This page lists the IAM roles and permissions for Service Networking. To search through all roles and permissions, see the role and permission index .
Service Networking roles
Servicenetworking Admin Beta
( roles/
)
Admin role for servicenetworking
resourcemanager.projects.get
resourcemanager.projects.list
servicenetworking.*
-
servicenetworking.operations. cancel -
servicenetworking.operations. delete -
servicenetworking.operations. get -
servicenetworking.operations. list -
servicenetworking.services. addDnsRecordSet -
servicenetworking.services. addDnsZone -
servicenetworking.services. addPeering -
servicenetworking.services. addSubnetwork -
servicenetworking.services. createPeeredDnsDomain -
servicenetworking.services. deleteConnection -
servicenetworking.services. deletePeeredDnsDomain -
servicenetworking.services. disableVpcServiceControls -
servicenetworking.services. enableVpcServiceControls -
servicenetworking.services.get -
servicenetworking.services. getConsumerConfig -
servicenetworking.services. getVpcServiceControls -
servicenetworking.services. listPeeredDnsDomains -
servicenetworking.services. removeDnsRecordSet -
servicenetworking.services. removeDnsZone -
servicenetworking.services. updateConsumerConfig -
servicenetworking.services. updateDnsRecordSet -
servicenetworking.services.use
Servicenetworking Editor Beta
( roles/
)
Editor role for servicenetworking
resourcemanager.projects.get
resourcemanager.projects.list
servicenetworking.operations.*
-
servicenetworking.operations. cancel -
servicenetworking.operations. delete -
servicenetworking.operations. get -
servicenetworking.operations. list
servicenetworking.
servicenetworking.
servicenetworking.
servicenetworking.
servicenetworking.
servicenetworking.
servicenetworking.
servicenetworking.
servicenetworking.services.get
servicenetworking.
servicenetworking.
servicenetworking.
servicenetworking.
servicenetworking.
servicenetworking.
servicenetworking.
servicenetworking.services.use
Service Networking Admin Beta
( roles/
)
Full control of service networking with projects.
servicenetworking.*
-
servicenetworking.operations. cancel -
servicenetworking.operations. delete -
servicenetworking.operations. get -
servicenetworking.operations. list -
servicenetworking.services. addDnsRecordSet -
servicenetworking.services. addDnsZone -
servicenetworking.services. addPeering -
servicenetworking.services. addSubnetwork -
servicenetworking.services. createPeeredDnsDomain -
servicenetworking.services. deleteConnection -
servicenetworking.services. deletePeeredDnsDomain -
servicenetworking.services. disableVpcServiceControls -
servicenetworking.services. enableVpcServiceControls -
servicenetworking.services.get -
servicenetworking.services. getConsumerConfig -
servicenetworking.services. getVpcServiceControls -
servicenetworking.services. listPeeredDnsDomains -
servicenetworking.services. removeDnsRecordSet -
servicenetworking.services. removeDnsZone -
servicenetworking.services. updateConsumerConfig -
servicenetworking.services. updateDnsRecordSet -
servicenetworking.services.use
Service Networking Service Agent
( roles/
)
Gives permission to manage network configuration, such as establishing network peering, necessary for service producers
compute.globalAddresses.get
compute.globalAddresses.list
compute.globalOperations.get
compute.networks.addPeering
compute.networks.create
compute.networks.delete
compute.networks.get
compute.networks.list
compute.
