This page lists the IAM roles and permissions for GKE Hub. To search through all roles and permissions, see the role and permission index .
GKE Hub roles
Fleet Admin (formerly GKE Hub Admin)
( roles/
)
Full access to Fleet resources.
gkehub.features.*
-
gkehub.features.create
-
gkehub.features.delete
-
gkehub.features.get
-
gkehub.features.getIamPolicy
-
gkehub.features.list
-
gkehub.features.setIamPolicy
-
gkehub.features.update
gkehub.fleet.*
-
gkehub.fleet.create
-
gkehub.fleet.createFreeTrial
-
gkehub.fleet.delete
-
gkehub.fleet.get
-
gkehub.fleet.getFreeTrial
-
gkehub.fleet.update
-
gkehub.fleet.updateFreeTrial
gkehub.locations.*
-
gkehub.locations.get
-
gkehub.locations.list
gkehub.membershipbindings.*
-
gkehub.
membershipbindings. create -
gkehub.
membershipbindings. delete -
gkehub.membershipbindings.get
-
gkehub.membershipbindings.list
-
gkehub.
membershipbindings. update
gkehub.membershipfeatures.*
-
gkehub.
membershipfeatures. create -
gkehub.
membershipfeatures. delete -
gkehub.membershipfeatures.get
-
gkehub.membershipfeatures.list
-
gkehub.
membershipfeatures. update
gkehub.memberships.*
-
gkehub.memberships.create
-
gkehub.memberships.delete
-
gkehub.
memberships. generateConnectManifest -
gkehub.memberships.get
-
gkehub.
memberships. getIamPolicy -
gkehub.memberships.list
-
gkehub.
memberships. setIamPolicy -
gkehub.memberships.update
gkehub.namespaces.*
-
gkehub.namespaces.create
-
gkehub.namespaces.delete
-
gkehub.namespaces.get
-
gkehub.namespaces.list
-
gkehub.namespaces.update
gkehub.operations.*
-
gkehub.operations.cancel
-
gkehub.operations.delete
-
gkehub.operations.get
-
gkehub.operations.list
gkehub.rbacrolebindings.*
-
gkehub.rbacrolebindings.create
-
gkehub.rbacrolebindings.delete
-
gkehub.rbacrolebindings.get
-
gkehub.rbacrolebindings.list
-
gkehub.rbacrolebindings.update
gkehub.scopes.*
-
gkehub.scopes.create
-
gkehub.scopes.delete
-
gkehub.scopes.get
-
gkehub.scopes.getIamPolicy
-
gkehub.scopes.list
-
gkehub.
scopes. listBoundMemberships -
gkehub.scopes.setIamPolicy
-
gkehub.scopes.update
resourcemanager.projects.get
resourcemanager.projects.list
GKE Connect Agent
( roles/
)
Ability to set up GKE Connect between external clusters and Google.
gkehub.endpoints.connect
GKE Hub Cross Project Service Agent
( roles/
)
Gives the GKE Hub service agent permission to manage the project for cross-project fleet registration.
resourcemanager.
resourcemanager.
Fleet Editor (formerly GKE Hub Editor)
( roles/
)
Edit access to Fleet resources.
gkehub.features.create
gkehub.features.delete
gkehub.features.get
gkehub.features.getIamPolicy
gkehub.features.list
gkehub.features.update
gkehub.fleet.*
-
gkehub.fleet.create
-
gkehub.fleet.createFreeTrial
-
gkehub.fleet.delete
-
gkehub.fleet.get
-
gkehub.fleet.getFreeTrial
-
gkehub.fleet.update
-
gkehub.fleet.updateFreeTrial
gkehub.locations.*
-
gkehub.locations.get
-
gkehub.locations.list
gkehub.membershipbindings.*
-
gkehub.
membershipbindings. create -
gkehub.
membershipbindings. delete -
gkehub.membershipbindings.get
-
gkehub.membershipbindings.list
-
gkehub.
membershipbindings. update
gkehub.membershipfeatures.*
-
gkehub.
membershipfeatures. create -
gkehub.
membershipfeatures. delete -
gkehub.membershipfeatures.get
-
gkehub.membershipfeatures.list
-
gkehub.
membershipfeatures. update
gkehub.memberships.create
gkehub.memberships.delete
gkehub.
gkehub.memberships.get
gkehub.
gkehub.memberships.list
gkehub.memberships.update
gkehub.namespaces.*
-
gkehub.namespaces.create
-
gkehub.namespaces.delete
-
gkehub.namespaces.get
-
gkehub.namespaces.list
-
gkehub.namespaces.update
gkehub.operations.*
-
gkehub.operations.cancel
-
gkehub.operations.delete
-
gkehub.operations.get
-
gkehub.operations.list
gkehub.rbacrolebindings.*
-
gkehub.rbacrolebindings.create
-
gkehub.rbacrolebindings.delete
-
gkehub.rbacrolebindings.get
-
gkehub.rbacrolebindings.list
-
gkehub.rbacrolebindings.update
gkehub.scopes.create
gkehub.scopes.delete
gkehub.scopes.get
gkehub.scopes.getIamPolicy
gkehub.scopes.list
gkehub.
gkehub.scopes.update
resourcemanager.projects.get
resourcemanager.projects.list
Connect Gateway Admin
( roles/
)
Full access to Connect Gateway.
gkehub.gateway.*
-
gkehub.gateway.delete
-
gkehub.
gateway. generateCredentials -
gkehub.gateway.get
-
gkehub.gateway.patch
-
gkehub.gateway.post
-
gkehub.gateway.put
-
gkehub.gateway.stream
gkehub.memberships.get
serviceusage.services.get
Connect Gateway Editor
( roles/
)
Edit access to Connect Gateway.
gkehub.gateway.delete
gkehub.
gkehub.gateway.get
gkehub.gateway.patch
gkehub.gateway.post
gkehub.gateway.put
gkehub.memberships.get
serviceusage.services.get
Connect Gateway Reader
( roles/
)
Read-only access to Connect Gateway.
gkehub.
gkehub.gateway.get
gkehub.memberships.get
serviceusage.services.get
Fleet Scope Admin
( roles/
)
Admin access to Fleet Scopes to set IAM Bindings and RBACRoleBindings.
gkehub.namespaces.create
gkehub.namespaces.delete
gkehub.namespaces.get
gkehub.namespaces.list
gkehub.rbacrolebindings.*
-
gkehub.rbacrolebindings.create
-
gkehub.rbacrolebindings.delete
-
gkehub.rbacrolebindings.get
-
gkehub.rbacrolebindings.list
-
gkehub.rbacrolebindings.update
gkehub.scopes.get
gkehub.scopes.getIamPolicy
gkehub.
gkehub.scopes.setIamPolicy
Fleet Scope Editor
( roles/
)
Edit access to Namespaces under Fleet Scopes.
gkehub.namespaces.create
gkehub.namespaces.delete
gkehub.namespaces.get
gkehub.namespaces.list
gkehub.rbacrolebindings.get
gkehub.rbacrolebindings.list
gkehub.scopes.get
gkehub.scopes.getIamPolicy
gkehub.
Fleet Project-level Scope Editor
( roles/
)
Role for project-level permissions for editor of Fleet Scopes.
gkehub.gateway.delete
gkehub.
gkehub.gateway.get
gkehub.gateway.patch
gkehub.gateway.post
gkehub.gateway.put
gkehub.memberships.get
gkehub.operations.get
monitoring.timeSeries.list
resourcemanager.projects.get
resourcemanager.projects.list
serviceusage.services.get
Fleet Scope Viewer
( roles/
)
Viewer of Fleet Scopes and associated resources.
gkehub.namespaces.get
gkehub.namespaces.list
gkehub.rbacrolebindings.get
gkehub.rbacrolebindings.list
gkehub.scopes.get
gkehub.scopes.getIamPolicy
gkehub.
Fleet Project-level Scope Viewer
( roles/
)
Role for project-level permissions for viewer of Fleet Scopes.
gkehub.
gkehub.gateway.get
gkehub.memberships.get
monitoring.timeSeries.list
resourcemanager.projects.get
resourcemanager.projects.list
serviceusage.services.get
GKE Hub Service Agent
( roles/
)
Gives the GKE Hub service agent access to Cloud Platform resources.
container.
