Escopo
project
Permissões
16
Role ID
roles/container.hostServiceAgentUserSpecialized
Narrow-scope role for a specific action or use case
Descrição
Allows the Kubernetes Engine service account in the host project to configure shared network resources for cluster management. Also gives access to inspect the firewall rules in the host project.
Permissions(16)
Carregando permissões…
Role Definition (JSON)
{
"name": "roles/container.hostServiceAgentUser",
"title": "Kubernetes Engine Host Service Agent User",
"description": "Allows the Kubernetes Engine service account in the host project to configure shared network resources for cluster management. Also gives access to inspect the firewall rules in the host project.",
"stage": "GA",
"includedPermissions": []
}Roles relacionadasKubernetes
Kubernetes Engine Admin
Provides access to full management of clusters and their Kubernetes API objects. To set a service account on nodes, you must also have the Service Account User role (roles/iam.serviceAccountUser) on the user-managed service account that your nodes will use.
Kubernetes Engine KMS Crypto Key User
Allow the Kubernetes Engine service agent in the cluster project to call KMS with user provided crypto keys to sign payloads.
Kubernetes Engine Cluster Admin
Provides access to management of clusters. To set a service account on nodes, you must also have the Service Account User role (roles/iam.serviceAccountUser) on the user-managed service account that your nodes will use.
Kubernetes Engine Cluster Viewer
Provides access to get and list GKE clusters.
Kubernetes Engine Default Node Service Account
Least privilege role to use as the default service account for GKE Nodes.