Skip to content

Instantly share code, notes, and snippets.

@tevanraj
Last active February 6, 2020 06:19
Show Gist options
  • Save tevanraj/0a7edae58a6e226da4ba3bc8ee1a286b to your computer and use it in GitHub Desktop.
Save tevanraj/0a7edae58a6e226da4ba3bc8ee1a286b to your computer and use it in GitHub Desktop.

Revisions

  1. tevanraj revised this gist Feb 6, 2020. 1 changed file with 90 additions and 5 deletions.
    95 changes: 90 additions & 5 deletions list-gcp-iam-roles
    Original file line number Diff line number Diff line change
    @@ -4,12 +4,27 @@ roles/accessapproval.viewer
    roles/accesscontextmanager.policyAdmin
    roles/accesscontextmanager.policyEditor
    roles/accesscontextmanager.policyReader
    roles/actions.Admin
    roles/actions.Viewer
    roles/androidmanagement.user
    roles/apigee.admin
    roles/apigee.analyticsAgent
    roles/apigee.analyticsEditor
    roles/apigee.analyticsViewer
    roles/apigee.apiCreator
    roles/apigee.deployer
    roles/apigee.developerAdmin
    roles/apigee.readOnlyAdmin
    roles/apigee.synchronizerManager
    roles/appengine.appAdmin
    roles/appengine.appViewer
    roles/appengine.codeViewer
    roles/appengine.deployer
    roles/appengine.serviceAdmin
    roles/artifactregistry.admin
    roles/artifactregistry.reader
    roles/artifactregistry.repoAdmin
    roles/artifactregistry.writer
    roles/automl.admin
    roles/automl.editor
    roles/automl.predictor
    @@ -46,16 +61,23 @@ roles/binaryauthorization.policyAdmin
    roles/binaryauthorization.policyEditor
    roles/binaryauthorization.policyViewer
    roles/browser
    roles/chat.owner
    roles/chat.reader
    roles/cloudasset.owner
    roles/cloudasset.serviceAgent
    roles/cloudasset.viewer
    roles/cloudbuild.builds.builder
    roles/cloudbuild.builds.editor
    roles/cloudbuild.builds.viewer
    roles/cloudbuild.serviceAgent
    roles/cloudconfig.admin
    roles/cloudconfig.viewer
    roles/clouddebugger.agent
    roles/clouddebugger.user
    roles/cloudfunctions.admin
    roles/cloudfunctions.developer
    roles/cloudfunctions.invoker
    roles/cloudfunctions.serviceAgent
    roles/cloudfunctions.viewer
    roles/cloudiot.admin
    roles/cloudiot.deviceController
    @@ -71,6 +93,7 @@ roles/cloudkms.admin
    roles/cloudkms.cryptoKeyDecrypter
    roles/cloudkms.cryptoKeyEncrypter
    roles/cloudkms.cryptoKeyEncrypterDecrypter
    roles/cloudkms.importer
    roles/cloudkms.publicKeyViewer
    roles/cloudkms.signer
    roles/cloudkms.signerVerifier
    @@ -133,6 +156,8 @@ roles/compute.orgSecurityResourceAdmin
    roles/compute.osAdminLogin
    roles/compute.osLogin
    roles/compute.osLoginExternalUser
    roles/compute.packetMirroringAdmin
    roles/compute.packetMirroringUser
    roles/compute.securityAdmin
    roles/compute.storageAdmin
    roles/compute.viewer
    @@ -150,7 +175,8 @@ roles/containeranalysis.notes.viewer
    roles/containeranalysis.occurrences.editor
    roles/containeranalysis.occurrences.viewer
    roles/datacatalog.admin
    roles/datacatalog.entryCreator
    roles/datacatalog.categoryAdmin
    roles/datacatalog.categoryFineGrainedReader
    roles/datacatalog.entryGroupCreator
    roles/datacatalog.entryGroupOwner
    roles/datacatalog.entryOwner
    @@ -177,6 +203,8 @@ roles/dataproc.editor
    roles/dataproc.serviceAgent
    roles/dataproc.viewer
    roles/dataproc.worker
    roles/dataprocessing.admin
    roles/dataprocessing.iamAccessHistoryExporter
    roles/datastore.importExportAdmin
    roles/datastore.indexAdmin
    roles/datastore.owner
    @@ -226,11 +254,42 @@ roles/firebase.growthViewer
    roles/firebase.qualityAdmin
    roles/firebase.qualityViewer
    roles/firebase.viewer
    roles/firebaseabt.admin
    roles/firebaseabt.viewer
    roles/firebaseappdistro.admin
    roles/firebaseappdistro.viewer
    roles/firebaseauth.admin
    roles/firebaseauth.viewer
    roles/firebasecrash.symbolMappingsAdmin
    roles/firebasecrashlytics.admin
    roles/firebasecrashlytics.viewer
    roles/firebasedatabase.admin
    roles/firebasedatabase.viewer
    roles/firebasedynamiclinks.admin
    roles/firebasedynamiclinks.viewer
    roles/firebasehosting.admin
    roles/firebasehosting.viewer
    roles/firebaseinappmessaging.admin
    roles/firebaseinappmessaging.viewer
    roles/firebaseml.admin
    roles/firebaseml.viewer
    roles/firebasenotifications.admin
    roles/firebasenotifications.viewer
    roles/firebaseperformance.admin
    roles/firebaseperformance.viewer
    roles/firebasepredictions.admin
    roles/firebasepredictions.viewer
    roles/firebaserules.admin
    roles/firebaserules.viewer
    roles/gameservices.admin
    roles/gameservices.viewer
    roles/genomics.admin
    roles/genomics.editor
    roles/genomics.pipelinesRunner
    roles/genomics.viewer
    roles/gkehub.admin
    roles/gkehub.connect
    roles/gkehub.viewer
    roles/healthcare.annotationEditor
    roles/healthcare.annotationReader
    roles/healthcare.annotationStoreAdmin
    @@ -265,7 +324,14 @@ roles/iam.serviceAccountUser
    roles/iam.workloadIdentityUser
    roles/iap.admin
    roles/iap.httpsResourceAccessor
    roles/iap.settingsAdmin
    roles/iap.tunnelResourceAccessor
    roles/identitytoolkit.admin
    roles/identitytoolkit.viewer
    roles/lifesciences.admin
    roles/lifesciences.editor
    roles/lifesciences.viewer
    roles/lifesciences.workflowsRunner
    roles/logging.admin
    roles/logging.configWriter
    roles/logging.logWriter
    @@ -285,20 +351,28 @@ roles/mobilecrashreporting.symbolMappingsAdmin
    roles/monitoring.admin
    roles/monitoring.alertPolicyEditor
    roles/monitoring.alertPolicyViewer
    roles/monitoring.dashboardEditor
    roles/monitoring.dashboardViewer
    roles/monitoring.editor
    roles/monitoring.metricWriter
    roles/monitoring.notificationChannelEditor
    roles/monitoring.notificationChannelViewer
    roles/monitoring.uptimeCheckConfigEditor
    roles/monitoring.uptimeCheckConfigViewer
    roles/monitoring.viewer
    roles/netappcloudvolumes.admin
    roles/netappcloudvolumes.viewer
    roles/networkmanagement.admin
    roles/networkmanagement.viewer
    roles/notebooks.admin
    roles/notebooks.viewer
    roles/opsconfigmonitoring.resourceMetadata.writer
    roles/orgpolicy.policyAdmin
    roles/orgpolicy.policyViewer
    roles/ownerlist a project's namespaces.