-
container.
clusterRoleBindings. create -
container.
clusterRoleBindings. delete -
container.
clusterRoleBindings. get -
container.
clusterRoleBindings. list -
container.
clusterRoleBindings. update
container.clusterRoles.*
-
container.clusterRoles.bind
-
container.clusterRoles.create
-
container.clusterRoles.delete
-
container.
clusterRoles. escalate -
container.clusterRoles.get
-
container.clusterRoles.list
-
container.clusterRoles.update
container.clusters.connect
container.clusters.get
container.clusters.list
container.clusters.update
container.
container.
container.
container.
container.
container.namespaces.get
container.operations.get
container.thirdPartyObjects.*
-
container.
thirdPartyObjects. create -
container.
thirdPartyObjects. delete -
container.
thirdPartyObjects. get -
container.
thirdPartyObjects. list -
container.
thirdPartyObjects. update
gkehub.features.create
gkehub.features.get
gkehub.features.list
gkehub.fleet.create
gkehub.fleet.get
gkehub.gateway.delete
gkehub.
gkehub.gateway.get
gkehub.gateway.patch
gkehub.gateway.post
gkehub.gateway.put
gkehub.locations.*
-
gkehub.locations.get
-
gkehub.locations.list
gkehub.memberships.create
gkehub.
gkehub.memberships.get
gkehub.memberships.list
gkehub.operations.get
gkemulticloud.awsClusters.get
gkemulticloud.
gkeonprem.
gkeonprem.vmwareClusters.get
logging.buckets.create
logging.buckets.get
logging.buckets.list
logging.buckets.update
logging.exclusions.*
-
logging.exclusions.create
-
logging.exclusions.delete
-
logging.exclusions.get
-
logging.exclusions.list
-
logging.exclusions.update
logging.sinks.*
-
logging.sinks.create
-
logging.sinks.delete
-
logging.sinks.get
-
logging.sinks.list
-
logging.sinks.update
logging.views.create
logging.views.get
logging.views.list
logging.views.update
monitoring.metricsScopes.link
resourcemanager.projects.get
resourcemanager.projects.list
serviceusage.services.get
serviceusage.services.list
Fleet Viewer (formerly GKE Hub Viewer)
( roles/
)
Read-only access to Fleets and related resources.
gkehub.features.get
gkehub.features.getIamPolicy
gkehub.features.list
gkehub.fleet.get
gkehub.fleet.getFreeTrial
gkehub.locations.*
-
gkehub.locations.get
-
gkehub.locations.list
gkehub.membershipbindings.get
gkehub.membershipbindings.list
gkehub.membershipfeatures.get
gkehub.membershipfeatures.list
gkehub.
gkehub.memberships.get
gkehub.
gkehub.memberships.list
gkehub.namespaces.get
gkehub.namespaces.list
gkehub.operations.get
gkehub.operations.list
gkehub.rbacrolebindings.get
gkehub.rbacrolebindings.list
gkehub.scopes.get
gkehub.scopes.list
gkehub.
resourcemanager.projects.get
resourcemanager.projects.list
GKE Hub permissions
gkehub.endpoints.connect
Owner
( roles/
)
Velostrata Manager
( roles/
)
Velostrata Manager Connection Agent
( roles/
)
GKE Connect Agent
( roles/
)
Service agent roles
- Edge Container Cluster Service Agent
(
roles/
)edgecontainer.clusterServiceAgent
gkehub.features.create
Owner
( roles/
)
Editor
( roles/
)
Fleet Admin (formerly GKE Hub Admin)
( roles/
)
Fleet Editor (formerly GKE Hub Editor)
( roles/
)
Service agent roles
- GKE Hub Service Agent
(
roles/
)gkehub.serviceAgent - Anthos Multi-Cloud Service Agent
(
roles/
)gkemulticloud.serviceAgent - KRM API Hosting AnthosApiEndpoint Service Agent
(
roles/
)krmapihosting.anthosApiEndpointServiceAgent - Edge Container Cluster Service Agent
(
roles/
)edgecontainer.clusterServiceAgent
gkehub.features.delete
Owner
( roles/
)
Editor
( roles/
)
Fleet Admin (formerly GKE Hub Admin)
( roles/
)
Fleet Editor (formerly GKE Hub Editor)
( roles/
)
Service agent roles
- KRM API Hosting AnthosApiEndpoint Service Agent
(
roles/
)krmapihosting.anthosApiEndpointServiceAgent - Anthos Multi-Cloud Service Agent
(
roles/
)gkemulticloud.serviceAgent
gkehub.features.get
Owner
( roles/
)
Editor
( roles/
)
Viewer
( roles/
)
Fleet Admin (formerly GKE Hub Admin)
( roles/
)
Fleet Editor (formerly GKE Hub Editor)
( roles/
)
Fleet Viewer (formerly GKE Hub Viewer)
( roles/
)
Support User
( roles/
)
Service agent roles
- Anthos Service Agent
(
roles/
)anthos.serviceAgent - Anthos Audit Service Agent
(
roles/
)anthosaudit.serviceAgent - Anthos Config Management Service Agent
(
roles/
)anthosconfigmanagement.serviceAgent - Anthos Identity Service Agent
(
roles/
)anthosidentityservice.serviceAgent - Anthos Policy Controller Service Agent
(
roles/
)anthospolicycontroller.serviceAgent - Anthos Service Mesh Service Agent
(
roles/
)anthosservicemesh.serviceAgent - Anthos Support Service Agent
(
roles/
)anthossupport.serviceAgent - App Development Experience Service Agent
(
roles/
)appdevelopmentexperience.serviceAgent - Edge Container Cluster Service Agent
(
roles/
)edgecontainer.clusterServiceAgent - Game Services Service Agent
(
roles/
)gameservices.serviceAgent - GKE Hub Service Agent
(
roles/
)gkehub.serviceAgent - Anthos Multi-Cloud Service Agent
(
roles/
)gkemulticloud.serviceAgent - KRM API Hosting AnthosApiEndpoint Service Agent
(
roles/
)krmapihosting.anthosApiEndpointServiceAgent - Mesh Managed Control Plane Service Agent
(
roles/
)meshcontrolplane.serviceAgent - Multi Cluster Ingress Service Agent
(
roles/
)multiclusteringress.serviceAgent - Multi-cluster metering Service Agent
(
roles/
)multiclustermetering.serviceAgent - Multi-Cluster Service Discovery Service Agent
(
roles/
)multiclusterservicediscovery.serviceAgent - Service Directory Service Agent
(
roles/
)servicedirectory.serviceAgent - Workload Certificate Service Agent
(
roles/
)workloadcertificate.serviceAgent - Vertex AI Online Prediction Service Agent
(
roles/
)aiplatform.onlinePredictionServiceAgent
gkehub.features.getIamPolicy
Owner
( roles/
)
Editor
( roles/
)
Viewer
( roles/
)
Fleet Admin (formerly GKE Hub Admin)
( roles/
)
Fleet Editor (formerly GKE Hub Editor)
( roles/
)
Fleet Viewer (formerly GKE Hub Viewer)
( roles/
)
Security Admin
( roles/
)
Security Auditor
( roles/
)
Security Reviewer
( roles/
)
Support User
( roles/
)
Service agent roles
- Anthos Support Service Agent
(
roles/
)anthossupport.serviceAgent - Game Services Service Agent
(
roles/
)gameservices.serviceAgent - Anthos Multi-Cloud Service Agent
(
roles/
)gkemulticloud.serviceAgent - KRM API Hosting AnthosApiEndpoint Service Agent
(
roles/
)krmapihosting.anthosApiEndpointServiceAgent - Mesh Managed Control Plane Service Agent
(
roles/
)meshcontrolplane.serviceAgent - Vertex AI Online Prediction Service Agent
(
roles/
)aiplatform.onlinePredictionServiceAgent
gkehub.features.list
Owner
( roles/
)
Editor
( roles/
)
Viewer
( roles/
)
Fleet Admin (formerly GKE Hub Admin)
( roles/
)
Fleet Editor (formerly GKE Hub Editor)
( roles/
)
