This page lists the IAM roles and permissions for Google Distributed Cloud. To search through all roles and permissions, see the role and permission index .
Google Distributed Cloud roles
GKE on-prem Admin
( roles/  
)
Full access to GKE on-prem all resources.
  gkeonprem.* 
 
-  gkeonprem.bareMetalAdminClusters. connect 
-  gkeonprem.bareMetalAdminClusters. create 
-  gkeonprem.bareMetalAdminClusters. createTagBinding 
-  gkeonprem.bareMetalAdminClusters. deleteTagBinding 
-  gkeonprem.bareMetalAdminClusters. enroll 
-  gkeonprem.bareMetalAdminClusters. get 
-  gkeonprem.bareMetalAdminClusters. getIamPolicy 
-  gkeonprem.bareMetalAdminClusters. list 
-  gkeonprem.bareMetalAdminClusters. listEffectiveTags 
-  gkeonprem.bareMetalAdminClusters. listTagBindings 
-  gkeonprem.bareMetalAdminClusters. queryVersionConfig 
-  gkeonprem.bareMetalAdminClusters. setIamPolicy 
-  gkeonprem.bareMetalAdminClusters. unenroll 
-  gkeonprem.bareMetalAdminClusters. update 
-  gkeonprem.bareMetalClusters. create 
-  gkeonprem.bareMetalClusters. createTagBinding 
-  gkeonprem.bareMetalClusters. delete 
-  gkeonprem.bareMetalClusters. deleteTagBinding 
-  gkeonprem.bareMetalClusters. enroll 
-  gkeonprem.bareMetalClusters. get 
-  gkeonprem.bareMetalClusters. getIamPolicy 
-  gkeonprem.bareMetalClusters. list 
-  gkeonprem.bareMetalClusters. listEffectiveTags 
-  gkeonprem.bareMetalClusters. listTagBindings 
-  gkeonprem.bareMetalClusters. queryVersionConfig 
-  gkeonprem.bareMetalClusters. setIamPolicy 
-  gkeonprem.bareMetalClusters. unenroll 
-  gkeonprem.bareMetalClusters. update 
-  gkeonprem.bareMetalNodePools. create 
-  gkeonprem.bareMetalNodePools. delete 
-  gkeonprem.bareMetalNodePools. enroll 
-  gkeonprem.bareMetalNodePools. get 
-  gkeonprem.bareMetalNodePools. getIamPolicy 
-  gkeonprem.bareMetalNodePools. list 
-  gkeonprem.bareMetalNodePools. setIamPolicy 
-  gkeonprem.bareMetalNodePools. unenroll 
-  gkeonprem.bareMetalNodePools. update 
-  gkeonprem.locations.get
-  gkeonprem.locations.list
-  gkeonprem.operations.cancel
-  gkeonprem.operations.delete
-  gkeonprem.operations.get
-  gkeonprem.operations.list
-  gkeonprem.vmwareAdminClusters. connect 
-  gkeonprem.vmwareAdminClusters. createTagBinding 
-  gkeonprem.vmwareAdminClusters. deleteTagBinding 
-  gkeonprem.vmwareAdminClusters. enroll 
-  gkeonprem.vmwareAdminClusters. get 
-  gkeonprem.vmwareAdminClusters. getIamPolicy 
-  gkeonprem.vmwareAdminClusters. list 
-  gkeonprem.vmwareAdminClusters. listEffectiveTags 
-  gkeonprem.vmwareAdminClusters. listTagBindings 
-  gkeonprem.vmwareAdminClusters. setIamPolicy 
-  gkeonprem.vmwareAdminClusters. unenroll 
-  gkeonprem.vmwareAdminClusters. update 
-  gkeonprem.vmwareClusters. create 
-  gkeonprem.vmwareClusters. createTagBinding 
-  gkeonprem.vmwareClusters. delete 
-  gkeonprem.vmwareClusters. deleteTagBinding 
-  gkeonprem.vmwareClusters. enroll 
-  gkeonprem.vmwareClusters.get
-  gkeonprem.vmwareClusters. getIamPolicy 
-  gkeonprem.vmwareClusters.list
-  gkeonprem.vmwareClusters. listEffectiveTags 
-  gkeonprem.vmwareClusters. listTagBindings 
-  gkeonprem.vmwareClusters. queryVersionConfig 
-  gkeonprem.vmwareClusters. setIamPolicy 
-  gkeonprem.vmwareClusters. unenroll 
-  gkeonprem.vmwareClusters. update 
-  gkeonprem.vmwareNodePools. create 
-  gkeonprem.vmwareNodePools. delete 
-  gkeonprem.vmwareNodePools. enroll 
-  gkeonprem.vmwareNodePools.get
-  gkeonprem.vmwareNodePools. getIamPolicy 
-  gkeonprem.vmwareNodePools.list
-  gkeonprem.vmwareNodePools. setIamPolicy 
-  gkeonprem.vmwareNodePools. unenroll 
-  gkeonprem.vmwareNodePools. update 
 resourcemanager.projects.get 
 resourcemanager.projects.list 
GKE On-Prem Service Agent
( roles/  
)
Gives the GKE On-Prem service agent access to Cloud Platform resources.
 gkehub.memberships.delete 
 gkehub.memberships.get 
 gkehub.memberships.update 
 gkeonprem.  
 gkeonprem.  
 gkeonprem.  
 gkeonprem.  
 gkeonprem.  
 gkeonprem.  
 gkeonprem.  
 gkeonprem.  
 gkeonprem.  
 gkeonprem.  
 gkeonprem.operations.get 
 gkeonprem.operations.list 
 gkeonprem.  
 gkeonprem.  
 gkeonprem.  
 gkeonprem.  
 gkeonprem.  
 gkeonprem.vmwareClusters.get 
 gkeonprem.  
 gkeonprem.  
 gkeonprem.vmwareNodePools.get 
 gkeonprem.  
GKE on-prem Viewer
( roles/  
)
Read-only access to GKE on-prem all resources.
 gkeonprem.  
 gkeonprem.  
 gkeonprem.  
 gkeonprem.  
 gkeonprem.  
 gkeonprem.  
 gkeonprem.  
 gkeonprem.  
 gkeonprem.  
 gkeonprem.  
 gkeonprem.  
 gkeonprem.  
 gkeonprem.  
 gkeonprem.  
 gkeonprem.  
 gkeonprem.  
  gkeonprem.locations.* 
 
