Skip to content
J. Passing edited this page Jan 10, 2021 · 5 revisions

The IAM roles required to use IAP Desktop depend on the feature set that you use:

Feature Required IAM role(s) Resource
Connect to VM instances from within a web browser IAP-secured Tunnel User VM instance or project
Add a project to the Project Explorer, listing VM instances Compute Viewer Project
Connect to VM instances in Project Explorer IAP-secured Tunnel User VM instance or project
Generate Windows logon credentials Compute Instance Admin and Service Account User if the VM has an associated service account VM instance/service account or project
View logs Logs Viewer Project
View serial port output Compute Viewer VM instance or project
Analyzing VM instance and sole tenant node usage Compute Viewer, Logs Viewer, and optionally Storage Object Viewer (to access audit logs exported to Cloud Storage) Project

You can use custom roles instead of predefined IAM roles.

Clone this wiki locally