Fleet Viewer (formerly GKE Hub Viewer)
( roles/
)
Security Admin
( roles/
)
Security Auditor
( roles/
)
Security Reviewer
( roles/
)
Support User
( roles/
)
Service agent roles
- Anthos Support Service Agent
(
roles/
)anthossupport.serviceAgent - Edge Container Cluster Service Agent
(
roles/
)edgecontainer.clusterServiceAgent - Game Services Service Agent
(
roles/
)gameservices.serviceAgent - GKE Hub Service Agent
(
roles/
)gkehub.serviceAgent - Anthos Multi-Cloud Service Agent
(
roles/
)gkemulticloud.serviceAgent - KRM API Hosting AnthosApiEndpoint Service Agent
(
roles/
)krmapihosting.anthosApiEndpointServiceAgent - Mesh Managed Control Plane Service Agent
(
roles/
)meshcontrolplane.serviceAgent - Vertex AI Online Prediction Service Agent
(
roles/
)aiplatform.onlinePredictionServiceAgent
gkehub.features.setIamPolicy
Owner
( roles/
)
Fleet Admin (formerly GKE Hub Admin)
( roles/
)
Security Admin
( roles/
)
Service agent roles
- KRM API Hosting AnthosApiEndpoint Service Agent
(
roles/
)krmapihosting.anthosApiEndpointServiceAgent - Anthos Multi-Cloud Service Agent
(
roles/
)gkemulticloud.serviceAgent
gkehub.features.update
Owner
( roles/
)
Editor
( roles/
)
Fleet Admin (formerly GKE Hub Admin)
( roles/
)
Fleet Editor (formerly GKE Hub Editor)
( roles/
)
Service agent roles
- Anthos Multi-Cloud Service Agent
(
roles/
)gkemulticloud.serviceAgent - KRM API Hosting AnthosApiEndpoint Service Agent
(
roles/
)krmapihosting.anthosApiEndpointServiceAgent - Edge Container Cluster Service Agent
(
roles/
)edgecontainer.clusterServiceAgent
gkehub.fleet.create
Owner
( roles/
)
Editor
( roles/
)
Fleet Admin (formerly GKE Hub Admin)
( roles/
)
Fleet Editor (formerly GKE Hub Editor)
( roles/
)
Service agent roles
- GKE Hub Service Agent
(
roles/
)gkehub.serviceAgent - Anthos Multi-Cloud Service Agent
(
roles/
)gkemulticloud.serviceAgent - KRM API Hosting AnthosApiEndpoint Service Agent
(
roles/
)krmapihosting.anthosApiEndpointServiceAgent - Workload Certificate Service Agent
(
roles/
)workloadcertificate.serviceAgent - Edge Container Cluster Service Agent
(
roles/
)edgecontainer.clusterServiceAgent
gkehub.fleet.createFreeTrial
Owner
( roles/
)
Editor
( roles/
)
Fleet Admin (formerly GKE Hub Admin)
( roles/
)
Fleet Editor (formerly GKE Hub Editor)
( roles/
)
Service agent roles
- KRM API Hosting AnthosApiEndpoint Service Agent
(
roles/
)krmapihosting.anthosApiEndpointServiceAgent - Anthos Multi-Cloud Service Agent
(
roles/
)gkemulticloud.serviceAgent
gkehub.fleet.delete
Owner
( roles/
)
Editor
( roles/
)
Fleet Admin (formerly GKE Hub Admin)
( roles/
)
Fleet Editor (formerly GKE Hub Editor)
( roles/
)
Service agent roles
- Anthos Multi-Cloud Service Agent
(
roles/
)gkemulticloud.serviceAgent - KRM API Hosting AnthosApiEndpoint Service Agent
(
roles/
)krmapihosting.anthosApiEndpointServiceAgent - Edge Container Cluster Service Agent
(
roles/
)edgecontainer.clusterServiceAgent
gkehub.fleet.get
Owner
( roles/
)
Editor
( roles/
)
Viewer
( roles/
)
Fleet Admin (formerly GKE Hub Admin)
( roles/
)
Fleet Editor (formerly GKE Hub Editor)
( roles/
)
Fleet Viewer (formerly GKE Hub Viewer)
( roles/
)
Support User
( roles/
)
Service agent roles
- Anthos Support Service Agent
(
roles/
)anthossupport.serviceAgent - Edge Container Cluster Service Agent
(
roles/
)edgecontainer.clusterServiceAgent - Game Services Service Agent
(
roles/
)gameservices.serviceAgent - GKE Hub Service Agent
(
roles/
)gkehub.serviceAgent - Anthos Multi-Cloud Service Agent
(
roles/
)gkemulticloud.serviceAgent - KRM API Hosting AnthosApiEndpoint Service Agent
(
roles/
)krmapihosting.anthosApiEndpointServiceAgent - Mesh Managed Control Plane Service Agent
(
roles/
)meshcontrolplane.serviceAgent - Workload Certificate Service Agent
(
roles/
)workloadcertificate.serviceAgent - Vertex AI Online Prediction Service Agent
(
roles/
)aiplatform.onlinePredictionServiceAgent
gkehub.fleet.getFreeTrial
Owner
( roles/
)
Editor
( roles/
)
Viewer
( roles/
)
Fleet Admin (formerly GKE Hub Admin)
( roles/
)
Fleet Editor (formerly GKE Hub Editor)
( roles/
)
Fleet Viewer (formerly GKE Hub Viewer)
( roles/
)
Support User
( roles/
)
Service agent roles
- Game Services Service Agent
(
roles/
)gameservices.serviceAgent - Anthos Multi-Cloud Service Agent
(
roles/
)gkemulticloud.serviceAgent - KRM API Hosting AnthosApiEndpoint Service Agent
(
roles/
)krmapihosting.anthosApiEndpointServiceAgent - Mesh Managed Control Plane Service Agent
(
roles/
)meshcontrolplane.serviceAgent - Anthos Support Service Agent
(
roles/
)anthossupport.serviceAgent
gkehub.fleet.update
Owner
( roles/
)
Editor
( roles/
)
Fleet Admin (formerly GKE Hub Admin)
( roles/
)
Fleet Editor (formerly GKE Hub Editor)
( roles/
)
Service agent roles
- KRM API Hosting AnthosApiEndpoint Service Agent
(
roles/
)krmapihosting.anthosApiEndpointServiceAgent - Anthos Multi-Cloud Service Agent
(
roles/
)gkemulticloud.serviceAgent
gkehub.fleet.updateFreeTrial
Owner
( roles/
)
Editor
( roles/
)
Fleet Admin (formerly GKE Hub Admin)
( roles/
)
Fleet Editor (formerly GKE Hub Editor)
( roles/
)
Service agent roles
- KRM API Hosting AnthosApiEndpoint Service Agent
(
roles/
)krmapihosting.anthosApiEndpointServiceAgent - Anthos Multi-Cloud Service Agent
(
roles/
)gkemulticloud.serviceAgent
gkehub.gateway.delete
Owner
( roles/
)
Editor
( roles/
)
Connect Gateway Admin
( roles/
)
Connect Gateway Editor
( roles/
)
Fleet Project-level Scope Editor
( roles/
)
Service agent roles
- Anthos Config Management Service Agent
(
roles/
)anthosconfigmanagement.serviceAgent - Anthos Identity Service Agent
(
roles/
)anthosidentityservice.serviceAgent - Anthos Policy Controller Service Agent
(
roles/
)anthospolicycontroller.serviceAgent - Anthos Service Mesh Service Agent
(
roles/
)anthosservicemesh.serviceAgent - App Development Experience Service Agent
(
roles/
)appdevelopmentexperience.serviceAgent - Config Delivery Service Agent
(
roles/
)configdelivery.serviceAgent - GKE Hub Service Agent
(
roles/
)gkehub.serviceAgent - KRM API Hosting AnthosApiEndpoint Service Agent
(
roles/
)krmapihosting.anthosApiEndpointServiceAgent - Mesh Managed Control Plane Service Agent
(
roles/
)meshcontrolplane.serviceAgent - Multi Cluster Ingress Service Agent
(
roles/
)multiclusteringress.serviceAgent - Multi-cluster metering Service Agent
(
roles/
)multiclustermetering.serviceAgent - Multi-Cluster Service Discovery Service Agent
(
roles/
)multiclusterservicediscovery.serviceAgent - Service Directory Service Agent
(
roles/
)servicedirectory.serviceAgent - Vertex AI Online Prediction Service Agent
(
roles/
)aiplatform.onlinePredictionServiceAgent
gkehub.
gateway.
