-
Notifications
You must be signed in to change notification settings - Fork 177
Roles
Johannes Passing edited this page Jan 10, 2021
·
5 revisions
The IAM roles required to use IAP Desktop depend on the feature set that you use:
| Feature | Required IAM role(s) | Resource |
|---|---|---|
| Connect to VM instances from within a web browser | IAP-secured Tunnel User | VM instance or project |
| Add a project to the Project Explorer, listing VM instances | Compute Viewer | Project |
| Connect to VM instances in Project Explorer | IAP-secured Tunnel User | VM instance or project |
| Generate Windows logon credentials | Compute Instance Admin and Service Account User if the VM has an associated service account | VM instance/service account or project |
| View logs | Logs Viewer | Project |
| View serial port output | Compute Viewer | VM instance or project |
| Analyzing VM instance and sole tenant node usage | Compute Viewer, Logs Viewer, and optionally Storage Object Viewer (to access audit logs exported to Cloud Storage) | Project |
You can use custom roles instead of predefined IAM roles.
IAP Desktop is an open-source project and not an officially supported Google product.