roles/  
)
 Cloud Filestore Editor 
( roles/  
)
 Cloud Filestore Viewer 
( roles/  
)
 Support User 
( roles/  
)
Service agent roles
-  Kubernetes Engine Service Agent 
( roles/)container.serviceAgent 
-  Cloud Deployment Manager Service Agent 
( roles/)clouddeploymentmanager.serviceAgent 
 file.operations.list 
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Viewer 
( roles/  
)
 Cloud Filestore Editor 
( roles/  
)
 Cloud Filestore Viewer 
( roles/  
)
 Security Admin 
( roles/  
)
 Security Auditor 
( roles/  
)
 Security Reviewer 
( roles/  
)
 Support User 
( roles/  
)
Service agent roles
-  Kubernetes Engine Service Agent 
( roles/)container.serviceAgent 
 file.  
 
 Owner 
( roles/  
)
 DLP Organization Data Profiles Driver 
( roles/  
)
 DLP Project Data Profiles Driver 
( roles/  
)
 Cloud Filestore Editor 
( roles/  
)
 Tag User 
( roles/  
)
Service agent roles
-  Kubernetes Engine Service Agent 
( roles/)container.serviceAgent 
 file.  
 
 Owner 
( roles/  
)
 DLP Organization Data Profiles Driver 
( roles/  
)
 DLP Project Data Profiles Driver 
( roles/  
)
 Cloud Filestore Editor 
( roles/  
)
 Tag User 
( roles/  
)
Service agent roles
-  Kubernetes Engine Service Agent 
( roles/)container.serviceAgent 
 file.  
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Viewer 
( roles/  
)
 DLP Organization Data Profiles Driver 
( roles/  
)
 DLP Project Data Profiles Driver 
( roles/  
)
 Cloud Filestore Editor 
( roles/  
)
 Cloud Filestore Viewer 
( roles/  
)
 Security Auditor 
( roles/  
)
 Support User 
( roles/  
)
 Tag User 
( roles/  
)
 Tag Viewer 
( roles/  
)
Service agent roles
-  Kubernetes Engine Service Agent 
( roles/)container.serviceAgent 
 file.snapshots.listTagBindings 
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Viewer 
( roles/  
)
 DLP Organization Data Profiles Driver 
( roles/  
)
 DLP Project Data Profiles Driver 
( roles/  
)
 Cloud Filestore Editor 
( roles/  
)
 Cloud Filestore Viewer 
( roles/  
)
 Security Auditor 
( roles/  
)
 Support User 
( roles/  
)
 Tag User 
( roles/  
)
 Tag Viewer 
( roles/  
)
Service agent roles
-  Kubernetes Engine Service Agent 
( roles/)container.serviceAgent 