-  gkeonprem.locations.get
-  gkeonprem.locations.list
 gkeonprem.operations.get 
 gkeonprem.operations.list 
 gkeonprem.  
 gkeonprem.  
 gkeonprem.  
 gkeonprem.  
 gkeonprem.  
 gkeonprem.  
 gkeonprem.vmwareClusters.get 
 gkeonprem.  
 gkeonprem.vmwareClusters.list 
 gkeonprem.  
 gkeonprem.  
 gkeonprem.  
 gkeonprem.vmwareNodePools.get 
 gkeonprem.  
 gkeonprem.vmwareNodePools.list 
 resourcemanager.projects.get 
 resourcemanager.projects.list 
Google Distributed Cloud permissions
 gkeonprem.  
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Viewer 
( roles/  
)
 GKE on-prem Admin 
( roles/  
)
 GKE on-prem Viewer 
( roles/  
)
 Support User 
( roles/  
)
Service agent roles
-  GKE On-Prem Service Agent 
( roles/)gkeonprem.serviceAgent 
 gkeonprem.  
 
 gkeonprem.  
 
 Owner 
( roles/  
)
 DLP Organization Data Profiles Driver 
( roles/  
)
 DLP Project Data Profiles Driver 
( roles/  
)
 GKE on-prem Admin 
( roles/  
)
 Tag User 
( roles/  
)
 gkeonprem.  
 
