This page lists the IAM roles and permissions for Serverless VPC Access. To search through all roles and permissions, see the role and permission index .
Serverless VPC Access roles
Serverless VPC Access Admin
( roles/
)
Full access to all Serverless VPC Access resources
resourcemanager.projects.get
resourcemanager.projects.list
vpcaccess.*
-
vpcaccess.connectors.create
-
vpcaccess.connectors.delete
-
vpcaccess.connectors.get
-
vpcaccess.connectors.list
-
vpcaccess.connectors.update
-
vpcaccess.connectors.use
-
vpcaccess.locations.list
-
vpcaccess.operations.get
-
vpcaccess.operations.list
Serverless VPC Access Service Agent
( roles/
)
Can create and manage resources to support serverless application to connect to virtual private cloud.
billing.accounts.get
compute.autoscalers.*
-
compute.autoscalers.create
-
compute.autoscalers.delete
-
compute.autoscalers.get
-
compute.autoscalers.list
-
compute.autoscalers.update
compute.disks.create
compute.firewalls.create
compute.firewalls.delete
compute.firewalls.get
compute.firewalls.list
compute.firewalls.update
compute.healthChecks.create
compute.healthChecks.delete
compute.healthChecks.get
compute.healthChecks.list
compute.healthChecks.update
compute.healthChecks.use
compute.
compute.
compute.
compute.httpHealthChecks.get
compute.httpHealthChecks.list
compute.httpHealthChecks.use
compute.
compute.
compute.
compute.httpsHealthChecks.get
compute.
compute.httpsHealthChecks.use
compute.
compute.images.get
compute.images.useReadOnly
compute.
compute.
compute.
compute.
compute.
compute.instanceGroups.create
compute.instanceGroups.delete
compute.instanceGroups.get
compute.instanceGroups.update
compute.
compute.
compute.instanceTemplates.get
compute.
compute.instances.create
compute.instances.delete
compute.instances.get
compute.
compute.instances.list
compute.instances.reset
compute.instances.setLabels
compute.instances.setMetadata
compute.instances.setTags
compute.instances.start
compute.instances.stop
compute.instances.use
compute.machineTypes.get
compute.networks.get
compute.networks.use
compute.projects.get
compute.
compute.regionOperations.get
compute.regionOperations.list
compute.regions.*
-
compute.regions.get
-
compute.regions.list
compute.subnetworks.create
compute.subnetworks.delete
compute.subnetworks.get
compute.subnetworks.list
compute.subnetworks.use
compute.zoneOperations.get
compute.zoneOperations.list
compute.zones.*
-
compute.zones.get
-
compute.zones.list
deploymentmanager.
deploymentmanager.
deploymentmanager.
deploymentmanager.
deploymentmanager.
deploymentmanager.
deploymentmanager.manifests.*
-
deploymentmanager.
manifests. get -
deploymentmanager.
manifests. list
deploymentmanager.operations.*
-
deploymentmanager.
operations. get -
deploymentmanager.
operations. list
deploymentmanager.
deploymentmanager.
logging.logEntries.create
logging.logMetrics.create
logging.logMetrics.delete
logging.logMetrics.get
logging.logMetrics.update
resourcemanager.projects.get
Serverless VPC Access User
( roles/
)
User of Serverless VPC Access connectors
compute.networks.access
resourcemanager.projects.get
resourcemanager.projects.list
vpcaccess.connectors.get
vpcaccess.connectors.list
vpcaccess.connectors.use
vpcaccess.locations.list
vpcaccess.operations.*
-
vpcaccess.operations.get
-
vpcaccess.operations.list
Serverless VPC Access Viewer
( roles/
)
Viewer of all Serverless VPC Access resources
resourcemanager.projects.get
resourcemanager.projects.list
vpcaccess.connectors.get
vpcaccess.connectors.list
vpcaccess.locations.list
vpcaccess.operations.*
-
vpcaccess.operations.get
-
vpcaccess.operations.list
Serverless VPC Access permissions
vpcaccess.connectors.create
Owner
( roles/
)
Editor
( roles/
)
Serverless VPC Access Admin
( roles/
)
Service agent roles
- Cloud Deployment Manager Service Agent
(
roles/
)clouddeploymentmanager.serviceAgent
vpcaccess.connectors.delete
Owner
( roles/
)
Editor
( roles/
)
Serverless VPC Access Admin
( roles/
)
Service agent roles
- Cloud Deployment Manager Service Agent
(
roles/
)clouddeploymentmanager.serviceAgent
vpcaccess.connectors.get
Owner
( roles/
)
Editor
( roles/
)
Viewer
( roles/
)
Support User
( roles/
)
Cloud Run Service Agent
( roles/
)
Serverless VPC Access Admin
( roles/
)
Serverless VPC Access User
( roles/
)
Serverless VPC Access Viewer
( roles/
)
Service agent roles
- Data Connectors Service Agent
(
roles/
)dataconnectors.serviceAgent - Cloud Run Service Agent
(
roles/
)run.serviceAgent - Serverless Integrations Service Agent
(
roles/
)runapps.serviceAgent - Cloud Functions Service Agent
(
roles/
)cloudfunctions.serviceAgent
vpcaccess.connectors.list
Owner
( roles/
)
Editor
( roles/
)
Viewer
( roles/
)
Security Admin
( roles/
)
Security Auditor
( roles/
)
Security Reviewer
( roles/
)
Support User
( roles/
)
Serverless VPC Access Admin
( roles/
)
Serverless VPC Access User
( roles/
)
Serverless VPC Access Viewer
( roles/
)
Service agent roles
- Serverless Integrations Service Agent
(
roles/
)runapps.serviceAgent
vpcaccess.connectors.update
Owner
( roles/
)
Editor
( roles/
)
Serverless VPC Access Admin
( roles/
)
vpcaccess.connectors.use
Owner
( roles/
)
Editor
( roles/
)
Viewer
( roles/
)
Support User
( roles/
)
Cloud Run Service Agent
( roles/
)
Serverless VPC Access Admin
( roles/
)
Serverless VPC Access User
( roles/
)
Service agent roles
- Data Connectors Service Agent
(
roles/
)dataconnectors.serviceAgent - Cloud Run Service Agent
(
roles/
)run.serviceAgent - Cloud Functions Service Agent
(
roles/
)cloudfunctions.serviceAgent
vpcaccess.locations.list
Owner
( roles/
)
Editor
( roles/
)
Viewer
( roles/
)
Security Admin
( roles/
)
Security Auditor
( roles/
)
Security Reviewer
( roles/
)
Support User
( roles/
)
Serverless VPC Access Admin
( roles/
)
Serverless VPC Access User
( roles/
)
Serverless VPC Access Viewer
( roles/
)
vpcaccess.operations.get
Owner
( roles/
)
Editor
( roles/
)
Viewer
( roles/
)
Support User
( roles/
)
Serverless VPC Access Admin
( roles/
)
Serverless VPC Access User
( roles/
)
Serverless VPC Access Viewer
( roles/
)
Service agent roles
- Cloud Deployment Manager Service Agent
(
roles/
)clouddeploymentmanager.serviceAgent
vpcaccess.operations.list
Owner
( roles/
)
Editor
( roles/
)
Viewer
( roles/
)
Security Admin
( roles/
)
Security Auditor
( roles/
)
Security Reviewer
( roles/
)
Support User
( roles/
)
Serverless VPC Access Admin
( roles/
)
Serverless VPC Access User
( roles/
)
Serverless VPC Access Viewer
( roles/
)