If the pre-defined roles Project: Viewer and Pub/Sub: Pub/Sub Subscriber are too broad for your use, or are otherwise unsuitable for you, you can define a new role whose access is limited according to your needs.Documentation Index
Fetch the complete documentation index at: https://docs.levelblue.com/llms.txt
Use this file to discover all available pages before exploring further.
Project-Level Permissions
Project-Level Permissions
- In the Google Cloud Console, go to your project.
- Go to the IAM & admin tab in the navigation pane and click IAM.
- Click Add.
- Enter the name of the service account whose permissions you are editing.
- In the Role field, select the appropriate role for this service account.
- Click Save.
Required IAM Policies
Required IAM Policies
| IAM Policy | Description | Dependency |
|---|---|---|
| logging.logEntries.list | Allows the sensor to fetch log entries from Stackdriver | Google Cloud Audit Logs for Organizations |
resourcemanager.organizations.get | Allows the sensor to get the details for a specific organization | Application Status Cloud Audit Logs for organizations |
| IAM Policy | Description | Dependency |
|---|---|---|
| logging.logEntries.list | Allows the sensor to fetch log entries from Stackdriver | Cloud Audit Logs for Projects Firewall Logs for Projects VPC Flow Logs for Projects Stackdriver Agent Logs |
resourcemanager.projects.list | Allows the sensor to access a list of the available projects | Application Status Asset Inventory Configuration Issues Cloud Audit Logs for Projects Firewall Logs for Projects VPC Flow Logs for Projects Stackdriver Agent Logs |
| resourcemanager.projects.get | Allows the sensor to fetch the details for a specific project | |
| deploymentmanager.deployments.create | Allows the sensor to be created and deployed | Deployment of a sensor |
| compute.firewalls.list | Allows the sensor to list the existing firewall rules | Configuration Issues |
| compute.firewalls.get | Allows the sensor to get the details for a specific firewall rule | Configuration Issues |
| compute.instances.list | Allows the sensor to list the existing virtual machines | Asset Inventory Configuration Issues |
| compute.instances.get | Allows the sensor to get the details for a specific virtual machine | Asset Inventory Configuration Issues |
| compute.zones.list | Allows the sensor to list the available zones | Asset Inventory Configuration Issues |