compute.networks.removePeering
compute.networks.update
compute.networks.updatePeering
compute.networks.updatePolicy
compute.projects.get
compute.regionOperations.get
compute.routers.get
compute.routers.list
compute.routes.list
compute.subnetworks.create
compute.subnetworks.delete
compute.subnetworks.get
compute.subnetworks.list
dns.changes.*
-
dns.changes.create -
dns.changes.get -
dns.changes.list
dns.dnsKeys.*
-
dns.dnsKeys.get -
dns.dnsKeys.list
dns.gkeClusters.*
-
dns.gkeClusters. bindDNSResponsePolicy -
dns.gkeClusters. bindPrivateDNSZone
dns.managedZoneOperations.*
-
dns.managedZoneOperations.get -
dns.managedZoneOperations.list
dns.managedZones.create
dns.managedZones.delete
dns.managedZones.get
dns.managedZones.getIamPolicy
dns.managedZones.list
dns.managedZones.update
dns.networks.*
-
dns.networks. bindDNSResponsePolicy -
dns.networks. bindPrivateDNSPolicy -
dns.networks. bindPrivateDNSZone -
dns.networks. targetWithPeeringZone -
dns.networks.useHealthSignals
dns.policies.create
dns.policies.delete
dns.policies.get
dns.policies.list
dns.policies.listEffectiveTags
dns.policies.listTagBindings
dns.policies.update
dns.projects.get
dns.resourceRecordSets.*
-
dns.resourceRecordSets.create -
dns.resourceRecordSets.delete -
dns.resourceRecordSets.get -
dns.resourceRecordSets.list -
dns.resourceRecordSets.update
dns.responsePolicies.*
-
dns.responsePolicies.create -
dns.responsePolicies.delete -
dns.responsePolicies.get -
dns.responsePolicies.list -
dns.responsePolicies.update
dns.responsePolicyRules.*
-
dns.responsePolicyRules.create -
dns.responsePolicyRules.delete -
dns.responsePolicyRules.get -
dns.responsePolicyRules.list -
dns.responsePolicyRules.update
networkconnectivity.
resourcemanager.projects.get
resourcemanager.projects.list
Servicenetworking Viewer Beta
( roles/
)
Viewer role for servicenetworking
resourcemanager.projects.get
resourcemanager.projects.list
servicenetworking.
servicenetworking.
servicenetworking.services.get
servicenetworking.
servicenetworking.
servicenetworking.
servicenetworking.services.use
Service Networking permissions
servicenetworking.
operations.
cancel
Owner
( roles/
)
Editor
( roles/
)
Servicenetworking Admin
( roles/
)
Servicenetworking Editor
( roles/
)
Service Networking Admin
( roles/
)
servicenetworking.
operations.
delete
Owner
( roles/
)
Editor
( roles/
)
Servicenetworking Admin
( roles/
)
Servicenetworking Editor
( roles/
)
Service Networking Admin
( roles/
)
servicenetworking.
operations.
get
Owner
( roles/
)
Editor
( roles/
)
Viewer
( roles/
)
Compute Network Admin
( roles/
)
Infrastructure Administrator
( roles/
)
Network Administrator
( roles/
)
Support User
( roles/
)
Servicenetworking Admin
( roles/
)
Servicenetworking Editor
( roles/
)
Service Networking Admin
( roles/
)
Servicenetworking Viewer
( roles/
)
Service agent roles
- Cloud TPU V2 API Service Agent
(
roles/)cloudtpu.serviceAgent - Cloud Composer API Service Agent
(
roles/)composer.serviceAgent - Kubernetes Engine Service Agent
(
roles/)container.serviceAgent - Cloud Dataflow Service Agent
(
roles/)dataflow.serviceAgent - Cluster Director Service Agent
(
roles/)hypercomputecluster.serviceAgent - Cloud Deployment Manager Service Agent
(
roles/)clouddeploymentmanager.serviceAgent
servicenetworking.
operations.
list
Owner
( roles/
)
Editor
( roles/
)
Viewer
( roles/
)
Security Admin
( roles/
)
Security Auditor
( roles/
)
Security Reviewer
( roles/
)
Support User
( roles/
)
Servicenetworking Admin
( roles/
)
Servicenetworking Editor
( roles/
)
Service Networking Admin
( roles/
)
Servicenetworking Viewer
( roles/
)
servicenetworking.
services.
addDnsRecordSet
Owner
( roles/
)
Editor
( roles/
)
Servicenetworking Admin
( roles/
)
Servicenetworking Editor
( roles/
)
Service Networking Admin
( roles/
)
servicenetworking.
services.
addDnsZone
Owner
( roles/
)
Editor
( roles/
)
Servicenetworking Admin
( roles/
)
Servicenetworking Editor
( roles/
)
Service Networking Admin
( roles/
)
servicenetworking.
services.
addPeering
Owner
( roles/
)
Compute Network Admin
( roles/
)
Infrastructure Administrator
( roles/
)
Network Administrator
( roles/
)
Servicenetworking Admin
( roles/
)
Service Networking Admin
( roles/
)
Service agent roles
- Cloud TPU V2 API Service Agent
(
roles/)cloudtpu.serviceAgent - Cloud Composer API Service Agent
(
roles/)composer.serviceAgent - Kubernetes Engine Service Agent
(
roles/)container.serviceAgent - Cloud Dataflow Service Agent
(
roles/)dataflow.serviceAgent - Cluster Director Service Agent
(
roles/)hypercomputecluster.serviceAgent - Cloud Deployment Manager Service Agent
(
roles/)clouddeploymentmanager.serviceAgent
servicenetworking.
