cloud-foundation-fabric/fast/stages/01-resman/IAM.md

6.1 KiB

IAM bindings reference

Legend: + additive, conditional.

Organization [org_id #0]

members roles
dev-resman-dp-0
serviceAccount
roles/orgpolicy.policyAdmin +
roles/billing.user +
dev-resman-pf-0
serviceAccount
roles/orgpolicy.policyAdmin +
roles/billing.costsManager +
roles/billing.user +
prod-resman-dp-0
serviceAccount
roles/orgpolicy.policyAdmin +
roles/billing.user +
prod-resman-net-0
serviceAccount
roles/billing.user +
roles/compute.orgFirewallPolicyAdmin +
roles/compute.xpnAdmin +
prod-resman-pf-0
serviceAccount
roles/orgpolicy.policyAdmin +
roles/billing.costsManager +
roles/billing.user +
prod-resman-sec-0
serviceAccount
roles/accesscontextmanager.policyAdmin +
roles/billing.user +

Folder development

members roles
dev-resman-dp-0
serviceAccount
roles/compute.xpnAdmin
roles/logging.admin
roles/owner
roles/resourcemanager.folderAdmin
roles/resourcemanager.projectCreator
roles/compute.xpnAdmin
dev-resman-pf-0
serviceAccount
roles/compute.xpnAdmin

Folder networking

members roles
gcp-network-admins
group
roles/editor
prod-resman-net-0
serviceAccount
roles/compute.xpnAdmin
roles/logging.admin
roles/owner
roles/resourcemanager.folderAdmin
roles/resourcemanager.projectCreator

Folder production

members roles
prod-resman-dp-0
serviceAccount
roles/compute.xpnAdmin
roles/logging.admin
roles/owner
roles/resourcemanager.folderAdmin
roles/resourcemanager.projectCreator
roles/compute.xpnAdmin
prod-resman-pf-0
serviceAccount
roles/compute.xpnAdmin

Folder sandbox

members roles
dev-resman-sbox-0
serviceAccount
roles/logging.admin
roles/owner
roles/resourcemanager.folderAdmin
roles/resourcemanager.projectCreator

Folder security

members roles
gcp-security-admins
group
roles/viewer
prod-resman-sec-0
serviceAccount
roles/logging.admin
roles/owner
roles/resourcemanager.folderAdmin
roles/resourcemanager.projectCreator