generateCredentials
Owner
( roles/
)
Editor
( roles/
)
Viewer
( roles/
)
Connect Gateway Admin
( roles/
)
Connect Gateway Editor
( roles/
)
Connect Gateway Reader
( roles/
)
Fleet Project-level Scope Editor
( roles/
)
Fleet Project-level Scope Viewer
( roles/
)
Support User
( roles/
)
Service agent roles
- Anthos Config Management Service Agent
(
roles/
)anthosconfigmanagement.serviceAgent - Anthos Identity Service Agent
(
roles/
)anthosidentityservice.serviceAgent - Anthos Policy Controller Service Agent
(
roles/
)anthospolicycontroller.serviceAgent - Anthos Service Mesh Service Agent
(
roles/
)anthosservicemesh.serviceAgent - Anthos Support Service Agent
(
roles/
)anthossupport.serviceAgent - App Development Experience Service Agent
(
roles/
)appdevelopmentexperience.serviceAgent - Config Delivery Service Agent
(
roles/
)configdelivery.serviceAgent - GKE Hub Service Agent
(
roles/
)gkehub.serviceAgent - KRM API Hosting AnthosApiEndpoint Service Agent
(
roles/
)krmapihosting.anthosApiEndpointServiceAgent - Mesh Managed Control Plane Service Agent
(
roles/
)meshcontrolplane.serviceAgent - Multi Cluster Ingress Service Agent
(
roles/
)multiclusteringress.serviceAgent - Multi-cluster metering Service Agent
(
roles/
)multiclustermetering.serviceAgent - Multi-Cluster Service Discovery Service Agent
(
roles/
)multiclusterservicediscovery.serviceAgent - Service Directory Service Agent
(
roles/
)servicedirectory.serviceAgent - Vertex AI Online Prediction Service Agent
(
roles/
)aiplatform.onlinePredictionServiceAgent
gkehub.gateway.get
Owner
( roles/
)
Editor
( roles/
)
Viewer
( roles/
)
Connect Gateway Admin
( roles/
)
Connect Gateway Editor
( roles/
)
Connect Gateway Reader
( roles/
)
Fleet Project-level Scope Editor
( roles/
)
Fleet Project-level Scope Viewer
( roles/
)
Support User
( roles/
)
Service agent roles
- Anthos Config Management Service Agent
(
roles/
)anthosconfigmanagement.serviceAgent - Anthos Identity Service Agent
(
roles/
)anthosidentityservice.serviceAgent - Anthos Policy Controller Service Agent
(
roles/
)anthospolicycontroller.serviceAgent - Anthos Service Mesh Service Agent
(
roles/
)anthosservicemesh.serviceAgent - Anthos Support Service Agent
(
roles/
)anthossupport.serviceAgent - App Development Experience Service Agent
(
roles/
)appdevelopmentexperience.serviceAgent - Config Delivery Service Agent
(
roles/
)configdelivery.serviceAgent - GKE Hub Service Agent
(
roles/
)gkehub.serviceAgent - KRM API Hosting AnthosApiEndpoint Service Agent
(
roles/
)krmapihosting.anthosApiEndpointServiceAgent - Mesh Managed Control Plane Service Agent
(
roles/
)meshcontrolplane.serviceAgent - Multi Cluster Ingress Service Agent
(
roles/
)multiclusteringress.serviceAgent - Multi-cluster metering Service Agent
(
roles/
)multiclustermetering.serviceAgent - Multi-Cluster Service Discovery Service Agent
(
roles/
)multiclusterservicediscovery.serviceAgent - Service Directory Service Agent
(
roles/
)servicedirectory.serviceAgent - Vertex AI Online Prediction Service Agent
(
roles/
)aiplatform.onlinePredictionServiceAgent
gkehub.gateway.patch
Owner
( roles/
)
Editor
( roles/
)
Connect Gateway Admin
( roles/
)
Connect Gateway Editor
( roles/
)
Fleet Project-level Scope Editor
( roles/
)
Service agent roles
- Anthos Config Management Service Agent
(
roles/
)anthosconfigmanagement.serviceAgent - Anthos Identity Service Agent
(
roles/
)anthosidentityservice.serviceAgent - Anthos Policy Controller Service Agent
(
roles/
)anthospolicycontroller.serviceAgent - Anthos Service Mesh Service Agent
(
roles/
)anthosservicemesh.serviceAgent - App Development Experience Service Agent
(
roles/
)appdevelopmentexperience.serviceAgent - Config Delivery Service Agent
(
roles/
)configdelivery.serviceAgent - GKE Hub Service Agent
(
roles/
)gkehub.serviceAgent - KRM API Hosting AnthosApiEndpoint Service Agent
(
roles/
)krmapihosting.anthosApiEndpointServiceAgent - Mesh Managed Control Plane Service Agent
(
roles/
)meshcontrolplane.serviceAgent - Multi Cluster Ingress Service Agent
(
roles/
)multiclusteringress.serviceAgent - Multi-cluster metering Service Agent
(
roles/
)multiclustermetering.serviceAgent - Multi-Cluster Service Discovery Service Agent
(
roles/
)multiclusterservicediscovery.serviceAgent - Service Directory Service Agent
(
roles/
)servicedirectory.serviceAgent - Vertex AI Online Prediction Service Agent
(
roles/
)aiplatform.onlinePredictionServiceAgent
gkehub.gateway.post
Owner
( roles/
)
Editor
( roles/
)
Connect Gateway Admin
( roles/
)
Connect Gateway Editor
( roles/
)
Fleet Project-level Scope Editor
( roles/
)
Service agent roles
- Anthos Config Management Service Agent
(
roles/
)anthosconfigmanagement.serviceAgent - Anthos Identity Service Agent
(
roles/
)anthosidentityservice.serviceAgent - Anthos Policy Controller Service Agent
(
roles/
)anthospolicycontroller.serviceAgent - Anthos Service Mesh Service Agent
(
roles/
)anthosservicemesh.serviceAgent - App Development Experience Service Agent
(
roles/
)appdevelopmentexperience.serviceAgent - Config Delivery Service Agent
(
roles/
)configdelivery.serviceAgent - GKE Hub Service Agent
(
roles/
)gkehub.serviceAgent - KRM API Hosting AnthosApiEndpoint Service Agent
(
roles/
)krmapihosting.anthosApiEndpointServiceAgent - Mesh Managed Control Plane Service Agent
(
roles/
)meshcontrolplane.serviceAgent - Multi Cluster Ingress Service Agent
(
roles/
)multiclusteringress.serviceAgent - Multi-cluster metering Service Agent
(
roles/
)multiclustermetering.serviceAgent - Multi-Cluster Service Discovery Service Agent
(
roles/
)multiclusterservicediscovery.serviceAgent - Service Directory Service Agent
(
roles/
)servicedirectory.serviceAgent - Vertex AI Online Prediction Service Agent
(
roles/
)aiplatform.onlinePredictionServiceAgent
gkehub.gateway.put
Owner
( roles/
)
Editor
( roles/
)
Connect Gateway Admin
( roles/
)
Connect Gateway Editor
( roles/
)
Fleet Project-level Scope Editor
( roles/
)
Service agent roles
- Anthos Config Management Service Agent
(
roles/
)anthosconfigmanagement.serviceAgent - Anthos Identity Service Agent
(
roles/
)anthosidentityservice.serviceAgent - Anthos Policy Controller Service Agent
(
roles/
)anthospolicycontroller.serviceAgent - Anthos Service Mesh Service Agent
(
roles/
)anthosservicemesh.serviceAgent - App Development Experience Service Agent
(
roles/
)appdevelopmentexperience.serviceAgent - Config Delivery Service Agent
(
roles/
)configdelivery.serviceAgent - GKE Hub Service Agent
(
roles/
)gkehub.serviceAgent - KRM API Hosting AnthosApiEndpoint Service Agent
(
roles/
)krmapihosting.anthosApiEndpointServiceAgent - Mesh Managed Control Plane Service Agent
(
roles/
)meshcontrolplane.serviceAgent - Multi Cluster Ingress Service Agent
(
roles/
)multiclusteringress.serviceAgent - Multi-cluster metering Service Agent
(
roles/
)multiclustermetering.serviceAgent - Multi-Cluster Service Discovery Service Agent
(
roles/
)multiclusterservicediscovery.serviceAgent - Service Directory Service Agent
(
roles/
)servicedirectory.serviceAgent - Vertex AI Online Prediction Service Agent
(
roles/
)aiplatform.onlinePredictionServiceAgent
gkehub.gateway.stream
Owner
( roles/
)
Editor
( roles/
)
Connect Gateway Admin
( roles/
)
Service agent roles
- Mesh Managed Control Plane Service Agent
(
roles/
)meshcontrolplane.serviceAgent - KRM API Hosting AnthosApiEndpoint Service Agent
(
roles/
)krmapihosting.anthosApiEndpointServiceAgent
gkehub.locations.get
Owner
( roles/
)
Editor
( roles/
)
Viewer
( roles/
)
Fleet Admin (formerly GKE Hub Admin)
( roles/
)
Fleet Editor (formerly GKE Hub Editor)
( roles/
)
Fleet Viewer (formerly GKE Hub Viewer)
( roles/
)
Support User
( roles/
)
Service agent roles
- Anthos Service Agent
(
roles/
)anthos.serviceAgent - Anthos Audit Service Agent
(
roles/
)anthosaudit.serviceAgent - Anthos Config Management Service Agent
(
roles/
)anthosconfigmanagement.serviceAgent - Anthos Identity Service Agent
(
roles/
)anthosidentityservice.serviceAgent - Anthos Policy Controller Service Agent
(
roles/
)anthospolicycontroller.serviceAgent - Anthos Service Mesh Service Agent
(
roles/
)anthosservicemesh.serviceAgent - Anthos Support Service Agent
(
roles/
)anthossupport.serviceAgent - App Development Experience Service Agent
(
roles/
)appdevelopmentexperience.serviceAgent - Edge Container Cluster Service Agent
(
roles/
)edgecontainer.clusterServiceAgent - Game Services Service Agent
(
roles/
)gameservices.serviceAgent - GKE Hub Service Agent
(
roles/
)gkehub.serviceAgent - Anthos Multi-Cloud Service Agent
(
roles/
)gkemulticloud.serviceAgent - KRM API Hosting AnthosApiEndpoint Service Agent
(
roles/
)krmapihosting.anthosApiEndpointServiceAgent - Mesh Managed Control Plane Service Agent
(
roles/
)meshcontrolplane.serviceAgent - Multi Cluster Ingress Service Agent
(
roles/
)multiclusteringress.serviceAgent - Multi-cluster metering Service Agent
(
roles/
)multiclustermetering.serviceAgent - Multi-Cluster Service Discovery Service Agent
(
roles/
)multiclusterservicediscovery.serviceAgent - Service Directory Service Agent
(
roles/
)servicedirectory.serviceAgent - Workload Certificate Service Agent
(
roles/
)workloadcertificate.serviceAgent - Vertex AI Online Prediction Service Agent
(
roles/
)aiplatform.onlinePredictionServiceAgent
gkehub.locations.list
Owner
( roles/
)
Editor
( roles/
)
Viewer
( roles/
)
Fleet Admin (formerly GKE Hub Admin)
( roles/
)
Fleet Editor (formerly GKE Hub Editor)
( roles/
)
Fleet Viewer (formerly GKE Hub Viewer)
( roles/
)
Security Admin
( roles/
)
Security Auditor
( roles/
)
Security Reviewer
( roles/
)
Support User
( roles/
)
Service agent roles
- Anthos Service Agent
(
roles/
)anthos.serviceAgent - Anthos Audit Service Agent
(
roles/
)anthosaudit.serviceAgent - Anthos Config Management Service Agent
(
roles/
)anthosconfigmanagement.serviceAgent - Anthos Identity Service Agent
(
roles/
)anthosidentityservice.serviceAgent - Anthos Policy Controller Service Agent
(
roles/
)anthospolicycontroller.serviceAgent - Anthos Service Mesh Service Agent
(
roles/
)anthosservicemesh.serviceAgent - Anthos Support Service Agent
(
roles/
)anthossupport.serviceAgent - App Development Experience Service Agent
(
roles/
)appdevelopmentexperience.serviceAgent - Edge Container Cluster Service Agent
(
roles/
)edgecontainer.clusterServiceAgent - Game Services Service Agent
(
roles/
)gameservices.serviceAgent - GKE Hub Service Agent
(
roles/
)gkehub.serviceAgent - Anthos Multi-Cloud Service Agent
(
roles/
)gkemulticloud.serviceAgent - KRM API Hosting AnthosApiEndpoint Service Agent
(
roles/
)krmapihosting.anthosApiEndpointServiceAgent - Mesh Managed Control Plane Service Agent
(
roles/
)meshcontrolplane.serviceAgent - Multi Cluster Ingress Service Agent
(
roles/
)multiclusteringress.serviceAgent - Multi-cluster metering Service Agent
(
roles/
)multiclustermetering.serviceAgent - Multi-Cluster Service Discovery Service Agent
(
roles/
)multiclusterservicediscovery.serviceAgent - Service Directory Service Agent
(
roles/
)servicedirectory.serviceAgent - Workload Certificate Service Agent
(
roles/
)workloadcertificate.serviceAgent - Vertex AI Online Prediction Service Agent
(
roles/
)aiplatform.onlinePredictionServiceAgent
gkehub.