    roles/proximitybeacon.attachmentEditorspaces not owned by this project.
    roles/owner
    roles/proximitybeacon.attachmentEditor
    roles/proximitybeacon.attachmentPublisher
    ption: Can view all attachments under a namespace; no beacon or namespace permissions.
    roles/proximitybeacon.attachmentVieweramespace permissions.
    roles/proximitybeacon.attachmentViewer
    roles/proximitybeacon.beaconEditor
    roles/pubsub.admin
    roles/pubsub.editor
    @@ -312,13 +386,16 @@ roles/recommender.iamViewer
    roles/redis.admin
    roles/redis.editor
    roles/redis.viewer
    roles/redisenterprisecloud.admin
    roles/redisenterprisecloud.viewer
    roles/remotebuildexecution.actionCacheWriter
    roles/remotebuildexecution.artifactAdmin
    roles/remotebuildexecution.artifactCreator
    roles/remotebuildexecution.artifactViewer
    roles/remotebuildexecution.configurationAdmin
    roles/remotebuildexecution.configurationViewer
    roles/remotebuildexecution.logstreamWriter
    roles/remotebuildexecution.reservationAdmin
    roles/remotebuildexecution.worker
    roles/resourcemanager.folderAdmin
    roles/resourcemanager.folderCreator
    @@ -338,6 +415,9 @@ roles/run.admin
    roles/run.invoker
    roles/run.viewer
    roles/runtimeconfig.admin
    roles/secretmanager.admin
    roles/secretmanager.secretAccessor
    roles/secretmanager.viewer
    roles/securitycenter.admin
    roles/securitycenter.adminEditor
    roles/securitycenter.adminViewer
    @@ -348,9 +428,12 @@ roles/securitycenter.findingSecurityMarksWriter
    roles/securitycenter.findingsEditor
    roles/securitycenter.findingsStateSetter
    roles/securitycenter.findingsViewer
    roles/securitycenter.notificationConfigEditor
    roles/securitycenter.notificationConfigViewer
    roles/securitycenter.sourcesAdmin
    roles/securitycenter.sourcesEditor
    roles/securitycenter.sourcesViewer
    roles/serverless.serviceAgent
    roles/servicebroker.admin
    roles/servicebroker.operator
    roles/serviceconsumermanagement.tenancyUnitsAdmin
    @@ -399,6 +482,8 @@ roles/threatdetection.viewer
    roles/tpu.admin
    roles/tpu.viewer
    roles/viewer
    roles/vmmigration.admin
    roles/vmmigration.viewer
    roles/vpaccess.user
    roles/vpaccess.viewer
    roles/vpcaccess.admin
  2. tevanraj revised this gist Aug 15, 2019. 1 changed file with 404 additions and 407 deletions.
    811 changes: 404 additions & 407 deletions list-gcp-iam-roles
    Original file line number Diff line number Diff line change
    @@ -1,407 +1,404 @@
    name: roles/accessapproval.approver
    name: roles/accessapproval.configEditor
    name: roles/accessapproval.viewer
    name: roles/accesscontextmanager.policyAdmin
    name: roles/accesscontextmanager.policyEditor
    name: roles/accesscontextmanager.policyReader
    name: roles/androidmanagement.user
    name: roles/appengine.appAdmin
    name: roles/appengine.appViewer
    name: roles/appengine.codeViewer
    name: roles/appengine.deployer
    name: roles/appengine.serviceAdmin
    name: roles/automl.admin
    name: roles/automl.editor
    name: roles/automl.predictor
    name: roles/automl.viewer
    name: roles/automlrecommendations.admin
    name: roles/automlrecommendations.adminViewer
    name: roles/automlrecommendations.editor
    name: roles/automlrecommendations.viewer
    name: roles/axt.admin
    name: roles/bigquery.admin
    name: roles/bigquery.connectionAdmin
    name: roles/bigquery.connectionUser
    name: roles/bigquery.dataEditor
    name: roles/bigquery.dataOwner
    name: roles/bigquery.dataViewer
    name: roles/bigquery.jobUser
    name: roles/bigquery.metadataViewer
    name: roles/bigquery.readSessionUser
    name: roles/bigquery.user
    name: roles/bigtable.admin
    name: roles/bigtable.reader
    name: roles/bigtable.user
    name: roles/bigtable.viewer
    name: roles/billing.admin
    name: roles/billing.creator
    name: roles/billing.projectManager
    name: roles/billing.user
    name: roles/billing.viewer
    name: roles/binaryauthorization.attestorsAdmin
    name: roles/binaryauthorization.attestorsEditor
    name: roles/binaryauthorization.attestorsVerifier
    name: roles/binaryauthorization.attestorsViewer
    name: roles/binaryauthorization.policyAdmin
    name: roles/binaryauthorization.policyEditor
    name: roles/binaryauthorization.policyViewer
    name: roles/browser
    name: roles/cloudasset.viewer
    name: roles/cloudbuild.builds.builder
    name: roles/cloudbuild.builds.editor
    name: roles/cloudbuild.builds.viewer
    name: roles/cloudbuild.serviceAgent
    name: roles/clouddebugger.agent
    name: roles/clouddebugger.user
    name: roles/cloudfunctions.admin
    name: roles/cloudfunctions.developer
    name: roles/cloudfunctions.invoker
    name: roles/cloudfunctions.viewer
    name: roles/cloudiot.admin
    name: roles/cloudiot.deviceController
    name: roles/cloudiot.editor
    name: roles/cloudiot.provisioner
    name: roles/cloudiot.viewer
    name: roles/cloudjobdiscovery.admin
    name: roles/cloudjobdiscovery.jobsEditor
    name: roles/cloudjobdiscovery.jobsViewer
    name: roles/cloudjobdiscovery.profilesEditor
    name: roles/cloudjobdiscovery.profilesViewer
    name: roles/cloudkms.admin
    name: roles/cloudkms.cryptoKeyDecrypter
    name: roles/cloudkms.cryptoKeyEncrypter
    name: roles/cloudkms.cryptoKeyEncrypterDecrypter
    name: roles/cloudkms.publicKeyViewer
    name: roles/cloudkms.signer
    name: roles/cloudkms.signerVerifier
    name: roles/cloudmigration.inframanager
    name: roles/cloudmigration.storageaccess
    name: roles/cloudmigration.velostrataconnect
    name: roles/cloudprivatecatalog.consumer
    name: roles/cloudprivatecatalogproducer.admin
    name: roles/cloudprivatecatalogproducer.manager
    name: roles/cloudprofiler.agent
    name: roles/cloudprofiler.user
    name: roles/cloudscheduler.admin
    name: roles/cloudscheduler.jobRunner
    name: roles/cloudscheduler.serviceAgent
    name: roles/cloudscheduler.viewer
    name: roles/cloudsecurityscanner.editor
    name: roles/cloudsecurityscanner.runner
    name: roles/cloudsecurityscanner.viewer
    name: roles/cloudsql.admin
    name: roles/cloudsql.client
    name: roles/cloudsql.editor
    name: roles/cloudsql.viewer
    name: roles/cloudsupport.admin
    name: roles/cloudsupport.viewer
    name: roles/cloudtasks.admin
    name: roles/cloudtasks.enqueuer
    name: roles/cloudtasks.queueAdmin
    name: roles/cloudtasks.serviceAgent
    name: roles/cloudtasks.taskDeleter
    name: roles/cloudtasks.taskRunner
    name: roles/cloudtasks.viewer
    name: roles/cloudtestservice.testAdmin
    name: roles/cloudtestservice.testViewer
    name: roles/cloudtrace.admin
    name: roles/cloudtrace.agent
    name: roles/cloudtrace.user
    name: roles/cloudtranslate.admin
    name: roles/cloudtranslate.editor
    name: roles/cloudtranslate.user
    name: roles/cloudtranslate.viewer
    name: roles/codelabapikeys.admin
    name: roles/codelabapikeys.editor