services.
addSubnetwork
Owner
( roles/
)
Editor
( roles/
)
Servicenetworking Admin
( roles/
)
Servicenetworking Editor
( roles/
)
Service Networking Admin
( roles/
)
servicenetworking.
services.
createPeeredDnsDomain
Owner
( roles/
)
Editor
( roles/
)
Compute Network Admin
( roles/
)
Infrastructure Administrator
( roles/
)
Network Administrator
( roles/
)
Servicenetworking Admin
( roles/
)
Servicenetworking Editor
( roles/
)
Service Networking Admin
( roles/
)
Service agent roles
- Cloud Composer API Service Agent
(
roles/)composer.serviceAgent - Kubernetes Engine Service Agent
(
roles/)container.serviceAgent - Cloud Dataflow Service Agent
(
roles/)dataflow.serviceAgent - Cloud TPU V2 API Service Agent
(
roles/)cloudtpu.serviceAgent
servicenetworking.
services.
deleteConnection
Owner
( roles/
)
Editor
( roles/
)
Compute Network Admin
( roles/
)
Infrastructure Administrator
( roles/
)
Network Administrator
( roles/
)
Servicenetworking Admin
( roles/
)
Servicenetworking Editor
( roles/
)
Service Networking Admin
( roles/
)
Service agent roles
- Cloud Composer API Service Agent
(
roles/)composer.serviceAgent - Kubernetes Engine Service Agent
(
roles/)container.serviceAgent - Cloud Dataflow Service Agent
(
roles/)dataflow.serviceAgent - Cluster Director Service Agent
(
roles/)hypercomputecluster.serviceAgent - Cloud TPU V2 API Service Agent
(
roles/)cloudtpu.serviceAgent
servicenetworking.
services.
deletePeeredDnsDomain
Owner
( roles/
)
Editor
( roles/
)
Compute Network Admin
( roles/
)
Infrastructure Administrator
( roles/
)
Network Administrator
( roles/
)
Servicenetworking Admin
( roles/
)
Servicenetworking Editor
( roles/
)
Service Networking Admin
( roles/
)
Service agent roles
- Cloud Composer API Service Agent
(
roles/)composer.serviceAgent - Kubernetes Engine Service Agent
(
roles/)container.serviceAgent - Cloud Dataflow Service Agent
(
roles/)dataflow.serviceAgent - Cluster Director Service Agent
(
roles/)hypercomputecluster.serviceAgent - Cloud TPU V2 API Service Agent
(
roles/)cloudtpu.serviceAgent
servicenetworking.
services.
disableVpcServiceControls
Owner
( roles/
)
Editor
( roles/
)
Compute Network Admin
( roles/
)
Infrastructure Administrator
( roles/
)
Network Administrator
( roles/
)
Servicenetworking Admin
( roles/
)
Servicenetworking Editor
( roles/
)
Service Networking Admin
( roles/
)
Service agent roles
- Cloud Composer API Service Agent
(
roles/)composer.serviceAgent - Kubernetes Engine Service Agent
(
roles/)container.serviceAgent - Cloud Dataflow Service Agent
(
roles/)dataflow.serviceAgent - Cloud TPU V2 API Service Agent
(
roles/)cloudtpu.serviceAgent
servicenetworking.
services.