membershipbindings.
create
Owner
( roles/
)
Editor
( roles/
)
Fleet Admin (formerly GKE Hub Admin)
( roles/
)
Fleet Editor (formerly GKE Hub Editor)
( roles/
)
Service agent roles
- KRM API Hosting AnthosApiEndpoint Service Agent
(
roles/
)krmapihosting.anthosApiEndpointServiceAgent - Anthos Multi-Cloud Service Agent
(
roles/
)gkemulticloud.serviceAgent
gkehub.
membershipbindings.
delete
Owner
( roles/
)
Editor
( roles/
)
Fleet Admin (formerly GKE Hub Admin)
( roles/
)
Fleet Editor (formerly GKE Hub Editor)
( roles/
)
Service agent roles
- KRM API Hosting AnthosApiEndpoint Service Agent
(
roles/
)krmapihosting.anthosApiEndpointServiceAgent - Anthos Multi-Cloud Service Agent
(
roles/
)gkemulticloud.serviceAgent
gkehub.membershipbindings.get
Owner
( roles/
)
Editor
( roles/
)
Viewer
( roles/
)
Fleet Admin (formerly GKE Hub Admin)
( roles/
)
Fleet Editor (formerly GKE Hub Editor)
( roles/
)
Fleet Viewer (formerly GKE Hub Viewer)
( roles/
)
Support User
( roles/
)
Service agent roles
- Game Services Service Agent
(
roles/
)gameservices.serviceAgent - Anthos Multi-Cloud Service Agent
(
roles/
)gkemulticloud.serviceAgent - KRM API Hosting AnthosApiEndpoint Service Agent
(
roles/
)krmapihosting.anthosApiEndpointServiceAgent - Mesh Managed Control Plane Service Agent
(
roles/
)meshcontrolplane.serviceAgent - Anthos Support Service Agent
(
roles/
)anthossupport.serviceAgent
gkehub.membershipbindings.list
Owner
( roles/
)
Editor
( roles/
)
Viewer
( roles/
)
Fleet Admin (formerly GKE Hub Admin)
( roles/
)
Fleet Editor (formerly GKE Hub Editor)
( roles/
)
Fleet Viewer (formerly GKE Hub Viewer)
( roles/
)
Security Admin
( roles/
)
Security Auditor
( roles/
)
Security Reviewer
( roles/
)
Support User
( roles/
)
Service agent roles
- Game Services Service Agent
(
roles/
)gameservices.serviceAgent - Anthos Multi-Cloud Service Agent
(
roles/
)gkemulticloud.serviceAgent - KRM API Hosting AnthosApiEndpoint Service Agent
(
roles/
)krmapihosting.anthosApiEndpointServiceAgent - Mesh Managed Control Plane Service Agent
(
roles/
)meshcontrolplane.serviceAgent - Anthos Support Service Agent
(
roles/
)anthossupport.serviceAgent
gkehub.
membershipbindings.
update
Owner
( roles/
)
Editor
( roles/
)
Fleet Admin (formerly GKE Hub Admin)
( roles/
)
Fleet Editor (formerly GKE Hub Editor)
( roles/
)
Service agent roles
- KRM API Hosting AnthosApiEndpoint Service Agent
(
roles/
)krmapihosting.anthosApiEndpointServiceAgent - Anthos Multi-Cloud Service Agent
(
roles/
)gkemulticloud.serviceAgent
gkehub.
membershipfeatures.
create
Owner
( roles/
)
Editor
( roles/
)
Fleet Admin (formerly GKE Hub Admin)
( roles/
)
Fleet Editor (formerly GKE Hub Editor)
( roles/
)
Service agent roles
- KRM API Hosting AnthosApiEndpoint Service Agent
(
roles/
)krmapihosting.anthosApiEndpointServiceAgent - Anthos Multi-Cloud Service Agent
(
roles/
)gkemulticloud.serviceAgent
gkehub.
membershipfeatures.
delete
Owner
( roles/
)
Editor
( roles/
)
Fleet Admin (formerly GKE Hub Admin)
( roles/
)
Fleet Editor (formerly GKE Hub Editor)
( roles/
)
Service agent roles
- KRM API Hosting AnthosApiEndpoint Service Agent
(
roles/
)krmapihosting.anthosApiEndpointServiceAgent - Anthos Multi-Cloud Service Agent
(
roles/
)gkemulticloud.serviceAgent
gkehub.membershipfeatures.get
Owner
( roles/
)
Editor
( roles/
)
Viewer
( roles/
)
Fleet Admin (formerly GKE Hub Admin)
( roles/
)
Fleet Editor (formerly GKE Hub Editor)
( roles/
)
Fleet Viewer (formerly GKE Hub Viewer)
( roles/
)
Support User
( roles/
)
Service agent roles
- Game Services Service Agent
(
roles/
)gameservices.serviceAgent - Anthos Multi-Cloud Service Agent
(
roles/
)gkemulticloud.serviceAgent - KRM API Hosting AnthosApiEndpoint Service Agent
(
roles/
)krmapihosting.anthosApiEndpointServiceAgent - Mesh Managed Control Plane Service Agent
(
roles/
)meshcontrolplane.serviceAgent - Anthos Support Service Agent
(
roles/
)anthossupport.serviceAgent
gkehub.membershipfeatures.list
Owner
( roles/
)
Editor
( roles/
)
Viewer
( roles/
)
Fleet Admin (formerly GKE Hub Admin)
( roles/
)
Fleet Editor (formerly GKE Hub Editor)
( roles/
)
Fleet Viewer (formerly GKE Hub Viewer)
( roles/
)
Security Admin
( roles/
)
Security Auditor
( roles/
)
Security Reviewer
( roles/
)
Support User
( roles/
)
Service agent roles
- Game Services Service Agent
(
roles/
)gameservices.serviceAgent - Anthos Multi-Cloud Service Agent
(
roles/
)gkemulticloud.serviceAgent - KRM API Hosting AnthosApiEndpoint Service Agent
(
roles/
)krmapihosting.anthosApiEndpointServiceAgent - Mesh Managed Control Plane Service Agent
(
roles/
)meshcontrolplane.serviceAgent - Anthos Support Service Agent
(
roles/
)anthossupport.serviceAgent
gkehub.
membershipfeatures.