    name: roles/codelabapikeys.viewer
    name: roles/composer.admin
    name: roles/composer.environmentAndStorageObjectAdmin
    name: roles/composer.environmentAndStorageObjectViewer
    name: roles/composer.user
    name: roles/composer.worker
    name: roles/compute.admin
    name: roles/compute.imageUser
    name: roles/compute.instanceAdmin
    name: roles/compute.instanceAdmin.v1
    name: roles/compute.loadBalancerAdmin
    name: roles/compute.networkAdmin
    name: roles/compute.networkUser
    name: roles/compute.networkViewer
    name: roles/compute.orgSecurityPolicyAdmin
    name: roles/compute.orgSecurityPolicyUser
    name: roles/compute.orgSecurityResourceAdmin
    name: roles/compute.osAdminLogin
    name: roles/compute.osLogin
    name: roles/compute.osLoginExternalUser
    name: roles/compute.securityAdmin
    name: roles/compute.storageAdmin
    name: roles/compute.viewer
    name: roles/compute.xpnAdmin
    name: roles/container.admin
    name: roles/container.clusterAdmin
    name: roles/container.clusterViewer
    name: roles/container.developer
    name: roles/container.hostServiceAgentUser
    name: roles/container.viewer
    name: roles/containeranalysis.admin
    name: roles/containeranalysis.notes.attacher
    name: roles/containeranalysis.notes.editor
    name: roles/containeranalysis.notes.viewer
    name: roles/containeranalysis.occurrences.editor
    name: roles/containeranalysis.occurrences.viewer
    name: roles/datacatalog.admin
    name: roles/datacatalog.entryCreator
    name: roles/datacatalog.entryGroupCreator
    name: roles/datacatalog.entryGroupOwner
    name: roles/datacatalog.entryOwner
    name: roles/datacatalog.entryViewer
    name: roles/datacatalog.tagEditor
    name: roles/datacatalog.tagTemplateCreator
    name: roles/datacatalog.tagTemplateOwner
    name: roles/datacatalog.tagTemplateUser
    name: roles/datacatalog.tagTemplateViewer
    name: roles/datacatalog.viewer
    name: roles/dataflow.admin
    name: roles/dataflow.developer
    name: roles/dataflow.viewer
    name: roles/dataflow.worker
    name: roles/datafusion.admin
    name: roles/datafusion.serviceAgent
    name: roles/datafusion.viewer
    name: roles/datalabeling.admin
    name: roles/datalabeling.editor
    name: roles/datalabeling.viewer
    name: roles/dataprep.projects.user
    name: roles/dataproc.admin
    name: roles/dataproc.editor
    name: roles/dataproc.serviceAgent
    name: roles/dataproc.viewer
    name: roles/dataproc.worker
    name: roles/datastore.importExportAdmin
    name: roles/datastore.indexAdmin
    name: roles/datastore.owner
    name: roles/datastore.user
    name: roles/datastore.viewer
    name: roles/deploymentmanager.editor
    name: roles/deploymentmanager.typeEditor
    name: roles/deploymentmanager.typeViewer
    name: roles/deploymentmanager.viewer
    name: roles/dialogflow.admin
    name: roles/dialogflow.client
    name: roles/dialogflow.consoleAgentEditor
    name: roles/dialogflow.reader
    name: roles/dlp.admin
    name: roles/dlp.analyzeRiskTemplatesEditor
    name: roles/dlp.analyzeRiskTemplatesReader
    name: roles/dlp.deidentifyTemplatesEditor
    name: roles/dlp.deidentifyTemplatesReader
    name: roles/dlp.inspectTemplatesEditor
    name: roles/dlp.inspectTemplatesReader
    name: roles/dlp.jobTriggersEditor
    name: roles/dlp.jobTriggersReader
    name: roles/dlp.jobsEditor
    name: roles/dlp.jobsReader
    name: roles/dlp.reader
    name: roles/dlp.storedInfoTypesEditor
    name: roles/dlp.storedInfoTypesReader
    name: roles/dlp.user
    name: roles/dns.admin
    name: roles/dns.peer
    name: roles/dns.reader
    name: roles/editor
    name: roles/endpoints.portalAdmin
    name: roles/errorreporting.admin
    name: roles/errorreporting.user
    name: roles/errorreporting.viewer
    name: roles/errorreporting.writer
    name: roles/file.editor
    name: roles/file.viewer
    name: roles/firebase.admin
    name: roles/firebase.analyticsAdmin
    name: roles/firebase.analyticsViewer
    name: roles/firebase.developAdmin
    name: roles/firebase.developViewer
    name: roles/firebase.growthAdmin
    name: roles/firebase.growthViewer
    name: roles/firebase.qualityAdmin
    name: roles/firebase.qualityViewer
    name: roles/firebase.viewer
    name: roles/firebasecrash.symbolMappingsAdmin
    name: roles/genomics.admin
    name: roles/genomics.editor
    name: roles/genomics.pipelinesRunner
    name: roles/genomics.viewer
    name: roles/healthcare.annotationEditor
    name: roles/healthcare.annotationReader
    name: roles/healthcare.annotationStoreAdmin
    name: roles/healthcare.annotationStoreViewer
    name: roles/healthcare.datasetAdmin
    name: roles/healthcare.datasetViewer
    name: roles/healthcare.dicomEditor
    name: roles/healthcare.dicomStoreAdmin
    name: roles/healthcare.dicomStoreViewer
    name: roles/healthcare.dicomViewer
    name: roles/healthcare.fhirResourceEditor
    name: roles/healthcare.fhirResourceReader
    name: roles/healthcare.fhirStoreAdmin
    name: roles/healthcare.fhirStoreViewer
    name: roles/healthcare.hl7V2Consumer
    name: roles/healthcare.hl7V2Editor
    name: roles/healthcare.hl7V2Ingest
    name: roles/healthcare.hl7V2StoreAdmin
    name: roles/healthcare.hl7V2StoreViewer
    name: roles/iam.organizationRoleAdmin
    name: roles/iam.organizationRoleViewer
    name: roles/iam.roleAdmin
    name: roles/iam.roleViewer
    name: roles/iam.securityAdmin
    name: roles/iam.securityReviewer
    name: roles/iam.serviceAccountAdmin
    name: roles/iam.serviceAccountCreator
    name: roles/iam.serviceAccountDeleter
    name: roles/iam.serviceAccountKeyAdmin
    name: roles/iam.serviceAccountTokenCreator
    name: roles/iam.serviceAccountUser
    name: roles/iam.workloadIdentityUser
    name: roles/iap.admin
    name: roles/iap.httpsResourceAccessor
    name: roles/iap.tunnelResourceAccessor
    name: roles/logging.admin
    name: roles/logging.configWriter
    name: roles/logging.logWriter
    name: roles/logging.privateLogViewer
    name: roles/logging.viewer
    name: roles/managedidentities.admin
    name: roles/managedidentities.domainAdmin
    name: roles/managedidentities.viewer
    name: roles/ml.admin
    name: roles/ml.developer
    name: roles/ml.jobOwner
    name: roles/ml.modelOwner
    name: roles/ml.modelUser
    name: roles/ml.operationOwner
    name: roles/ml.viewer
    name: roles/mobilecrashreporting.symbolMappingsAdmin
    name: roles/monitoring.admin
    name: roles/monitoring.alertPolicyEditor
    name: roles/monitoring.alertPolicyViewer
    name: roles/monitoring.editor
    name: roles/monitoring.metricWriter
    name: roles/monitoring.notificationChannelEditor
    name: roles/monitoring.notificationChannelViewer
    name: roles/monitoring.uptimeCheckConfigEditor
    name: roles/monitoring.uptimeCheckConfigViewer
    name: roles/monitoring.viewer
    name: roles/orgpolicy.policyAdmin
    name: roles/orgpolicy.policyViewer
    name: roles/owner
    can list a project's namespaces.
