This page lists the IAM roles and permissions for Service Networking. To search through all roles and permissions, see the role and permission index .
Service Networking roles
Service Networking Admin Beta
( roles/  
)
Full control of service networking with projects.
  servicenetworking.* 
 
-  servicenetworking.operations. cancel 
-  servicenetworking.operations. delete 
-  servicenetworking.operations. get 
-  servicenetworking.operations. list 
-  servicenetworking.services. addDnsRecordSet 
-  servicenetworking.services. addDnsZone 
-  servicenetworking.services. addPeering 
-  servicenetworking.services. addSubnetwork 
-  servicenetworking.services. createPeeredDnsDomain 
-  servicenetworking.services. deleteConnection 
-  servicenetworking.services. deletePeeredDnsDomain 
-  servicenetworking.services. disableVpcServiceControls 
-  servicenetworking.services. enableVpcServiceControls 
-  servicenetworking.services.get
-  servicenetworking.services. getConsumerConfig 
-  servicenetworking.services. listPeeredDnsDomains 
-  servicenetworking.services. removeDnsRecordSet 
-  servicenetworking.services. removeDnsZone 
-  servicenetworking.services. updateConsumerConfig 
-  servicenetworking.services. updateDnsRecordSet 
-  servicenetworking.services.use
Service Networking Service Agent
( roles/  
)
Gives permission to manage network configuration, such as establishing network peering, necessary for service producers
 compute.globalAddresses.get 
 compute.globalAddresses.list 
 compute.globalOperations.get 
 compute.networks.addPeering 
 compute.networks.create 
 compute.networks.delete 
 compute.networks.get 
 compute.networks.list 
 compute.  
 compute.networks.removePeering 
 compute.networks.update 
 compute.networks.updatePeering 
 compute.networks.updatePolicy 
 compute.projects.get 
 compute.regionOperations.get 
 compute.routers.get 
 compute.routers.list 
 compute.routes.list 
 compute.subnetworks.create 
 compute.subnetworks.delete 
 compute.subnetworks.get 
 compute.subnetworks.list 
  dns.changes.* 
 
-  dns.changes.create
-  dns.changes.get
-  dns.changes.list
  dns.dnsKeys.* 
 
-  dns.dnsKeys.get
-  dns.dnsKeys.list
  dns.gkeClusters.* 
 
-  dns.gkeClusters. bindDNSResponsePolicy 
-  dns.gkeClusters. bindPrivateDNSZone 
  dns.managedZoneOperations.* 
 
-  dns.managedZoneOperations.get
-  dns.managedZoneOperations.list
 dns.managedZones.create 
 dns.managedZones.delete 
 dns.managedZones.get 
 dns.managedZones.getIamPolicy 
 dns.managedZones.list 
 dns.managedZones.update 
  dns.networks.* 
 
-  dns.networks. bindDNSResponsePolicy 
-  dns.networks. bindPrivateDNSPolicy 
-  dns.networks. bindPrivateDNSZone 
-  dns.networks. targetWithPeeringZone 
-  dns.networks.useHealthSignals
  dns.policies.* 
 
-  dns.policies.create
-  dns.policies.delete
-  dns.policies.get
-  dns.policies.list
-  dns.policies.update
 dns.projects.get 
  dns.resourceRecordSets.* 
 
-  dns.resourceRecordSets.create
-  dns.resourceRecordSets.delete
-  dns.resourceRecordSets.get
-  dns.resourceRecordSets.list
-  dns.resourceRecordSets.update
  dns.responsePolicies.* 
 
-  dns.responsePolicies.create
-  dns.responsePolicies.delete
-  dns.responsePolicies.get
-  dns.responsePolicies.list
-  dns.responsePolicies.update
  dns.responsePolicyRules.* 
 
-  dns.responsePolicyRules.create
-  dns.responsePolicyRules.delete
-  dns.responsePolicyRules.get
-  dns.responsePolicyRules.list
-  dns.responsePolicyRules.update
 networkconnectivity.  
 resourcemanager.projects.get 
 resourcemanager.projects.list 
Service Networking permissions
 servicenetworking.  
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Service Networking Admin 
( roles/  
)
 servicenetworking.  
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Service Networking Admin 
( roles/  
)
 servicenetworking.  
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Viewer 
( roles/  
)
 Compute Network Admin 
( roles/  
)
 Infrastructure Administrator 
( roles/  
)
 Network Administrator 
( roles/  
)
 Support User 
( roles/  
)
 Service Networking Admin 
( roles/  
)
Service agent roles
-  Cloud TPU V2 API Service Agent 
( roles/)cloudtpu.serviceAgent 
-  Cloud Composer API Service Agent 
( roles/)composer.serviceAgent 
-  Kubernetes Engine Service Agent 
( roles/)container.serviceAgent 
-  Cloud Dataflow Service Agent 
( roles/)dataflow.serviceAgent 
-  Cloud Deployment Manager Service Agent 
( roles/)clouddeploymentmanager.serviceAgent 
 servicenetworking.  
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Viewer 
( roles/  
)
 Security Admin 
( roles/  
)
 Security Auditor 
( roles/  
)
 Security Reviewer 
( roles/  
)
 Support User 
( roles/  
)
 Service Networking Admin 
( roles/  
)
 servicenetworking.  
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Service Networking Admin 
( roles/  
)
 servicenetworking.  
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Service Networking Admin 
( roles/  
)
 servicenetworking.  
 