update
Owner
( roles/
)
Editor
( roles/
)
Fleet Admin (formerly GKE Hub Admin)
( roles/
)
Fleet Editor (formerly GKE Hub Editor)
( roles/
)
Service agent roles
- KRM API Hosting AnthosApiEndpoint Service Agent
(
roles/
)krmapihosting.anthosApiEndpointServiceAgent - Anthos Multi-Cloud Service Agent
(
roles/
)gkemulticloud.serviceAgent
gkehub.memberships.create
Owner
( roles/
)
Editor
( roles/
)
Fleet Admin (formerly GKE Hub Admin)
( roles/
)
Fleet Editor (formerly GKE Hub Editor)
( roles/
)
Service agent roles
- Edge Container Service Agent
(
roles/
)edgecontainer.serviceAgent - GKE Hub Service Agent
(
roles/
)gkehub.serviceAgent - Anthos Multi-Cloud Service Agent
(
roles/
)gkemulticloud.serviceAgent - KRM API Hosting AnthosApiEndpoint Service Agent
(
roles/
)krmapihosting.anthosApiEndpointServiceAgent - Edge Container Cluster Service Agent
(
roles/
)edgecontainer.clusterServiceAgent
gkehub.memberships.delete
Owner
( roles/
)
Editor
( roles/
)
Fleet Admin (formerly GKE Hub Admin)
( roles/
)
Fleet Editor (formerly GKE Hub Editor)
( roles/
)
Service agent roles
- Edge Container Service Agent
(
roles/
)edgecontainer.serviceAgent - Anthos Multi-Cloud Service Agent
(
roles/
)gkemulticloud.serviceAgent - GKE On-Prem Service Agent
(
roles/
)gkeonprem.serviceAgent - KRM API Hosting AnthosApiEndpoint Service Agent
(
roles/
)krmapihosting.anthosApiEndpointServiceAgent - Edge Container Cluster Service Agent
(
roles/
)edgecontainer.clusterServiceAgent
gkehub.
memberships.
generateConnectManifest
Owner
( roles/
)
Editor
( roles/
)
Viewer
( roles/
)
Fleet Admin (formerly GKE Hub Admin)
( roles/
)
Fleet Editor (formerly GKE Hub Editor)
( roles/
)
Fleet Viewer (formerly GKE Hub Viewer)
( roles/
)
Support User
( roles/
)
Service agent roles
- Edge Container Cluster Service Agent
(
roles/
)edgecontainer.clusterServiceAgent - Edge Container Service Agent
(
roles/
)edgecontainer.serviceAgent - Game Services Service Agent
(
roles/
)gameservices.serviceAgent - GKE Hub Service Agent
(
roles/
)gkehub.serviceAgent - Anthos Multi-Cloud Service Agent
(
roles/
)gkemulticloud.serviceAgent - KRM API Hosting AnthosApiEndpoint Service Agent
(
roles/
)krmapihosting.anthosApiEndpointServiceAgent - Mesh Managed Control Plane Service Agent
(
roles/
)meshcontrolplane.serviceAgent - Anthos Support Service Agent
(
roles/
)anthossupport.serviceAgent
gkehub.memberships.get
Owner
( roles/
)
Editor
( roles/
)
Viewer
( roles/
)
Fleet Admin (formerly GKE Hub Admin)
( roles/
)
Fleet Editor (formerly GKE Hub Editor)
( roles/
)
Connect Gateway Admin
( roles/
)
Connect Gateway Editor
( roles/
)
Connect Gateway Reader
( roles/
)
Fleet Project-level Scope Editor
( roles/
)
Fleet Project-level Scope Viewer
( roles/
)
Fleet Viewer (formerly GKE Hub Viewer)
( roles/
)
Support User
( roles/
)
Service agent roles
- Anthos Service Agent
(
roles/
)anthos.serviceAgent - Anthos Audit Service Agent
(
roles/
)anthosaudit.serviceAgent - Anthos Config Management Service Agent
(
roles/
)anthosconfigmanagement.serviceAgent - Anthos Identity Service Agent
(
roles/
)anthosidentityservice.serviceAgent - Anthos Policy Controller Service Agent
(
roles/
)anthospolicycontroller.serviceAgent - Anthos Service Mesh Service Agent
(
roles/
)anthosservicemesh.serviceAgent - Anthos Support Service Agent
(
roles/
)anthossupport.serviceAgent - App Development Experience Service Agent
(
roles/
)appdevelopmentexperience.serviceAgent - Config Delivery Service Agent
(
roles/
)configdelivery.serviceAgent - Edge Container Cluster Service Agent
(
roles/
)edgecontainer.clusterServiceAgent - Edge Container Service Agent
(
roles/
)edgecontainer.serviceAgent - Game Services Service Agent
(
roles/
)gameservices.serviceAgent - GKE Hub Service Agent
(
roles/
)gkehub.serviceAgent - Anthos Multi-Cloud Service Agent
(
roles/
)gkemulticloud.serviceAgent - GKE On-Prem Service Agent
(
roles/
)gkeonprem.serviceAgent - KRM API Hosting AnthosApiEndpoint Service Agent
(
roles/
)krmapihosting.anthosApiEndpointServiceAgent - Mesh Managed Control Plane Service Agent
(
roles/
)meshcontrolplane.serviceAgent - Multi Cluster Ingress Service Agent
(
roles/
)multiclusteringress.serviceAgent - Multi-cluster metering Service Agent
(
roles/
)multiclustermetering.serviceAgent - Multi-Cluster Service Discovery Service Agent
(
roles/
)multiclusterservicediscovery.serviceAgent - Service Directory Service Agent
(
roles/
)servicedirectory.serviceAgent - Workload Certificate Service Agent
(
roles/
)workloadcertificate.serviceAgent - Vertex AI Online Prediction Service Agent
(
roles/
)aiplatform.onlinePredictionServiceAgent
gkehub.
memberships.
getIamPolicy
Owner
( roles/
)
Editor
( roles/
)
Viewer
( roles/
)
Fleet Admin (formerly GKE Hub Admin)
( roles/
)
Fleet Editor (formerly GKE Hub Editor)
( roles/
)
Fleet Viewer (formerly GKE Hub Viewer)
( roles/
)
Security Admin
( roles/
)
Security Auditor
( roles/
)
Security Reviewer
( roles/
)
Support User
( roles/
)
Service agent roles
- Anthos Support Service Agent
(
roles/
)anthossupport.serviceAgent - Game Services Service Agent
(
roles/
)gameservices.serviceAgent - Anthos Multi-Cloud Service Agent
(
roles/
)gkemulticloud.serviceAgent - KRM API Hosting AnthosApiEndpoint Service Agent
(
roles/
)krmapihosting.anthosApiEndpointServiceAgent - Mesh Managed Control Plane Service Agent
(
roles/
)meshcontrolplane.serviceAgent - Vertex AI Online Prediction Service Agent
(
roles/
)aiplatform.onlinePredictionServiceAgent
gkehub.memberships.list
Owner
( roles/
)
Editor
( roles/
)
Viewer
( roles/
)
Fleet Admin (formerly GKE Hub Admin)
( roles/
)
Fleet Editor (formerly GKE Hub Editor)
( roles/
)
Fleet Viewer (formerly GKE Hub Viewer)
( roles/
)
Security Admin
( roles/
)
Security Auditor
( roles/
)
Security Reviewer
( roles/
)
Support User
( roles/
)
Service agent roles
- Anthos Service Agent
(
roles/
)anthos.serviceAgent - Anthos Audit Service Agent
(
roles/
)anthosaudit.serviceAgent - Anthos Config Management Service Agent
(
roles/
)anthosconfigmanagement.serviceAgent - Anthos Identity Service Agent
(
roles/
)anthosidentityservice.serviceAgent - Anthos Policy Controller Service Agent
(
roles/
)anthospolicycontroller.serviceAgent - Anthos Service Mesh Service Agent
(
roles/
)anthosservicemesh.serviceAgent - Anthos Support Service Agent
(
roles/
)anthossupport.serviceAgent - App Development Experience Service Agent
(
roles/
)appdevelopmentexperience.serviceAgent - Edge Container Cluster Service Agent
(
roles/
)edgecontainer.clusterServiceAgent - Edge Container Service Agent
(
roles/
)edgecontainer.serviceAgent - Game Services Service Agent
(
roles/
)gameservices.serviceAgent - GKE Hub Service Agent
(
roles/
)gkehub.serviceAgent - Anthos Multi-Cloud Service Agent
(
roles/
)gkemulticloud.serviceAgent - KRM API Hosting AnthosApiEndpoint Service Agent
(
roles/
)krmapihosting.anthosApiEndpointServiceAgent - Mesh Managed Control Plane Service Agent
(
roles/
)meshcontrolplane.serviceAgent - Multi Cluster Ingress Service Agent
(
roles/
)multiclusteringress.serviceAgent - Multi-cluster metering Service Agent
(
roles/
)multiclustermetering.serviceAgent - Multi-Cluster Service Discovery Service Agent
(
roles/
)multiclusterservicediscovery.serviceAgent - Service Directory Service Agent
(
roles/
)servicedirectory.serviceAgent - Workload Certificate Service Agent
(
roles/
)workloadcertificate.serviceAgent - Vertex AI Online Prediction Service Agent
(
roles/
)aiplatform.onlinePredictionServiceAgent
gkehub.
