Roles in GCP IAM

 

Roles in GCP IAM

A role is a collection of permissions that can be granted to a user, group, or service account.

Think:

Identity → Role → Permissions → Resource

1. Basic Roles

These are broad, legacy roles:

RoleWhat it means
ViewerCan view resources, but cannot modify them
EditorCan view and modify resources
OwnerCan view, modify, and manage access/IAM

Example:

User
 ↓
Viewer
 ↓
Can view VM
Cannot start/delete VM

⚠️ In real projects, avoid broad Basic Roles when a more specific role is available.


2. Predefined Roles ⭐

These are Google-created roles designed for specific services and tasks.

Examples:

  • Compute Instance Admin → manage Compute Engine instances
  • Storage Object Viewer → view objects in Cloud Storage
  • Storage Object Admin → manage objects
  • BigQuery Data Viewer → view BigQuery data
  • BigQuery Job User → run BigQuery jobs
  • Kubernetes Engine Developer → work with GKE resources

Example:

Developer
   ↓
Storage Object Viewer
   ↓
Can READ files from Cloud Storage

Predefined roles are generally preferred because they follow the least-privilege principle more closely.


3. Custom Roles

You can create your own role with exactly the permissions you need.

Example:

Suppose you want a user to:

View VM
Start VM
Stop VM

but not delete VM.

You can create a custom role containing only the required permissions.

Custom Role
 ├── instances.get
 ├── instances.start
 └── instances.stop

This gives very precise control.


Basic vs Predefined vs Custom

TypeCreated byFlexibilityExample
BasicGoogleLowViewer, Editor, Owner
PredefinedGoogleMedium/HighStorage Object Viewer
CustomYou/OrganizationVery HighMyVMOperator

⭐ Remember for GCP exams

Basic roles:
Viewer → Editor → Owner

Predefined roles:
Google provides service-specific roles.

Custom roles:
You choose the permissions.

And the key principle is:

Use the minimum permissions required to perform the task — Least Privilege.



GCP IAM Roles

A role defines:

Who can do what on which resource

There are 3 types of IAM roles:

  1. Basic roles
  2. Predefined roles
  3. Custom roles

1. Basic Roles

Basic roles are the original IAM roles in Google Cloud.

They provide broad/coarse-grained access and are generally applied at the project level, affecting resources within that project.

Three main Basic Roles

RoleAccess
OwnerFull administrative access
EditorModify and delete resources
ViewerRead-only access

Owner

Owner has the highest level of the three basic roles.

Can:

  • View resources
  • Modify resources
  • Delete resources
  • Add/remove project members
  • Manage access
  • Delete projects

Editor

Editor can:

  • View resources
  • Modify resources
  • Delete resources
  • Deploy applications
  • Configure resources

But doesn't have the full administrative access of Owner, particularly around project IAM management.

Viewer

Viewer has:

  • Read-only access
  • Can view resources/configuration
  • Cannot modify or delete resources

Important: Roles are concentric

Think of them like this:

Owner
  ↓ includes
Editor
  ↓ includes
Viewer

So:

Viewer
  = Read

Editor
  = Read + Modify/Delete

Owner
  = Read + Modify/Delete + Administrative/IAM control

2. Billing Administrator

There is also a Billing Administrator role.

Its purpose is to manage billing-related administration without giving the person permission to modify the actual resources in the project.

For example, they can manage billing administrators, but they don't automatically get permission to change your VM, VPC, Cloud Storage resources, etc.

A project can have multiple:

  • Owners
  • Editors
  • Viewers
  • Billing Administrators

3. Predefined Roles ⭐

Predefined roles are Google-created roles for specific Google Cloud services.

Unlike Basic roles, they provide more granular access.

For example:

Basic Role
    ↓
Editor
    ↓
Can modify many different resources

Whereas:

Predefined Role
    ↓
Compute Engine role
    ↓
Specific Compute permissions

This helps implement least privilege.


Role vs Permission

This is an important distinction.

Permission

A permission represents one specific action.

Example:

compute.instances.start

Break it down:

compute       → Service
instances     → Resource
start         → Action/verb

Meaning:

Permission to start a Compute Engine instance.

A permission generally corresponds to an operation exposed through a Google Cloud API.


Role

A role is a collection of permissions.

For example:

Compute Role
   ├── Permission 1
   ├── Permission 2
   ├── Permission 3
   ├── Permission 4
   └── ...

Instead of assigning hundreds of permissions individually, Google groups related permissions into a role.

So remember:

Permission = one specific action
Role = collection of permissions


Example: Compute Engine Predefined Roles

Your course gives three useful examples.

Compute Admin

Provides extensive control over Compute Engine resources.

The role contains Compute Engine permissions covering many Compute Engine operations.

Think:

Compute Admin
      ↓
Compute Engine
      ↓
Manage Compute resources

Network Admin

Used for managing networking resources.

It provides permissions to create, modify, and delete many networking resources.

However, there are exceptions.

For example, it does not provide full management of:

  • Firewall rules
  • SSL certificates

It can have read access to certain resources that are needed for networking administration.


Storage Admin

Provides management permissions for certain Compute Engine storage-related resources such as:

  • Disks
  • Images
  • Snapshots

Example scenario:

Suppose someone in your company is responsible for managing project images.

You don't necessarily need to make them:

Editor

on the entire project.

Instead:

User
 ↓
Storage Admin
 ↓
Required storage-related resources

This follows the principle of least privilege.


4. Custom Roles ⭐⭐⭐

This is the most important concept from the last part of your transcript.

Sometimes Google's predefined roles are too broad.

You may want to create your own role containing only the permissions your users actually need.

That's a Custom Role.


Example: Instance Operator

Suppose you have an employee who only needs to:

Start VM
Stop VM

But they should not be able to:

Change VM configuration
Delete VM
Create VM

You can create a custom role such as:

Instance Operator
       ↓
instances.start
instances.stop

Now the user gets only those required permissions.

This is Least Privilege

Give a user only the minimum permissions required to perform their job.


Complete Picture

Remember the hierarchy like this:

IAM
 │
 └── Roles
      │
      ├── Basic Roles
      │    ├── Viewer
      │    ├── Editor
      │    └── Owner
      │
      ├── Predefined Roles
      │    ├── Compute Admin
      │    ├── Network Admin
      │    └── Storage Admin
      │
      └── Custom Roles
           └── You choose the permissions

And:

Permission
     ↓
Individual action
     ↓
compute.instances.start

Multiple Permissions
     ↓
Role
     ↓
Compute-related role

Identity
     ↓
gets Role
     ↓
gets Permissions
     ↓
can perform actions on Resource

🧠 Easy exam memory

Basic = Broad

Predefined = Google-defined + granular

Custom = You-defined + very specific

Permission = Individual action

Role = Collection of permissions

Least privilege = Give only what's required 

Comments

Popular posts from this blog

Async/await

First negative in every window of size k

Valid Parentheses