    name: roles/proximitybeacon.attachmentEditor
    namespaces not owned by this project.
    name: roles/proximitybeacon.attachmentPublisher
    description: Can view all attachments under a namespace; no beacon or namespace permissions.
    name: roles/proximitybeacon.attachmentViewer
    or namespace permissions.
    name: roles/proximitybeacon.beaconEditor
    name: roles/pubsub.admin
    name: roles/pubsub.editor
    name: roles/pubsub.publisher
    name: roles/pubsub.subscriber
    name: roles/pubsub.viewer
    name: roles/recommender.computeAdmin
    name: roles/recommender.computeViewer
    name: roles/recommender.iamAdmin
    name: roles/recommender.iamViewer
    name: roles/redis.admin
    name: roles/redis.editor
    name: roles/redis.viewer
    name: roles/remotebuildexecution.actionCacheWriter
    name: roles/remotebuildexecution.artifactAdmin
    name: roles/remotebuildexecution.artifactCreator
    name: roles/remotebuildexecution.artifactViewer
    name: roles/remotebuildexecution.configurationAdmin
    name: roles/remotebuildexecution.configurationViewer
    name: roles/remotebuildexecution.logstreamWriter
    name: roles/remotebuildexecution.worker
    name: roles/resourcemanager.folderAdmin
    name: roles/resourcemanager.folderCreator
    name: roles/resourcemanager.folderEditor
    name: roles/resourcemanager.folderIamAdmin
    name: roles/resourcemanager.folderMover
    name: roles/resourcemanager.folderViewer
    name: roles/resourcemanager.lienModifier
    name: roles/resourcemanager.organizationAdmin
    name: roles/resourcemanager.organizationCreator
    name: roles/resourcemanager.organizationViewer
    name: roles/resourcemanager.projectCreator
    name: roles/resourcemanager.projectDeleter
    name: roles/resourcemanager.projectIamAdmin
    name: roles/resourcemanager.projectMover
    name: roles/run.admin
    name: roles/run.invoker
    name: roles/run.viewer
    name: roles/runtimeconfig.admin
    name: roles/securitycenter.admin
    name: roles/securitycenter.adminEditor
    name: roles/securitycenter.adminViewer
    name: roles/securitycenter.assetSecurityMarksWriter
    name: roles/securitycenter.assetsDiscoveryRunner
    name: roles/securitycenter.assetsViewer
    name: roles/securitycenter.findingSecurityMarksWriter
    name: roles/securitycenter.findingsEditor
    name: roles/securitycenter.findingsStateSetter
    name: roles/securitycenter.findingsViewer
    name: roles/securitycenter.sourcesAdmin
    name: roles/securitycenter.sourcesEditor
    name: roles/securitycenter.sourcesViewer
    name: roles/servicebroker.admin
    name: roles/servicebroker.operator
    name: roles/serviceconsumermanagement.tenancyUnitsAdmin
    name: roles/serviceconsumermanagement.tenancyUnitsViewer
    name: roles/servicemanagement.admin
    name: roles/servicemanagement.configEditor
    name: roles/servicemanagement.quotaAdmin
    name: roles/servicemanagement.quotaViewer
    name: roles/servicemanagement.serviceConsumer
    name: roles/servicemanagement.serviceController
    name: roles/servicenetworking.networksAdmin
    name: roles/serviceusage.apiKeysAdmin
    name: roles/serviceusage.apiKeysViewer
    name: roles/serviceusage.serviceUsageAdmin
    name: roles/serviceusage.serviceUsageConsumer
    name: roles/serviceusage.serviceUsageViewer
    name: roles/source.admin
    name: roles/source.reader
    name: roles/source.writer
    name: roles/spanner.admin
    name: roles/spanner.databaseAdmin
    name: roles/spanner.databaseReader
    name: roles/spanner.databaseUser
    name: roles/spanner.viewer
    name: roles/stackdriver.accounts.editor
    name: roles/stackdriver.accounts.viewer
    name: roles/stackdriver.resourceMaintenanceWindow.editor
    name: roles/stackdriver.resourceMaintenanceWindow.viewer
    name: roles/stackdriver.resourceMetadata.writer
    name: roles/storage.admin
    name: roles/storage.hmacKeyAdmin
    name: roles/storage.legacyBucketOwner
    name: roles/storage.legacyBucketReader
    name: roles/storage.legacyBucketWriter
    name: roles/storage.legacyObjectOwner
    name: roles/storage.legacyObjectReader
    name: roles/storage.objectAdmin
    name: roles/storage.objectCreator
    name: roles/storage.objectViewer
    name: roles/storagetransfer.admin
    name: roles/storagetransfer.user
    name: roles/storagetransfer.viewer
    name: roles/subscribewithgoogledeveloper.developer
    name: roles/threatdetection.editor
    name: roles/threatdetection.viewer
    name: roles/tpu.admin
    name: roles/tpu.viewer
    name: roles/viewer
    name: roles/vpaccess.user
    name: roles/vpaccess.viewer
    name: roles/vpcaccess.admin
    roles/accessapproval.approver
    roles/accessapproval.configEditor
    roles/accessapproval.viewer
    roles/accesscontextmanager.policyAdmin
    roles/accesscontextmanager.policyEditor
    roles/accesscontextmanager.policyReader
    roles/androidmanagement.user
    roles/appengine.appAdmin
    roles/appengine.appViewer
    roles/appengine.codeViewer
    roles/appengine.deployer
    roles/appengine.serviceAdmin
    roles/automl.admin
    roles/automl.editor
    roles/automl.predictor
    roles/automl.viewer
    roles/automlrecommendations.admin
    roles/automlrecommendations.adminViewer
    roles/automlrecommendations.editor
    roles/automlrecommendations.viewer
    roles/axt.admin
    roles/bigquery.admin
    roles/bigquery.connectionAdmin
    roles/bigquery.connectionUser
    roles/bigquery.dataEditor
    roles/bigquery.dataOwner
    roles/bigquery.dataViewer
    roles/bigquery.jobUser
    roles/bigquery.metadataViewer
    roles/bigquery.readSessionUser
    roles/bigquery.user
    roles/bigtable.admin
    roles/bigtable.reader
    roles/bigtable.user
    roles/bigtable.viewer
    roles/billing.admin
    roles/billing.creator
    roles/billing.projectManager
    roles/billing.user
    roles/billing.viewer
    roles/binaryauthorization.attestorsAdmin
    roles/binaryauthorization.attestorsEditor
    roles/binaryauthorization.attestorsVerifier
    roles/binaryauthorization.attestorsViewer
    roles/binaryauthorization.policyAdmin
    roles/binaryauthorization.policyEditor