 Owner 
( roles/  
)
 DLP Organization Data Profiles Driver 
( roles/  
)
 DLP Project Data Profiles Driver 
( roles/  
)
 GKE on-prem Admin 
( roles/  
)
 Tag User 
( roles/  
)
 gkeonprem.  
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 GKE on-prem Admin 
( roles/  
)
Service agent roles
-  GKE On-Prem Service Agent 
( roles/)gkeonprem.serviceAgent 
 gkeonprem.  
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Viewer 
( roles/  
)
 GKE on-prem Admin 
( roles/  
)
 GKE on-prem Viewer 
( roles/  
)
 Support User 
( roles/  
)
Service agent roles
-  GKE On-Prem Service Agent 
( roles/)gkeonprem.serviceAgent 
 gkeonprem.  
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Viewer 
( roles/  
)
 GKE on-prem Admin 
( roles/  
)
 GKE on-prem Viewer 
( roles/  
)
 Security Admin 
( roles/  
)
 Security Auditor 
( roles/  
)
 Security Reviewer 
( roles/  
)
 Support User 
( roles/  
)
 gkeonprem.  
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Viewer 
( roles/  
)
 GKE on-prem Admin 
( roles/  
)
 GKE on-prem Viewer 
( roles/  
)
 Security Admin 
( roles/  
)
 Security Auditor 
( roles/  
)
 Security Reviewer 
( roles/  
)
 Support User 
( roles/  
)
 gkeonprem.  
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Viewer 
( roles/  
)
 DLP Organization Data Profiles Driver 
( roles/  
)
 DLP Project Data Profiles Driver 
( roles/  
)
 GKE on-prem Admin 
( roles/  
)
 GKE on-prem Viewer 
( roles/  
)
 Security Auditor 
( roles/  
)
 Support User 
( roles/  
)
 Tag User 
( roles/  
)
 Tag Viewer 
( roles/  
)
 gkeonprem.  
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Viewer 
( roles/  
)
 DLP Organization Data Profiles Driver 
( roles/  
)
 DLP Project Data Profiles Driver 
( roles/  
)
 GKE on-prem Admin 
( roles/  
)
 GKE on-prem Viewer 
( roles/  
)
 Security Auditor 
( roles/  
)
 Support User 
( roles/  
)
 Tag User 
( roles/  
)
 Tag Viewer 
( roles/  
)
 gkeonprem.  
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Viewer 
( roles/  
)
 GKE on-prem Admin 
( roles/  
)
 GKE on-prem Viewer 
( roles/  
)
 Support User 
( roles/  
)
 gkeonprem.  
 
 Owner 
( roles/  
)
 GKE on-prem Admin 
( roles/  
)
 Security Admin 
( roles/  
)
 gkeonprem.  
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 GKE on-prem Admin 
( roles/  
)
Service agent roles
-  GKE On-Prem Service Agent 
( roles/)gkeonprem.serviceAgent 
 gkeonprem.  
 
 gkeonprem.  
 
 gkeonprem.  
 
 Owner 
( roles/  
)
 DLP Organization Data Profiles Driver 
( roles/  
)
 DLP Project Data Profiles Driver 
( roles/  
)
 GKE on-prem Admin 
( roles/  
)
 Tag User 
( roles/  
)
 gkeonprem.  
 
 gkeonprem.  
 
 Owner 
( roles/  
)
 DLP Organization Data Profiles Driver 
( roles/  
)
 DLP Project Data Profiles Driver 
( roles/  
)
 GKE on-prem Admin 
( roles/  
)
 Tag User 
( roles/  
)
 gkeonprem.  
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 GKE on-prem Admin 
( roles/  
)
Service agent roles
-  GKE On-Prem Service Agent 
( roles/)gkeonprem.serviceAgent 
 gkeonprem.  
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Viewer 
( roles/  
)
 GKE on-prem Admin 
( roles/  
)
 GKE on-prem Viewer 
( roles/  
)
 Support User 
( roles/  
)
Service agent roles
-  GKE On-Prem Service Agent 
( roles/)gkeonprem.serviceAgent 
-  GKE Hub Service Agent 
( roles/)gkehub.serviceAgent 
 gkeonprem.  
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Viewer 
( roles/  
)
 GKE on-prem Admin 
( roles/  
)
 GKE on-prem Viewer 
( roles/  
)
 Security Admin 
( roles/  
)
 Security Auditor 
( roles/  
)
 Security Reviewer 
( roles/  
)
 Support User 
( roles/  
)
 gkeonprem.  
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Viewer 
( roles/  
)
 GKE on-prem Admin 
( roles/  
)
 GKE on-prem Viewer 
( roles/  
)
 Security Admin 
( roles/  
)
 Security Auditor 
( roles/  
)
 Security Reviewer 
( roles/  
)
 Support User 
( roles/  
)
 gkeonprem.  
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Viewer 
( roles/  
)
 DLP Organization Data Profiles Driver 
( roles/  
)
 DLP Project Data Profiles Driver 
( roles/  
)
 GKE on-prem Admin 
( roles/  
)
 GKE on-prem Viewer 
( roles/  
)
 Security Auditor 
( roles/  
)
 Support User 
( roles/  
)
 Tag User 
( roles/  
)
 Tag Viewer 
( roles/  
)
 gkeonprem.  
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Viewer 
( roles/  
)
 DLP Organization Data Profiles Driver 
( roles/  
)
 DLP Project Data Profiles Driver 
( roles/  
)
 GKE on-prem Admin 
( roles/  
)
 GKE on-prem Viewer 
( roles/  
)
 Security Auditor 
( roles/  
)
 Support User 
( roles/  
)
 Tag User 
( roles/  
)
 Tag Viewer 
( roles/  
)
 gkeonprem.  
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Viewer 
( roles/  
)
 GKE on-prem Admin 
( roles/  
)
 GKE on-prem Viewer 
( roles/  
)
 Support User 
( roles/  
)
 gkeonprem.  
 
