Roles in GCP IAM
- Get link
- X
- Other Apps
Roles in GCP IAM
A role is a collection of permissions that can be granted to a user, group, or service account.
Think:
Identity → Role → Permissions → Resource
1. Basic Roles
These are broad, legacy roles:
| Role | What it means |
|---|---|
| Viewer | Can view resources, but cannot modify them |
| Editor | Can view and modify resources |
| Owner | Can view, modify, and manage access/IAM |
Example:
User ↓ Viewer ↓ Can view VM Cannot start/delete VM
⚠️ In real projects, avoid broad Basic Roles when a more specific role is available.
2. Predefined Roles ⭐
These are Google-created roles designed for specific services and tasks.
Examples:
- Compute Instance Admin → manage Compute Engine instances
- Storage Object Viewer → view objects in Cloud Storage
- Storage Object Admin → manage objects
- BigQuery Data Viewer → view BigQuery data
- BigQuery Job User → run BigQuery jobs
- Kubernetes Engine Developer → work with GKE resources
Example:
Developer ↓ Storage Object Viewer ↓ Can READ files from Cloud Storage
Predefined roles are generally preferred because they follow the least-privilege principle more closely.
3. Custom Roles
You can create your own role with exactly the permissions you need.
Example:
Suppose you want a user to:
View VM Start VM Stop VM
but not delete VM.
You can create a custom role containing only the required permissions.
Custom Role ├── instances.get ├── instances.start └── instances.stop
This gives very precise control.
Basic vs Predefined vs Custom
| Type | Created by | Flexibility | Example |
|---|---|---|---|
| Basic | Low | Viewer, Editor, Owner | |
| Predefined | Medium/High | Storage Object Viewer | |
| Custom | You/Organization | Very High | MyVMOperator |
⭐ Remember for GCP exams
Basic roles:
Viewer → Editor → Owner
Predefined roles:
Google provides service-specific roles.
Custom roles:
You choose the permissions.
And the key principle is:
Use the minimum permissions required to perform the task — Least Privilege.
GCP IAM Roles
A role defines:
Who can do what on which resource
There are 3 types of IAM roles:
- Basic roles
- Predefined roles
- Custom roles
1. Basic Roles
Basic roles are the original IAM roles in Google Cloud.
They provide broad/coarse-grained access and are generally applied at the project level, affecting resources within that project.
Three main Basic Roles
| Role | Access |
|---|---|
| Owner | Full administrative access |
| Editor | Modify and delete resources |
| Viewer | Read-only access |
Owner
Owner has the highest level of the three basic roles.
Can:
- View resources
- Modify resources
- Delete resources
- Add/remove project members
- Manage access
- Delete projects
Editor
Editor can:
- View resources
- Modify resources
- Delete resources
- Deploy applications
- Configure resources
But doesn't have the full administrative access of Owner, particularly around project IAM management.
Viewer
Viewer has:
- Read-only access
- Can view resources/configuration
- Cannot modify or delete resources
Important: Roles are concentric
Think of them like this:
Owner ↓ includes Editor ↓ includes Viewer
So:
Viewer = Read Editor = Read + Modify/Delete Owner = Read + Modify/Delete + Administrative/IAM control
2. Billing Administrator
There is also a Billing Administrator role.
Its purpose is to manage billing-related administration without giving the person permission to modify the actual resources in the project.
For example, they can manage billing administrators, but they don't automatically get permission to change your VM, VPC, Cloud Storage resources, etc.
A project can have multiple:
- Owners
- Editors
- Viewers
- Billing Administrators
3. Predefined Roles ⭐
Predefined roles are Google-created roles for specific Google Cloud services.
Unlike Basic roles, they provide more granular access.
For example:
Basic Role ↓ Editor ↓ Can modify many different resources
Whereas:
Predefined Role ↓ Compute Engine role ↓ Specific Compute permissions
This helps implement least privilege.
Role vs Permission
This is an important distinction.
Permission
A permission represents one specific action.
Example:
compute.instances.start
Break it down:
compute → Service instances → Resource start → Action/verb
Meaning:
Permission to start a Compute Engine instance.
A permission generally corresponds to an operation exposed through a Google Cloud API.
Role
A role is a collection of permissions.
For example:
Compute Role ├── Permission 1 ├── Permission 2 ├── Permission 3 ├── Permission 4 └── ...
Instead of assigning hundreds of permissions individually, Google groups related permissions into a role.
So remember:
Permission = one specific action
Role = collection of permissions
Example: Compute Engine Predefined Roles
Your course gives three useful examples.
Compute Admin
Provides extensive control over Compute Engine resources.
The role contains Compute Engine permissions covering many Compute Engine operations.
Think:
Compute Admin ↓ Compute Engine ↓ Manage Compute resources
Network Admin
Used for managing networking resources.
It provides permissions to create, modify, and delete many networking resources.
However, there are exceptions.
For example, it does not provide full management of:
- Firewall rules
- SSL certificates
It can have read access to certain resources that are needed for networking administration.
Storage Admin
Provides management permissions for certain Compute Engine storage-related resources such as:
- Disks
- Images
- Snapshots
Example scenario:
Suppose someone in your company is responsible for managing project images.
You don't necessarily need to make them:
Editor
on the entire project.
Instead:
User ↓ Storage Admin ↓ Required storage-related resources
This follows the principle of least privilege.
4. Custom Roles ⭐⭐⭐
This is the most important concept from the last part of your transcript.
Sometimes Google's predefined roles are too broad.
You may want to create your own role containing only the permissions your users actually need.
That's a Custom Role.
Example: Instance Operator
Suppose you have an employee who only needs to:
Start VM Stop VM
But they should not be able to:
Change VM configuration Delete VM Create VM
You can create a custom role such as:
Instance Operator ↓ instances.start instances.stop
Now the user gets only those required permissions.
This is Least Privilege
Give a user only the minimum permissions required to perform their job.
Complete Picture
Remember the hierarchy like this:
IAM │ └── Roles │ ├── Basic Roles │ ├── Viewer │ ├── Editor │ └── Owner │ ├── Predefined Roles │ ├── Compute Admin │ ├── Network Admin │ └── Storage Admin │ └── Custom Roles └── You choose the permissions
And:
Permission ↓ Individual action ↓ compute.instances.start Multiple Permissions ↓ Role ↓ Compute-related role Identity ↓ gets Role ↓ gets Permissions ↓ can perform actions on Resource
🧠 Easy exam memory
Basic = Broad
Predefined = Google-defined + granular
Custom = You-defined + very specific
Permission = Individual action
Role = Collection of permissions
Least privilege = Give only what's required
- Get link
- X
- Other Apps
Comments
Post a Comment