    roles/binaryauthorization.policyViewer
    roles/browser
    roles/cloudasset.viewer
    roles/cloudbuild.builds.builder
    roles/cloudbuild.builds.editor
    roles/cloudbuild.builds.viewer
    roles/cloudbuild.serviceAgent
    roles/clouddebugger.agent
    roles/clouddebugger.user
    roles/cloudfunctions.admin
    roles/cloudfunctions.developer
    roles/cloudfunctions.invoker
    roles/cloudfunctions.viewer
    roles/cloudiot.admin
    roles/cloudiot.deviceController
    roles/cloudiot.editor
    roles/cloudiot.provisioner
    roles/cloudiot.viewer
    roles/cloudjobdiscovery.admin
    roles/cloudjobdiscovery.jobsEditor
    roles/cloudjobdiscovery.jobsViewer
    roles/cloudjobdiscovery.profilesEditor
    roles/cloudjobdiscovery.profilesViewer
    roles/cloudkms.admin
    roles/cloudkms.cryptoKeyDecrypter
    roles/cloudkms.cryptoKeyEncrypter
    roles/cloudkms.cryptoKeyEncrypterDecrypter
    roles/cloudkms.publicKeyViewer
    roles/cloudkms.signer
    roles/cloudkms.signerVerifier
    roles/cloudmigration.inframanager
    roles/cloudmigration.storageaccess
    roles/cloudmigration.velostrataconnect
    roles/cloudprivatecatalog.consumer
    roles/cloudprivatecatalogproducer.admin
    roles/cloudprivatecatalogproducer.manager
    roles/cloudprofiler.agent
    roles/cloudprofiler.user
    roles/cloudscheduler.admin
    roles/cloudscheduler.jobRunner
    roles/cloudscheduler.serviceAgent
    roles/cloudscheduler.viewer
    roles/cloudsecurityscanner.editor
    roles/cloudsecurityscanner.runner
    roles/cloudsecurityscanner.viewer
    roles/cloudsql.admin
    roles/cloudsql.client
    roles/cloudsql.editor
    roles/cloudsql.viewer
    roles/cloudsupport.admin
    roles/cloudsupport.viewer
    roles/cloudtasks.admin
    roles/cloudtasks.enqueuer
    roles/cloudtasks.queueAdmin
    roles/cloudtasks.serviceAgent
    roles/cloudtasks.taskDeleter
    roles/cloudtasks.taskRunner
    roles/cloudtasks.viewer
    roles/cloudtestservice.testAdmin
    roles/cloudtestservice.testViewer
    roles/cloudtrace.admin
    roles/cloudtrace.agent
    roles/cloudtrace.user
    roles/cloudtranslate.admin
    roles/cloudtranslate.editor
    roles/cloudtranslate.user
    roles/cloudtranslate.viewer
    roles/codelabapikeys.admin
    roles/codelabapikeys.editor
    roles/codelabapikeys.viewer
    roles/composer.admin
    roles/composer.environmentAndStorageObjectAdmin
    roles/composer.environmentAndStorageObjectViewer
    roles/composer.user
    roles/composer.worker
    roles/compute.admin
    roles/compute.imageUser
    roles/compute.instanceAdmin
    roles/compute.instanceAdmin.v1
    roles/compute.loadBalancerAdmin
    roles/compute.networkAdmin
    roles/compute.networkUser
    roles/compute.networkViewer
    roles/compute.orgSecurityPolicyAdmin
    roles/compute.orgSecurityPolicyUser
    roles/compute.orgSecurityResourceAdmin
    roles/compute.osAdminLogin
    roles/compute.osLogin
    roles/compute.osLoginExternalUser
    roles/compute.securityAdmin
    roles/compute.storageAdmin
    roles/compute.viewer
    roles/compute.xpnAdmin
    roles/container.admin
    roles/container.clusterAdmin
    roles/container.clusterViewer
    roles/container.developer
    roles/container.hostServiceAgentUser
    roles/container.viewer
    roles/containeranalysis.admin
    roles/containeranalysis.notes.attacher
    roles/containeranalysis.notes.editor
    roles/containeranalysis.notes.viewer
    roles/containeranalysis.occurrences.editor
    roles/containeranalysis.occurrences.viewer
    roles/datacatalog.admin
    roles/datacatalog.entryCreator
    roles/datacatalog.entryGroupCreator
    roles/datacatalog.entryGroupOwner
    roles/datacatalog.entryOwner
    roles/datacatalog.entryViewer
    roles/datacatalog.tagEditor
    roles/datacatalog.tagTemplateCreator
    roles/datacatalog.tagTemplateOwner
    roles/datacatalog.tagTemplateUser
    roles/datacatalog.tagTemplateViewer
    roles/datacatalog.viewer
    roles/dataflow.admin
    roles/dataflow.developer
    roles/dataflow.viewer
    roles/dataflow.worker
    roles/datafusion.admin
    roles/datafusion.serviceAgent
    roles/datafusion.viewer
    roles/datalabeling.admin
    roles/datalabeling.editor
    roles/datalabeling.viewer
    roles/dataprep.projects.user
    roles/dataproc.admin
    roles/dataproc.editor
    roles/dataproc.serviceAgent
    roles/dataproc.viewer
    roles/dataproc.worker
    roles/datastore.importExportAdmin
    roles/datastore.indexAdmin
    roles/datastore.owner
    roles/datastore.user
    roles/datastore.viewer
    roles/deploymentmanager.editor
    roles/deploymentmanager.typeEditor
    roles/deploymentmanager.typeViewer
    roles/deploymentmanager.viewer
    roles/dialogflow.admin
    roles/dialogflow.client
    roles/dialogflow.consoleAgentEditor
    roles/dialogflow.reader
    roles/dlp.admin
    roles/dlp.analyzeRiskTemplatesEditor
    roles/dlp.analyzeRiskTemplatesReader
    roles/dlp.deidentifyTemplatesEditor
    roles/dlp.deidentifyTemplatesReader
    roles/dlp.inspectTemplatesEditor
    roles/dlp.inspectTemplatesReader
    roles/dlp.jobTriggersEditor
    roles/dlp.jobTriggersReader
    roles/dlp.jobsEditor
    roles/dlp.jobsReader
    roles/dlp.reader
    roles/dlp.storedInfoTypesEditor
    roles/dlp.storedInfoTypesReader
    roles/dlp.user
    roles/dns.admin
    roles/dns.peer
    roles/dns.reader
    roles/editor
    roles/endpoints.portalAdmin
    roles/errorreporting.admin
    roles/errorreporting.user
    roles/errorreporting.viewer
    roles/errorreporting.writer
    roles/file.editor
    roles/file.viewer
    roles/firebase.admin
    roles/firebase.analyticsAdmin
    roles/firebase.analyticsViewer
    roles/firebase.developAdmin
    roles/firebase.developViewer
    roles/firebase.growthAdmin
    roles/firebase.growthViewer
    roles/firebase.qualityAdmin
    roles/firebase.qualityViewer
    roles/firebase.viewer
    roles/firebasecrash.symbolMappingsAdmin
    roles/genomics.admin
    roles/genomics.editor
    roles/genomics.pipelinesRunner
    roles/genomics.viewer
    roles/healthcare.annotationEditor
    roles/healthcare.annotationReader