 Owner 
( roles/  
)
 GKE on-prem Admin 
( roles/  
)
 Security Admin 
( roles/  
)
 gkeonprem.  
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 GKE on-prem Admin 
( roles/  
)
Service agent roles
-  GKE On-Prem Service Agent 
( roles/)gkeonprem.serviceAgent 
 gkeonprem.  
 
 gkeonprem.  
 
 gkeonprem.  
 
 gkeonprem.  
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 GKE on-prem Admin 
( roles/  
)
Service agent roles
-  GKE On-Prem Service Agent 
( roles/)gkeonprem.serviceAgent 
 gkeonprem.  
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Viewer 
( roles/  
)
 GKE on-prem Admin 
( roles/  
)
 GKE on-prem Viewer 
( roles/  
)
 Support User 
( roles/  
)
Service agent roles
-  GKE On-Prem Service Agent 
( roles/)gkeonprem.serviceAgent 
 gkeonprem.  
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Viewer 
( roles/  
)
 GKE on-prem Admin 
( roles/  
)
 GKE on-prem Viewer 
( roles/  
)
 Security Admin 
( roles/  
)
 Security Auditor 
( roles/  
)
 Security Reviewer 
( roles/  
)
 Support User 
( roles/  
)
 gkeonprem.  
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Viewer 
( roles/  
)
 GKE on-prem Admin 
( roles/  
)
 GKE on-prem Viewer 
( roles/  
)
 Security Admin 
( roles/  
)
 Security Auditor 
( roles/  
)
 Security Reviewer 
( roles/  
)
 Support User 
( roles/  
)
 gkeonprem.  
 
 Owner 
( roles/  
)
 GKE on-prem Admin 
( roles/  
)
 Security Admin 
( roles/  
)
 gkeonprem.  
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 GKE on-prem Admin 
( roles/  
)
Service agent roles
-  GKE On-Prem Service Agent 
( roles/)gkeonprem.serviceAgent 
 gkeonprem.  
 
 gkeonprem.locations.get 
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Viewer 
( roles/  
)
 GKE on-prem Admin 
( roles/  
)
 GKE on-prem Viewer 
( roles/  
)
 Support User 
( roles/  
)
 gkeonprem.locations.list 
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Viewer 
( roles/  
)
 GKE on-prem Admin 
( roles/  
)
 GKE on-prem Viewer 
( roles/  
)
 Security Admin 
( roles/  
)
 Security Auditor 
( roles/  
)
 Security Reviewer 
( roles/  
)
 Support User 
( roles/  
)
 gkeonprem.operations.cancel 
 
 gkeonprem.operations.delete 
 
 gkeonprem.operations.get 
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Viewer 
( roles/  
)
 GKE on-prem Admin 
( roles/  
)
 GKE on-prem Viewer 
( roles/  
)
 Support User 
( roles/  
)
Service agent roles
-  GKE On-Prem Service Agent 
( roles/)gkeonprem.serviceAgent 
 gkeonprem.operations.list 
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Viewer 
( roles/  
)
 GKE on-prem Admin 
( roles/  
)
 GKE on-prem Viewer 
( roles/  
)
 Security Admin 
( roles/  
)
 Security Auditor 
( roles/  
)
 Security Reviewer 
( roles/  
)
 Support User 
( roles/  
)
Service agent roles
-  GKE On-Prem Service Agent 
( roles/)gkeonprem.serviceAgent 
 gkeonprem.  
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Viewer 
( roles/  
)
 GKE on-prem Admin 
( roles/  
)
 GKE on-prem Viewer 
( roles/  
)
 Support User 
( roles/  
)
Service agent roles
-  GKE On-Prem Service Agent 
( roles/)gkeonprem.serviceAgent 
 gkeonprem.  
 
