Roles in GCP IAM
Roles in GCP IAM A role is a collection of permissions that can be granted to a user, group, or service account. Think: Identity → Role → Permissions → Resource 1. Basic Roles These are broad, legacy roles: Role What it means Viewer Can view resources, but cannot modify them Editor Can view and modify resources Owner Can view, modify, and manage access/IAM Example: User ↓ Viewer ↓ Can view VM Cannot start/delete VM ⚠️ In real projects, avoid broad Basic Roles when a more specific role is available. 2. Predefined Roles ⭐ These are Google-created roles designed for specific services and tasks. Examples: Compute Instance Admin → manage Compute Engine instances Storage Object Viewer → view objects in Cloud Storage Storage Object Admin → manage objects BigQuery Data Viewer → view BigQuery data BigQuery Job User → run BigQuery jobs Kubernetes Engine Developer → work with GKE resources Example: Developer ↓ Storage Object Viewer ↓ Can READ fil...