    roles/healthcare.annotationStoreAdmin
    roles/healthcare.annotationStoreViewer
    roles/healthcare.datasetAdmin
    roles/healthcare.datasetViewer
    roles/healthcare.dicomEditor
    roles/healthcare.dicomStoreAdmin
    roles/healthcare.dicomStoreViewer
    roles/healthcare.dicomViewer
    roles/healthcare.fhirResourceEditor
    roles/healthcare.fhirResourceReader
    roles/healthcare.fhirStoreAdmin
    roles/healthcare.fhirStoreViewer
    roles/healthcare.hl7V2Consumer
    roles/healthcare.hl7V2Editor
    roles/healthcare.hl7V2Ingest
    roles/healthcare.hl7V2StoreAdmin
    roles/healthcare.hl7V2StoreViewer
    roles/iam.organizationRoleAdmin
    roles/iam.organizationRoleViewer
    roles/iam.roleAdmin
    roles/iam.roleViewer
    roles/iam.securityAdmin
    roles/iam.securityReviewer
    roles/iam.serviceAccountAdmin
    roles/iam.serviceAccountCreator
    roles/iam.serviceAccountDeleter
    roles/iam.serviceAccountKeyAdmin
    roles/iam.serviceAccountTokenCreator
    roles/iam.serviceAccountUser
    roles/iam.workloadIdentityUser
    roles/iap.admin
    roles/iap.httpsResourceAccessor
    roles/iap.tunnelResourceAccessor
    roles/logging.admin
    roles/logging.configWriter
    roles/logging.logWriter
    roles/logging.privateLogViewer
    roles/logging.viewer
    roles/managedidentities.admin
    roles/managedidentities.domainAdmin
    roles/managedidentities.viewer
    roles/ml.admin
    roles/ml.developer
    roles/ml.jobOwner
    roles/ml.modelOwner
    roles/ml.modelUser
    roles/ml.operationOwner
    roles/ml.viewer
    roles/mobilecrashreporting.symbolMappingsAdmin
    roles/monitoring.admin
    roles/monitoring.alertPolicyEditor
    roles/monitoring.alertPolicyViewer
    roles/monitoring.editor
    roles/monitoring.metricWriter
    roles/monitoring.notificationChannelEditor
    roles/monitoring.notificationChannelViewer
    roles/monitoring.uptimeCheckConfigEditor
    roles/monitoring.uptimeCheckConfigViewer
    roles/monitoring.viewer
    roles/orgpolicy.policyAdmin
    roles/orgpolicy.policyViewer
    roles/ownerlist a project's namespaces.
    roles/proximitybeacon.attachmentEditorspaces not owned by this project.
    roles/proximitybeacon.attachmentPublisher
    ption: Can view all attachments under a namespace; no beacon or namespace permissions.
    roles/proximitybeacon.attachmentVieweramespace permissions.
    roles/proximitybeacon.beaconEditor
    roles/pubsub.admin
    roles/pubsub.editor
    roles/pubsub.publisher
    roles/pubsub.subscriber
    roles/pubsub.viewer
    roles/recommender.computeAdmin
    roles/recommender.computeViewer
    roles/recommender.iamAdmin
    roles/recommender.iamViewer
    roles/redis.admin
    roles/redis.editor
    roles/redis.viewer
    roles/remotebuildexecution.actionCacheWriter
    roles/remotebuildexecution.artifactAdmin
    roles/remotebuildexecution.artifactCreator
    roles/remotebuildexecution.artifactViewer
    roles/remotebuildexecution.configurationAdmin
    roles/remotebuildexecution.configurationViewer
    roles/remotebuildexecution.logstreamWriter
    roles/remotebuildexecution.worker
    roles/resourcemanager.folderAdmin
    roles/resourcemanager.folderCreator
    roles/resourcemanager.folderEditor
    roles/resourcemanager.folderIamAdmin
    roles/resourcemanager.folderMover
    roles/resourcemanager.folderViewer
    roles/resourcemanager.lienModifier
    roles/resourcemanager.organizationAdmin
    roles/resourcemanager.organizationCreator
    roles/resourcemanager.organizationViewer
    roles/resourcemanager.projectCreator
    roles/resourcemanager.projectDeleter
    roles/resourcemanager.projectIamAdmin
    roles/resourcemanager.projectMover
    roles/run.admin
    roles/run.invoker
    roles/run.viewer
    roles/runtimeconfig.admin
    roles/securitycenter.admin
    roles/securitycenter.adminEditor
    roles/securitycenter.adminViewer
    roles/securitycenter.assetSecurityMarksWriter
    roles/securitycenter.assetsDiscoveryRunner
    roles/securitycenter.assetsViewer
    roles/securitycenter.findingSecurityMarksWriter
    roles/securitycenter.findingsEditor
    roles/securitycenter.findingsStateSetter
    roles/securitycenter.findingsViewer
    roles/securitycenter.sourcesAdmin
    roles/securitycenter.sourcesEditor
    roles/securitycenter.sourcesViewer
    roles/servicebroker.admin
    roles/servicebroker.operator
    roles/serviceconsumermanagement.tenancyUnitsAdmin
    roles/serviceconsumermanagement.tenancyUnitsViewer
    roles/servicemanagement.admin
    roles/servicemanagement.configEditor
    roles/servicemanagement.quotaAdmin
    roles/servicemanagement.quotaViewer
    roles/servicemanagement.serviceConsumer
    roles/servicemanagement.serviceController
    roles/servicenetworking.networksAdmin
    roles/serviceusage.apiKeysAdmin
    roles/serviceusage.apiKeysViewer
    roles/serviceusage.serviceUsageAdmin
    roles/serviceusage.serviceUsageConsumer
    roles/serviceusage.serviceUsageViewer
    roles/source.admin
    roles/source.reader
    roles/source.writer
    roles/spanner.admin
    roles/spanner.databaseAdmin
    roles/spanner.databaseReader
    roles/spanner.databaseUser
    roles/spanner.viewer
    roles/stackdriver.accounts.editor
    roles/stackdriver.accounts.viewer
    roles/stackdriver.resourceMaintenanceWindow.editor
    roles/stackdriver.resourceMaintenanceWindow.viewer
    roles/stackdriver.resourceMetadata.writer
    roles/storage.admin
    roles/storage.hmacKeyAdmin
    roles/storage.legacyBucketOwner
    roles/storage.legacyBucketReader
    roles/storage.legacyBucketWriter
    roles/storage.legacyObjectOwner
    roles/storage.legacyObjectReader
    roles/storage.objectAdmin
    roles/storage.objectCreator
    roles/storage.objectViewer
    roles/storagetransfer.admin
    roles/storagetransfer.user
    roles/storagetransfer.viewer
    roles/subscribewithgoogledeveloper.developer
    roles/threatdetection.editor
    roles/threatdetection.viewer
    roles/tpu.admin
    roles/tpu.viewer
    roles/viewer
    roles/vpaccess.user
    roles/vpaccess.viewer
    roles/vpcaccess.admin
  3. tevanraj created this gist Aug 15, 2019.