 Owner 
( roles/  
)
 Compute Network Admin 
( roles/  
)
 Infrastructure Administrator 
( roles/  
)
 Network Administrator 
( roles/  
)
 Service Networking Admin 
( roles/  
)
Service agent roles
-  Cloud TPU V2 API Service Agent 
( roles/)cloudtpu.serviceAgent 
-  Cloud Composer API Service Agent 
( roles/)composer.serviceAgent 
-  Kubernetes Engine Service Agent 
( roles/)container.serviceAgent 
-  Cloud Dataflow Service Agent 
( roles/)dataflow.serviceAgent 
-  Cloud Deployment Manager Service Agent 
( roles/)clouddeploymentmanager.serviceAgent 
 servicenetworking.  
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Service Networking Admin 
( roles/  
)
 servicenetworking.  
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Compute Network Admin 
( roles/  
)
 Infrastructure Administrator 
( roles/  
)
 Network Administrator 
( roles/  
)
 Service Networking Admin 
( roles/  
)
Service agent roles
-  Cloud Composer API Service Agent 
( roles/)composer.serviceAgent 
-  Kubernetes Engine Service Agent 
( roles/)container.serviceAgent 
-  Cloud Dataflow Service Agent 
( roles/)dataflow.serviceAgent 
-  Cloud TPU V2 API Service Agent 
( roles/)cloudtpu.serviceAgent 
 servicenetworking.  
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Compute Network Admin 
( roles/  
)
 Infrastructure Administrator 
( roles/  
)
 Network Administrator 
( roles/  
)
 Service Networking Admin 
( roles/  
)
Service agent roles
-  Cloud Composer API Service Agent 
( roles/)composer.serviceAgent 
-  Kubernetes Engine Service Agent 
( roles/)container.serviceAgent 
-  Cloud Dataflow Service Agent 
( roles/)dataflow.serviceAgent 
-  Cloud TPU V2 API Service Agent 
( roles/)cloudtpu.serviceAgent 
 servicenetworking.  
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Compute Network Admin 
( roles/  
)
 Infrastructure Administrator 
( roles/  
)
 Network Administrator 
( roles/  
)
 Service Networking Admin 
( roles/  
)
Service agent roles
-  Cloud Composer API Service Agent 
( roles/)composer.serviceAgent 
-  Kubernetes Engine Service Agent 
( roles/)container.serviceAgent 
-  Cloud Dataflow Service Agent 
( roles/)dataflow.serviceAgent 
-  Cloud TPU V2 API Service Agent 
( roles/)cloudtpu.serviceAgent 
 servicenetworking.  
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Compute Network Admin 
( roles/  
)
 Infrastructure Administrator 
( roles/  
)
 Network Administrator 
( roles/  
)
 Service Networking Admin 
( roles/  
)
Service agent roles
-  Cloud Composer API Service Agent 
( roles/)composer.serviceAgent 
-  Kubernetes Engine Service Agent 
( roles/)container.serviceAgent 
-  Cloud Dataflow Service Agent 
( roles/)dataflow.serviceAgent 
-  Cloud TPU V2 API Service Agent 
( roles/)cloudtpu.serviceAgent 
 servicenetworking.  
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Compute Network Admin 
( roles/  
)
 Infrastructure Administrator 
( roles/  
)
 Network Administrator 
( roles/  
)
 Service Networking Admin 
( roles/  
)
Service agent roles
-  Cloud Composer API Service Agent 
( roles/)composer.serviceAgent 
-  Kubernetes Engine Service Agent 
( roles/)container.serviceAgent 
-  Cloud Dataflow Service Agent 
( roles/)dataflow.serviceAgent 
-  Cloud TPU V2 API Service Agent 
( roles/)cloudtpu.serviceAgent 
 servicenetworking.services.get 
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Viewer 
( roles/  
)
 Compute Network Admin 
( roles/  
)
 Compute Network User 
( roles/  
)
 Compute Network Viewer 
( roles/  
)
 Infrastructure Administrator 
( roles/  
)
 Network Administrator 
( roles/  
)
 Security Auditor 
( roles/  
)
 Support User 
( roles/  
)
 Service Networking Admin 
( roles/  
)
Service agent roles
-  Cloud TPU V2 API Service Agent 
( roles/)cloudtpu.serviceAgent 
-  Cloud Composer API Service Agent 
( roles/)composer.serviceAgent 
-  Kubernetes Engine Service Agent 
( roles/)container.serviceAgent 
-  Cloud Dataflow Service Agent 
( roles/)dataflow.serviceAgent 
-  Cloud Data Fusion API Service Agent 
( roles/)datafusion.serviceAgent 
-  Cloud Deployment Manager Service Agent 
( roles/)clouddeploymentmanager.serviceAgent 
 servicenetworking.  
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Viewer 
( roles/  
)
 Support User 
( roles/  
)
 Service Networking Admin 
( roles/  
)
 servicenetworking.  
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Viewer 
( roles/  
)
 Compute Network Admin 
( roles/  
)
 Infrastructure Administrator 
( roles/  
)
 Network Administrator 
( roles/  
)
 Support User 
( roles/  
)
 Service Networking Admin 
( roles/  
)
Service agent roles
-  Cloud Composer API Service Agent 
( roles/)composer.serviceAgent 
-  Kubernetes Engine Service Agent 
( roles/)container.serviceAgent 
-  Cloud Dataflow Service Agent 
( roles/)dataflow.serviceAgent 
-  Cloud TPU V2 API Service Agent 
( roles/)cloudtpu.serviceAgent 
 servicenetworking.  
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Service Networking Admin 
( roles/  
)
 servicenetworking.  
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Service Networking Admin 
( roles/  
)
 servicenetworking.  
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Service Networking Admin 
( roles/  
)
 servicenetworking.  
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Service Networking Admin 
( roles/  
)
 servicenetworking.services.use 
 
 Owner 
( roles/  
)
 Editor 
( roles/  
)
 Viewer 
( roles/  
)
 Support User 
( roles/  
)
 Service Networking Admin 
( roles/  
)