 Owner 
( roles/  
)
 DLP Organization Data Profiles Driver 
( roles/  
)
 DLP Project Data Profiles Driver 
( roles/  
)
 GKE on-prem Admin 
( roles/  
)
 Tag User 
( roles/  
)
 gkeonprem.  
 
 Owner 
( roles/  
)
 DLP Organization Data Profiles Driver 
( roles/  
)
 DLP Project Data Profiles Driver 
( roles/  
)
 GKE on-prem Admin 
( roles/  
)
 Tag User 
( roles/  
)
 gkeonprem.  
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 GKE on-prem Admin 
( roles/  
)
Service agent roles
-  GKE On-Prem Service Agent 
( roles/)gkeonprem.serviceAgent 
 gkeonprem.  
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Viewer 
( roles/  
)
 GKE on-prem Admin 
( roles/  
)
 GKE on-prem Viewer 
( roles/  
)
 Support User 
( roles/  
)
Service agent roles
-  GKE On-Prem Service Agent 
( roles/)gkeonprem.serviceAgent 
 gkeonprem.  
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Viewer 
( roles/  
)
 GKE on-prem Admin 
( roles/  
)
 GKE on-prem Viewer 
( roles/  
)
 Security Admin 
( roles/  
)
 Security Auditor 
( roles/  
)
 Security Reviewer 
( roles/  
)
 Support User 
( roles/  
)
 gkeonprem.  
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Viewer 
( roles/  
)
 GKE on-prem Admin 
( roles/  
)
 GKE on-prem Viewer 
( roles/  
)
 Security Admin 
( roles/  
)
 Security Auditor 
( roles/  
)
 Security Reviewer 
( roles/  
)
 Support User 
( roles/  
)
 gkeonprem.  
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Viewer 
( roles/  
)
 DLP Organization Data Profiles Driver 
( roles/  
)
 DLP Project Data Profiles Driver 
( roles/  
)
 GKE on-prem Admin 
( roles/  
)
 GKE on-prem Viewer 
( roles/  
)
 Security Auditor 
( roles/  
)
 Support User 
( roles/  
)
 Tag User 
( roles/  
)
 Tag Viewer 
( roles/  
)
 gkeonprem.  
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Viewer 
( roles/  
)
 DLP Organization Data Profiles Driver 
( roles/  
)
 DLP Project Data Profiles Driver 
( roles/  
)
 GKE on-prem Admin 
( roles/  
)
 GKE on-prem Viewer 
( roles/  
)
 Security Auditor 
( roles/  
)
 Support User 
( roles/  
)
 Tag User 
( roles/  
)
 Tag Viewer 
( roles/  
)
 gkeonprem.  
 
 Owner 
( roles/  
)
 GKE on-prem Admin 
( roles/  
)
 Security Admin 
( roles/  
)
 gkeonprem.  
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 GKE on-prem Admin 
( roles/  
)
Service agent roles
-  GKE On-Prem Service Agent 
( roles/)gkeonprem.serviceAgent 
 gkeonprem.  
 
 gkeonprem.  
 
 gkeonprem.  
 
 Owner 
( roles/  
)
 DLP Organization Data Profiles Driver 
( roles/  
)
 DLP Project Data Profiles Driver 
( roles/  
)
 GKE on-prem Admin 
( roles/  
)
 Tag User 
( roles/  
)
 gkeonprem.  
 
 gkeonprem.  
 