    407 changes: 407 additions & 0 deletions list-gcp-iam-roles
    Original file line number Diff line number Diff line change
    @@ -0,0 +1,407 @@
    name: roles/accessapproval.approver
    name: roles/accessapproval.configEditor
    name: roles/accessapproval.viewer
    name: roles/accesscontextmanager.policyAdmin
    name: roles/accesscontextmanager.policyEditor
    name: roles/accesscontextmanager.policyReader
    name: roles/androidmanagement.user
    name: roles/appengine.appAdmin
    name: roles/appengine.appViewer
    name: roles/appengine.codeViewer
    name: roles/appengine.deployer
    name: roles/appengine.serviceAdmin
    name: roles/automl.admin
    name: roles/automl.editor
    name: roles/automl.predictor
    name: roles/automl.viewer
    name: roles/automlrecommendations.admin
    name: roles/automlrecommendations.adminViewer
    name: roles/automlrecommendations.editor
    name: roles/automlrecommendations.viewer
    name: roles/axt.admin
    name: roles/bigquery.admin
    name: roles/bigquery.connectionAdmin
    name: roles/bigquery.connectionUser
    name: roles/bigquery.dataEditor
    name: roles/bigquery.dataOwner
    name: roles/bigquery.dataViewer
    name: roles/bigquery.jobUser
    name: roles/bigquery.metadataViewer
    name: roles/bigquery.readSessionUser
    name: roles/bigquery.user
    name: roles/bigtable.admin
    name: roles/bigtable.reader
    name: roles/bigtable.user
    name: roles/bigtable.viewer
    name: roles/billing.admin
    name: roles/billing.creator
    name: roles/billing.projectManager
    name: roles/billing.user
    name: roles/billing.viewer
    name: roles/binaryauthorization.attestorsAdmin
    name: roles/binaryauthorization.attestorsEditor
    name: roles/binaryauthorization.attestorsVerifier
    name: roles/binaryauthorization.attestorsViewer
    name: roles/binaryauthorization.policyAdmin
    name: roles/binaryauthorization.policyEditor
    name: roles/binaryauthorization.policyViewer
    name: roles/browser
    name: roles/cloudasset.viewer
    name: roles/cloudbuild.builds.builder
    name: roles/cloudbuild.builds.editor
    name: roles/cloudbuild.builds.viewer
    name: roles/cloudbuild.serviceAgent
    name: roles/clouddebugger.agent
    name: roles/clouddebugger.user
    name: roles/cloudfunctions.admin
    name: roles/cloudfunctions.developer
    name: roles/cloudfunctions.invoker
    name: roles/cloudfunctions.viewer
    name: roles/cloudiot.admin
    name: roles/cloudiot.deviceController
    name: roles/cloudiot.editor
    name: roles/cloudiot.provisioner
    name: roles/cloudiot.viewer
    name: roles/cloudjobdiscovery.admin
    name: roles/cloudjobdiscovery.jobsEditor
    name: roles/cloudjobdiscovery.jobsViewer
    name: roles/cloudjobdiscovery.profilesEditor
    name: roles/cloudjobdiscovery.profilesViewer
    name: roles/cloudkms.admin
    name: roles/cloudkms.cryptoKeyDecrypter
    name: roles/cloudkms.cryptoKeyEncrypter
    name: roles/cloudkms.cryptoKeyEncrypterDecrypter
    name: roles/cloudkms.publicKeyViewer
    name: roles/cloudkms.signer
    name: roles/cloudkms.signerVerifier
    name: roles/cloudmigration.inframanager
    name: roles/cloudmigration.storageaccess
    name: roles/cloudmigration.velostrataconnect
    name: roles/cloudprivatecatalog.consumer
    name: roles/cloudprivatecatalogproducer.admin
    name: roles/cloudprivatecatalogproducer.manager
    name: roles/cloudprofiler.agent
    name: roles/cloudprofiler.user
    name: roles/cloudscheduler.admin
    name: roles/cloudscheduler.jobRunner
    name: roles/cloudscheduler.serviceAgent
    name: roles/cloudscheduler.viewer
    name: roles/cloudsecurityscanner.editor
    name: roles/cloudsecurityscanner.runner
    name: roles/cloudsecurityscanner.viewer
    name: roles/cloudsql.admin
    name: roles/cloudsql.client
    name: roles/cloudsql.editor
    name: roles/cloudsql.viewer
    name: roles/cloudsupport.admin
    name: roles/cloudsupport.viewer
    name: roles/cloudtasks.admin
    name: roles/cloudtasks.enqueuer
    name: roles/cloudtasks.queueAdmin
    name: roles/cloudtasks.serviceAgent
    name: roles/cloudtasks.taskDeleter
    name: roles/cloudtasks.taskRunner
    name: roles/cloudtasks.viewer
    name: roles/cloudtestservice.testAdmin
    name: roles/cloudtestservice.testViewer
    name: roles/cloudtrace.admin
    name: roles/cloudtrace.agent
    name: roles/cloudtrace.user
    name: roles/cloudtranslate.admin
    name: roles/cloudtranslate.editor
    name: roles/cloudtranslate.user
    name: roles/cloudtranslate.viewer
    name: roles/codelabapikeys.admin
    name: roles/codelabapikeys.editor
    name: roles/codelabapikeys.viewer
    name: roles/composer.admin
    name: roles/composer.environmentAndStorageObjectAdmin
    name: roles/composer.environmentAndStorageObjectViewer
    name: roles/composer.user
    name: roles/composer.worker
    name: roles/compute.admin
    name: roles/compute.imageUser
    name: roles/compute.instanceAdmin
    name: roles/compute.instanceAdmin.v1
    name: roles/compute.loadBalancerAdmin
    name: roles/compute.networkAdmin
    name: roles/compute.networkUser
    name: roles/compute.networkViewer
    name: roles/compute.orgSecurityPolicyAdmin
    name: roles/compute.orgSecurityPolicyUser
    name: roles/compute.orgSecurityResourceAdmin
    name: roles/compute.osAdminLogin
    name: roles/compute.osLogin
    name: roles/compute.osLoginExternalUser
    name: roles/compute.securityAdmin
    name: roles/compute.storageAdmin
    name: roles/compute.viewer
    name: roles/compute.xpnAdmin
    name: roles/container.admin
    name: roles/container.clusterAdmin
    name: roles/container.clusterViewer