memberships.
setIamPolicy
Owner
( roles/
)
Fleet Admin (formerly GKE Hub Admin)
( roles/
)
Security Admin
( roles/
)
Service agent roles
- KRM API Hosting AnthosApiEndpoint Service Agent
(
roles/
)krmapihosting.anthosApiEndpointServiceAgent - Anthos Multi-Cloud Service Agent
(
roles/
)gkemulticloud.serviceAgent
gkehub.memberships.update
Owner
( roles/
)
Editor
( roles/
)
Fleet Admin (formerly GKE Hub Admin)
( roles/
)
Fleet Editor (formerly GKE Hub Editor)
( roles/
)
Service agent roles
- Edge Container Service Agent
(
roles/
)edgecontainer.serviceAgent - Anthos Multi-Cloud Service Agent
(
roles/
)gkemulticloud.serviceAgent - GKE On-Prem Service Agent
(
roles/
)gkeonprem.serviceAgent - KRM API Hosting AnthosApiEndpoint Service Agent
(
roles/
)krmapihosting.anthosApiEndpointServiceAgent - Edge Container Cluster Service Agent
(
roles/
)edgecontainer.clusterServiceAgent
gkehub.namespaces.create
Owner
( roles/
)
Editor
( roles/
)
Fleet Admin (formerly GKE Hub Admin)
( roles/
)
Fleet Editor (formerly GKE Hub Editor)
( roles/
)
Fleet Scope Admin
( roles/
)
Fleet Scope Editor
( roles/
)
Service agent roles
- KRM API Hosting AnthosApiEndpoint Service Agent
(
roles/
)krmapihosting.anthosApiEndpointServiceAgent - Anthos Multi-Cloud Service Agent
(
roles/
)gkemulticloud.serviceAgent
gkehub.namespaces.delete
Owner
( roles/
)
Editor
( roles/
)
Fleet Admin (formerly GKE Hub Admin)
( roles/
)
Fleet Editor (formerly GKE Hub Editor)
( roles/
)
Fleet Scope Admin
( roles/
)
Fleet Scope Editor
( roles/
)
Service agent roles
- KRM API Hosting AnthosApiEndpoint Service Agent
(
roles/
)krmapihosting.anthosApiEndpointServiceAgent - Anthos Multi-Cloud Service Agent
(
roles/
)gkemulticloud.serviceAgent
gkehub.namespaces.get
Owner
( roles/
)
Editor
( roles/
)
Viewer
( roles/
)
Fleet Admin (formerly GKE Hub Admin)
( roles/
)
Fleet Editor (formerly GKE Hub Editor)
( roles/
)
Fleet Scope Admin
( roles/
)
Fleet Scope Editor
( roles/
)
Fleet Scope Viewer
( roles/
)
Fleet Viewer (formerly GKE Hub Viewer)
( roles/
)
Support User
( roles/
)
Service agent roles
- Game Services Service Agent
(
roles/
)gameservices.serviceAgent - Anthos Multi-Cloud Service Agent
(
roles/
)gkemulticloud.serviceAgent - KRM API Hosting AnthosApiEndpoint Service Agent
(
roles/
)krmapihosting.anthosApiEndpointServiceAgent - Mesh Managed Control Plane Service Agent
(
roles/
)meshcontrolplane.serviceAgent - Anthos Support Service Agent
(
roles/
)anthossupport.serviceAgent
gkehub.namespaces.list
Owner
( roles/
)
Editor
( roles/
)
Viewer
( roles/
)
Fleet Admin (formerly GKE Hub Admin)
( roles/
)
Fleet Editor (formerly GKE Hub Editor)
( roles/
)
Fleet Scope Admin
( roles/
)
Fleet Scope Editor
( roles/
)
Fleet Scope Viewer
( roles/
)
Fleet Viewer (formerly GKE Hub Viewer)
( roles/
)
Security Admin
( roles/
)
Security Auditor
( roles/
)
Security Reviewer
( roles/
)
Support User
( roles/
)
Service agent roles
- Game Services Service Agent
(
roles/
)gameservices.serviceAgent - Anthos Multi-Cloud Service Agent
(
roles/
)gkemulticloud.serviceAgent - KRM API Hosting AnthosApiEndpoint Service Agent
(
roles/
)krmapihosting.anthosApiEndpointServiceAgent - Mesh Managed Control Plane Service Agent
(
roles/
)meshcontrolplane.serviceAgent - Anthos Support Service Agent
(
roles/
)anthossupport.serviceAgent
gkehub.namespaces.update
Owner
( roles/
)
Editor
( roles/
)
Fleet Admin (formerly GKE Hub Admin)
( roles/
)
Fleet Editor (formerly GKE Hub Editor)
( roles/
)
Service agent roles
- KRM API Hosting AnthosApiEndpoint Service Agent
(
roles/
)krmapihosting.anthosApiEndpointServiceAgent - Anthos Multi-Cloud Service Agent
(
roles/
)gkemulticloud.serviceAgent
gkehub.operations.cancel
Owner
( roles/
)
Editor
( roles/
)
Fleet Admin (formerly GKE Hub Admin)
( roles/
)
Fleet Editor (formerly GKE Hub Editor)
( roles/
)
Service agent roles
- Edge Container Service Agent
(
roles/
)edgecontainer.serviceAgent - Anthos Multi-Cloud Service Agent
(
roles/
)gkemulticloud.serviceAgent - KRM API Hosting AnthosApiEndpoint Service Agent
(
roles/
)krmapihosting.anthosApiEndpointServiceAgent - Edge Container Cluster Service Agent
(
roles/
)edgecontainer.clusterServiceAgent
gkehub.operations.delete
Owner
( roles/
)
Editor
( roles/
)
Fleet Admin (formerly GKE Hub Admin)
( roles/
)
Fleet Editor (formerly GKE Hub Editor)
( roles/
)
Service agent roles
- Anthos Multi-Cloud Service Agent
(
roles/
)gkemulticloud.serviceAgent - KRM API Hosting AnthosApiEndpoint Service Agent
(
roles/
)krmapihosting.anthosApiEndpointServiceAgent - Edge Container Cluster Service Agent
(
roles/
)edgecontainer.clusterServiceAgent
gkehub.operations.get
Owner
( roles/
)
Editor
( roles/
)
Viewer
( roles/
)
Fleet Admin (formerly GKE Hub Admin)
( roles/
)
Fleet Editor (formerly GKE Hub Editor)
( roles/
)
Fleet Project-level Scope Editor
( roles/
)
Fleet Viewer (formerly GKE Hub Viewer)
( roles/
)
Support User
( roles/
)
Service agent roles
- Edge Container Cluster Service Agent
(
roles/
)edgecontainer.clusterServiceAgent - Edge Container Service Agent
(
roles/
)edgecontainer.serviceAgent - Game Services Service Agent
(
roles/
)gameservices.serviceAgent - GKE Hub Service Agent
(
roles/
)gkehub.serviceAgent - Anthos Multi-Cloud Service Agent
(
roles/
)gkemulticloud.serviceAgent - KRM API Hosting AnthosApiEndpoint Service Agent
(
roles/
)krmapihosting.anthosApiEndpointServiceAgent - Mesh Managed Control Plane Service Agent
(
roles/
)meshcontrolplane.serviceAgent - Workload Certificate Service Agent
(
roles/
)workloadcertificate.serviceAgent - Anthos Support Service Agent
(
roles/
)anthossupport.serviceAgent
gkehub.operations.list
Owner
( roles/
)
Editor
( roles/
)
Viewer
( roles/
)
Fleet Admin (formerly GKE Hub Admin)
( roles/
)
Fleet Editor (formerly GKE Hub Editor)
( roles/
)
Fleet Viewer (formerly GKE Hub Viewer)
( roles/
)
Security Admin
( roles/
)
Security Auditor
( roles/
)
Security Reviewer
( roles/
)
Support User
( roles/
)
Service agent roles
- Edge Container Cluster Service Agent
(
roles/
)edgecontainer.clusterServiceAgent - Game Services Service Agent
(
roles/
)gameservices.serviceAgent - Anthos Multi-Cloud Service Agent
(
roles/
)gkemulticloud.serviceAgent - KRM API Hosting AnthosApiEndpoint Service Agent
(
roles/
)krmapihosting.anthosApiEndpointServiceAgent - Mesh Managed Control Plane Service Agent
(
roles/
)meshcontrolplane.serviceAgent - Anthos Support Service Agent
(
roles/
)anthossupport.serviceAgent
gkehub.rbacrolebindings.create
Owner
( roles/
)
Editor
( roles/
)
Fleet Admin (formerly GKE Hub Admin)
( roles/
)
Fleet Editor (formerly GKE Hub Editor)
( roles/
)
Fleet Scope Admin
( roles/