enableVpcServiceControls
Owner
( roles/
)
Editor
( roles/
)
Compute Network Admin
( roles/
)
Infrastructure Administrator
( roles/
)
Network Administrator
( roles/
)
Servicenetworking Admin
( roles/
)
Servicenetworking Editor
( roles/
)
Service Networking Admin
( roles/
)
Service agent roles
- Cloud Composer API Service Agent
(
roles/)composer.serviceAgent - Kubernetes Engine Service Agent
(
roles/)container.serviceAgent - Cloud Dataflow Service Agent
(
roles/)dataflow.serviceAgent - Cloud TPU V2 API Service Agent
(
roles/)cloudtpu.serviceAgent
servicenetworking.services.get
Owner
( roles/
)
Editor
( roles/
)
Viewer
( roles/
)
Compute Network Admin
( roles/
)
Compute Network User
( roles/
)
Compute Network Viewer
( roles/
)
Infrastructure Administrator
( roles/
)
Network Administrator
( roles/
)
Security Auditor
( roles/
)
Support User
( roles/
)
Servicenetworking Admin
( roles/
)
Servicenetworking Editor
( roles/
)
Service Networking Admin
( roles/
)
Servicenetworking Viewer
( roles/
)
Service agent roles
- Cloud TPU V2 API Service Agent
(
roles/)cloudtpu.serviceAgent - Cloud Composer API Service Agent
(
roles/)composer.serviceAgent - Kubernetes Engine Service Agent
(
roles/)container.serviceAgent - Cloud Dataflow Service Agent
(
roles/)dataflow.serviceAgent - Cloud Data Fusion API Service Agent
(
roles/)datafusion.serviceAgent - Cluster Director Service Agent
(
roles/)hypercomputecluster.serviceAgent - Cluster Director Shared VPC Service Agent
(
roles/)hypercomputecluster.sharedVpcServiceAgent - Cloud Deployment Manager Service Agent
(
roles/)clouddeploymentmanager.serviceAgent
servicenetworking.
services.
getConsumerConfig
Owner
( roles/
)
Editor
( roles/
)
Viewer
( roles/
)
Support User
( roles/
)
Servicenetworking Admin
( roles/
)
Servicenetworking Editor
( roles/
)
Service Networking Admin
( roles/
)
Servicenetworking Viewer
( roles/
)
servicenetworking.
services.
getVpcServiceControls
Owner
( roles/
)
Editor
( roles/
)
Viewer
( roles/
)
Compute Network Admin
( roles/
)
Infrastructure Administrator
( roles/
)
Network Administrator
( roles/
)
Support User
( roles/
)
Servicenetworking Admin
( roles/
)
Servicenetworking Editor
( roles/
)
Service Networking Admin
( roles/
)
Servicenetworking Viewer
( roles/
)
Service agent roles
- Cloud Composer API Service Agent
(
roles/)composer.serviceAgent - Kubernetes Engine Service Agent
(
roles/)container.serviceAgent - Cloud Dataflow Service Agent
(
roles/)dataflow.serviceAgent - Cloud TPU V2 API Service Agent
(
roles/)cloudtpu.serviceAgent
servicenetworking.
services.
listPeeredDnsDomains
Owner
( roles/
)
Editor
( roles/
)
Viewer
( roles/
)
Compute Network Admin
( roles/
)
Infrastructure Administrator
( roles/
)
Network Administrator
( roles/
)
Support User
( roles/
)
Servicenetworking Admin
( roles/
)
Servicenetworking Editor
( roles/
)
Service Networking Admin
( roles/
)
Servicenetworking Viewer
( roles/
)
Service agent roles
- Cloud Composer API Service Agent
(
roles/)composer.serviceAgent - Kubernetes Engine Service Agent
(
roles/)container.serviceAgent - Cloud Dataflow Service Agent
(
roles/)dataflow.serviceAgent - Cluster Director Service Agent
(
roles/)hypercomputecluster.serviceAgent - Cloud TPU V2 API Service Agent
(
roles/)cloudtpu.serviceAgent
servicenetworking.
services.
removeDnsRecordSet
Owner
( roles/
)
Editor
( roles/
)
Servicenetworking Admin
( roles/
)
Servicenetworking Editor
( roles/
)
Service Networking Admin
( roles/
)
servicenetworking.
services.
removeDnsZone
Owner
( roles/
)
Editor
( roles/
)
Servicenetworking Admin
( roles/
)
Servicenetworking Editor
( roles/
)
Service Networking Admin
( roles/
)
servicenetworking.
services.
updateConsumerConfig
Owner
( roles/
)
Editor
( roles/
)
Servicenetworking Admin
( roles/
)
Servicenetworking Editor
( roles/
)
Service Networking Admin
( roles/
)
servicenetworking.
services.
updateDnsRecordSet
Owner
( roles/
)
Editor
( roles/
)
Servicenetworking Admin
( roles/
)
Servicenetworking Editor
( roles/
)
Service Networking Admin
( roles/
)
servicenetworking.services.use
Owner
( roles/
)
Editor
( roles/
)
Viewer
( roles/
)
Support User
( roles/
)
Servicenetworking Admin
( roles/
)
Servicenetworking Editor
( roles/
)
Service Networking Admin
( roles/
)
Servicenetworking Viewer
( roles/
)