 Owner 
( roles/  
)
 DLP Organization Data Profiles Driver 
( roles/  
)
 DLP Project Data Profiles Driver 
( roles/  
)
 GKE on-prem Admin 
( roles/  
)
 Tag User 
( roles/  
)
 gkeonprem.  
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 GKE on-prem Admin 
( roles/  
)
Service agent roles
-  GKE On-Prem Service Agent 
( roles/)gkeonprem.serviceAgent 
 gkeonprem.vmwareClusters.get 
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Viewer 
( roles/  
)
 GKE on-prem Admin 
( roles/  
)
 GKE on-prem Viewer 
( roles/  
)
 Support User 
( roles/  
)
Service agent roles
-  GKE On-Prem Service Agent 
( roles/)gkeonprem.serviceAgent 
-  GKE Hub Service Agent 
( roles/)gkehub.serviceAgent 
 gkeonprem.  
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Viewer 
( roles/  
)
 GKE on-prem Admin 
( roles/  
)
 GKE on-prem Viewer 
( roles/  
)
 Security Admin 
( roles/  
)
 Security Auditor 
( roles/  
)
 Security Reviewer 
( roles/  
)
 Support User 
( roles/  
)
 gkeonprem.vmwareClusters.list 
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Viewer 
( roles/  
)
 GKE on-prem Admin 
( roles/  
)
 GKE on-prem Viewer 
( roles/  
)
 Security Admin 
( roles/  
)
 Security Auditor 
( roles/  
)
 Security Reviewer 
( roles/  
)
 Support User 
( roles/  
)
 gkeonprem.  
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Viewer 
( roles/  
)
 DLP Organization Data Profiles Driver 
( roles/  
)
 DLP Project Data Profiles Driver 
( roles/  
)
 GKE on-prem Admin 
( roles/  
)
 GKE on-prem Viewer 
( roles/  
)
 Security Auditor 
( roles/  
)
 Support User 
( roles/  
)
 Tag User 
( roles/  
)
 Tag Viewer 
( roles/  
)
 gkeonprem.  
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Viewer 
( roles/  
)
 DLP Organization Data Profiles Driver 
( roles/  
)
 DLP Project Data Profiles Driver 
( roles/  
)
 GKE on-prem Admin 
( roles/  
)
 GKE on-prem Viewer 
( roles/  
)
 Security Auditor 
( roles/  
)
 Support User 
( roles/  
)
 Tag User 
( roles/  
)
 Tag Viewer 
( roles/  
)
 gkeonprem.  
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Viewer 
( roles/  
)
 GKE on-prem Admin 
( roles/  
)
 GKE on-prem Viewer 
( roles/  
)
 Support User 
( roles/  
)
 gkeonprem.  
 
 Owner 
( roles/  
)
 GKE on-prem Admin 
( roles/  
)
 Security Admin 
( roles/  
)
 gkeonprem.  
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 GKE on-prem Admin 
( roles/  
)
Service agent roles
-  GKE On-Prem Service Agent 
( roles/)gkeonprem.serviceAgent 
 gkeonprem.  
 
 gkeonprem.  
 
 gkeonprem.  
 
 gkeonprem.  
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 GKE on-prem Admin 
( roles/  
)
Service agent roles
-  GKE On-Prem Service Agent 
( roles/)gkeonprem.serviceAgent 
 gkeonprem.vmwareNodePools.get 
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Viewer 
( roles/  
)
 GKE on-prem Admin 
( roles/  
)
 GKE on-prem Viewer 
( roles/  
)
 Support User 
( roles/  
)
Service agent roles
-  GKE On-Prem Service Agent 
( roles/)gkeonprem.serviceAgent 
 gkeonprem.  
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Viewer 
( roles/  
)
 GKE on-prem Admin 
( roles/  
)
 GKE on-prem Viewer 
( roles/  
)
 Security Admin 
( roles/  
)
 Security Auditor 
( roles/  
)
 Security Reviewer 
( roles/  
)
 Support User 
( roles/  
)
 gkeonprem.vmwareNodePools.list 
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Viewer 
( roles/  
)
 GKE on-prem Admin 
( roles/  
)
 GKE on-prem Viewer 
( roles/  
)
 Security Admin 
( roles/  
)
 Security Auditor 
( roles/  
)
 Security Reviewer 
( roles/  
)
 Support User 
( roles/  
)
 gkeonprem.  
 
 Owner 
( roles/  
)
 GKE on-prem Admin 
( roles/  
)
 Security Admin 
( roles/  
)
 gkeonprem.  
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 GKE on-prem Admin 
( roles/  
)
Service agent roles
-  GKE On-Prem Service Agent 
( roles/)gkeonprem.serviceAgent 