)
Service agent roles
- KRM API Hosting AnthosApiEndpoint Service Agent
(
roles/
)krmapihosting.anthosApiEndpointServiceAgent - Anthos Multi-Cloud Service Agent
(
roles/
)gkemulticloud.serviceAgent
gkehub.rbacrolebindings.delete
Owner
( roles/
)
Editor
( roles/
)
Fleet Admin (formerly GKE Hub Admin)
( roles/
)
Fleet Editor (formerly GKE Hub Editor)
( roles/
)
Fleet Scope Admin
( roles/
)
Service agent roles
- KRM API Hosting AnthosApiEndpoint Service Agent
(
roles/
)krmapihosting.anthosApiEndpointServiceAgent - Anthos Multi-Cloud Service Agent
(
roles/
)gkemulticloud.serviceAgent
gkehub.rbacrolebindings.get
Owner
( roles/
)
Editor
( roles/
)
Viewer
( roles/
)
Fleet Admin (formerly GKE Hub Admin)
( roles/
)
Fleet Editor (formerly GKE Hub Editor)
( roles/
)
Fleet Scope Admin
( roles/
)
Fleet Scope Editor
( roles/
)
Fleet Scope Viewer
( roles/
)
Fleet Viewer (formerly GKE Hub Viewer)
( roles/
)
Support User
( roles/
)
Service agent roles
- Game Services Service Agent
(
roles/
)gameservices.serviceAgent - Anthos Multi-Cloud Service Agent
(
roles/
)gkemulticloud.serviceAgent - KRM API Hosting AnthosApiEndpoint Service Agent
(
roles/
)krmapihosting.anthosApiEndpointServiceAgent - Mesh Managed Control Plane Service Agent
(
roles/
)meshcontrolplane.serviceAgent - Anthos Support Service Agent
(
roles/
)anthossupport.serviceAgent
gkehub.rbacrolebindings.list
Owner
( roles/
)
Editor
( roles/
)
Viewer
( roles/
)
Fleet Admin (formerly GKE Hub Admin)
( roles/
)
Fleet Editor (formerly GKE Hub Editor)
( roles/
)
Fleet Scope Admin
( roles/
)
Fleet Scope Editor
( roles/
)
Fleet Scope Viewer
( roles/
)
Fleet Viewer (formerly GKE Hub Viewer)
( roles/
)
Security Admin
( roles/
)
Security Auditor
( roles/
)
Security Reviewer
( roles/
)
Support User
( roles/
)
Service agent roles
- Game Services Service Agent
(
roles/
)gameservices.serviceAgent - Anthos Multi-Cloud Service Agent
(
roles/
)gkemulticloud.serviceAgent - KRM API Hosting AnthosApiEndpoint Service Agent
(
roles/
)krmapihosting.anthosApiEndpointServiceAgent - Mesh Managed Control Plane Service Agent
(
roles/
)meshcontrolplane.serviceAgent - Anthos Support Service Agent
(
roles/
)anthossupport.serviceAgent
gkehub.rbacrolebindings.update
Owner
( roles/
)
Editor
( roles/
)
Fleet Admin (formerly GKE Hub Admin)
( roles/
)
Fleet Editor (formerly GKE Hub Editor)
( roles/
)
Fleet Scope Admin
( roles/
)
Service agent roles
- KRM API Hosting AnthosApiEndpoint Service Agent
(
roles/
)krmapihosting.anthosApiEndpointServiceAgent - Anthos Multi-Cloud Service Agent
(
roles/
)gkemulticloud.serviceAgent
gkehub.scopes.create
Owner
( roles/
)
Editor
( roles/
)
Fleet Admin (formerly GKE Hub Admin)
( roles/
)
Fleet Editor (formerly GKE Hub Editor)
( roles/
)
Service agent roles
- KRM API Hosting AnthosApiEndpoint Service Agent
(
roles/
)krmapihosting.anthosApiEndpointServiceAgent - Anthos Multi-Cloud Service Agent
(
roles/
)gkemulticloud.serviceAgent
gkehub.scopes.delete
Owner
( roles/
)
Editor
( roles/
)
Fleet Admin (formerly GKE Hub Admin)
( roles/
)
Fleet Editor (formerly GKE Hub Editor)
( roles/
)
Service agent roles
- KRM API Hosting AnthosApiEndpoint Service Agent
(
roles/
)krmapihosting.anthosApiEndpointServiceAgent - Anthos Multi-Cloud Service Agent
(
roles/
)gkemulticloud.serviceAgent
gkehub.scopes.get
Owner
( roles/
)
Editor
( roles/
)
Viewer
( roles/
)
Fleet Admin (formerly GKE Hub Admin)
( roles/
)
Fleet Editor (formerly GKE Hub Editor)
( roles/
)
Fleet Scope Admin
( roles/
)
Fleet Scope Editor
( roles/
)
Fleet Scope Viewer
( roles/
)
Fleet Viewer (formerly GKE Hub Viewer)
( roles/
)
Support User
( roles/
)
Service agent roles
- Game Services Service Agent
(
roles/
)gameservices.serviceAgent - Anthos Multi-Cloud Service Agent
(
roles/
)gkemulticloud.serviceAgent - KRM API Hosting AnthosApiEndpoint Service Agent
(
roles/
)krmapihosting.anthosApiEndpointServiceAgent - Mesh Managed Control Plane Service Agent
(
roles/
)meshcontrolplane.serviceAgent - Anthos Support Service Agent
(
roles/
)anthossupport.serviceAgent
gkehub.scopes.getIamPolicy
Owner
( roles/
)
Editor
( roles/
)
Viewer
( roles/
)
Fleet Admin (formerly GKE Hub Admin)
( roles/
)
Fleet Editor (formerly GKE Hub Editor)
( roles/
)
Fleet Scope Admin
( roles/
)
Fleet Scope Editor
( roles/
)
Fleet Scope Viewer
( roles/
)
Security Admin
( roles/
)
Security Auditor
( roles/
)
Security Reviewer
( roles/
)
Support User
( roles/
)
Service agent roles
- KRM API Hosting AnthosApiEndpoint Service Agent
(
roles/
)krmapihosting.anthosApiEndpointServiceAgent - Anthos Multi-Cloud Service Agent
(
roles/
)gkemulticloud.serviceAgent
gkehub.scopes.list
Owner
( roles/
)
Editor
( roles/
)
Viewer
( roles/
)
Fleet Admin (formerly GKE Hub Admin)
( roles/
)
Fleet Editor (formerly GKE Hub Editor)
( roles/
)
Fleet Viewer (formerly GKE Hub Viewer)
( roles/
)
Security Admin
( roles/
)
Security Auditor
( roles/
)
Security Reviewer
( roles/
)
Support User
( roles/
)
Service agent roles
- Game Services Service Agent
(
roles/
)gameservices.serviceAgent - Anthos Multi-Cloud Service Agent
(
roles/
)gkemulticloud.serviceAgent - KRM API Hosting AnthosApiEndpoint Service Agent
(
roles/
)krmapihosting.anthosApiEndpointServiceAgent - Mesh Managed Control Plane Service Agent
(
roles/
)meshcontrolplane.serviceAgent - Anthos Support Service Agent
(
roles/
)anthossupport.serviceAgent
gkehub.
scopes.
listBoundMemberships
Owner
( roles/
)
Editor
( roles/
)
Viewer
( roles/
)
Fleet Admin (formerly GKE Hub Admin)
( roles/
)
Fleet Editor (formerly GKE Hub Editor)
( roles/
)
Fleet Scope Admin
( roles/
)
Fleet Scope Editor
( roles/
)
Fleet Scope Viewer
( roles/
)
Fleet Viewer (formerly GKE Hub Viewer)
( roles/
)
Support User
( roles/
)
Service agent roles
- Game Services Service Agent
(
roles/
)gameservices.serviceAgent - Anthos Multi-Cloud Service Agent
(
roles/
)gkemulticloud.serviceAgent - KRM API Hosting AnthosApiEndpoint Service Agent
(
roles/
)krmapihosting.anthosApiEndpointServiceAgent - Mesh Managed Control Plane Service Agent
(
roles/
)meshcontrolplane.serviceAgent - Anthos Support Service Agent
(
roles/
)anthossupport.serviceAgent
gkehub.scopes.setIamPolicy
Owner
( roles/
)
Fleet Admin (formerly GKE Hub Admin)
( roles/
)
Fleet Scope Admin
( roles/
)
Security Admin
( roles/
)
gkehub.scopes.update
Owner
( roles/
)
Editor
( roles/
)
Fleet Admin (formerly GKE Hub Admin)
( roles/
)
Fleet Editor (formerly GKE Hub Editor)
( roles/
)
Service agent roles
- KRM API Hosting AnthosApiEndpoint Service Agent
(
roles/
)krmapihosting.anthosApiEndpointServiceAgent - Anthos Multi-Cloud Service Agent
(
roles/
)gkemulticloud.serviceAgent