    name: roles/container.developer
    name: roles/container.hostServiceAgentUser
    name: roles/container.viewer
    name: roles/containeranalysis.admin
    name: roles/containeranalysis.notes.attacher
    name: roles/containeranalysis.notes.editor
    name: roles/containeranalysis.notes.viewer
    name: roles/containeranalysis.occurrences.editor
    name: roles/containeranalysis.occurrences.viewer
    name: roles/datacatalog.admin
    name: roles/datacatalog.entryCreator
    name: roles/datacatalog.entryGroupCreator
    name: roles/datacatalog.entryGroupOwner
    name: roles/datacatalog.entryOwner
    name: roles/datacatalog.entryViewer
    name: roles/datacatalog.tagEditor
    name: roles/datacatalog.tagTemplateCreator
    name: roles/datacatalog.tagTemplateOwner
    name: roles/datacatalog.tagTemplateUser
    name: roles/datacatalog.tagTemplateViewer
    name: roles/datacatalog.viewer
    name: roles/dataflow.admin
    name: roles/dataflow.developer
    name: roles/dataflow.viewer
    name: roles/dataflow.worker
    name: roles/datafusion.admin
    name: roles/datafusion.serviceAgent
    name: roles/datafusion.viewer
    name: roles/datalabeling.admin
    name: roles/datalabeling.editor
    name: roles/datalabeling.viewer
    name: roles/dataprep.projects.user
    name: roles/dataproc.admin
    name: roles/dataproc.editor
    name: roles/dataproc.serviceAgent
    name: roles/dataproc.viewer
    name: roles/dataproc.worker
    name: roles/datastore.importExportAdmin
    name: roles/datastore.indexAdmin
    name: roles/datastore.owner
    name: roles/datastore.user
    name: roles/datastore.viewer
    name: roles/deploymentmanager.editor
    name: roles/deploymentmanager.typeEditor
    name: roles/deploymentmanager.typeViewer
    name: roles/deploymentmanager.viewer
    name: roles/dialogflow.admin
    name: roles/dialogflow.client
    name: roles/dialogflow.consoleAgentEditor
    name: roles/dialogflow.reader
    name: roles/dlp.admin
    name: roles/dlp.analyzeRiskTemplatesEditor
    name: roles/dlp.analyzeRiskTemplatesReader
    name: roles/dlp.deidentifyTemplatesEditor
    name: roles/dlp.deidentifyTemplatesReader
    name: roles/dlp.inspectTemplatesEditor
    name: roles/dlp.inspectTemplatesReader
    name: roles/dlp.jobTriggersEditor
    name: roles/dlp.jobTriggersReader
    name: roles/dlp.jobsEditor
    name: roles/dlp.jobsReader
    name: roles/dlp.reader
    name: roles/dlp.storedInfoTypesEditor
    name: roles/dlp.storedInfoTypesReader
    name: roles/dlp.user
    name: roles/dns.admin
    name: roles/dns.peer
    name: roles/dns.reader
    name: roles/editor
    name: roles/endpoints.portalAdmin
    name: roles/errorreporting.admin
    name: roles/errorreporting.user
    name: roles/errorreporting.viewer
    name: roles/errorreporting.writer
    name: roles/file.editor
    name: roles/file.viewer
    name: roles/firebase.admin
    name: roles/firebase.analyticsAdmin
    name: roles/firebase.analyticsViewer
    name: roles/firebase.developAdmin
    name: roles/firebase.developViewer
    name: roles/firebase.growthAdmin
    name: roles/firebase.growthViewer
    name: roles/firebase.qualityAdmin
    name: roles/firebase.qualityViewer
    name: roles/firebase.viewer
    name: roles/firebasecrash.symbolMappingsAdmin
    name: roles/genomics.admin
    name: roles/genomics.editor
    name: roles/genomics.pipelinesRunner
    name: roles/genomics.viewer
    name: roles/healthcare.annotationEditor
    name: roles/healthcare.annotationReader
    name: roles/healthcare.annotationStoreAdmin
    name: roles/healthcare.annotationStoreViewer
    name: roles/healthcare.datasetAdmin
    name: roles/healthcare.datasetViewer
    name: roles/healthcare.dicomEditor
    name: roles/healthcare.dicomStoreAdmin
    name: roles/healthcare.dicomStoreViewer
    name: roles/healthcare.dicomViewer
    name: roles/healthcare.fhirResourceEditor
    name: roles/healthcare.fhirResourceReader
    name: roles/healthcare.fhirStoreAdmin
    name: roles/healthcare.fhirStoreViewer
    name: roles/healthcare.hl7V2Consumer
    name: roles/healthcare.hl7V2Editor
    name: roles/healthcare.hl7V2Ingest
    name: roles/healthcare.hl7V2StoreAdmin
    name: roles/healthcare.hl7V2StoreViewer
    name: roles/iam.organizationRoleAdmin
    name: roles/iam.organizationRoleViewer
    name: roles/iam.roleAdmin
    name: roles/iam.roleViewer
    name: roles/iam.securityAdmin
    name: roles/iam.securityReviewer
    name: roles/iam.serviceAccountAdmin
    name: roles/iam.serviceAccountCreator
    name: roles/iam.serviceAccountDeleter
    name: roles/iam.serviceAccountKeyAdmin
    name: roles/iam.serviceAccountTokenCreator
    name: roles/iam.serviceAccountUser
    name: roles/iam.workloadIdentityUser
    name: roles/iap.admin
    name: roles/iap.httpsResourceAccessor
    name: roles/iap.tunnelResourceAccessor
    name: roles/logging.admin
    name: roles/logging.configWriter
    name: roles/logging.logWriter
    name: roles/logging.privateLogViewer
    name: roles/logging.viewer
    name: roles/managedidentities.admin
    name: roles/managedidentities.domainAdmin
    name: roles/managedidentities.viewer
    name: roles/ml.admin
    name: roles/ml.developer
    name: roles/ml.jobOwner
    name: roles/ml.modelOwner
    name: roles/ml.modelUser
    name: roles/ml.operationOwner
    name: roles/ml.viewer
    name: roles/mobilecrashreporting.symbolMappingsAdmin
    name: roles/monitoring.admin
    name: roles/monitoring.alertPolicyEditor
    name: roles/monitoring.alertPolicyViewer
    name: roles/monitoring.editor
    name: roles/monitoring.metricWriter
    name: roles/monitoring.notificationChannelEditor
    name: roles/monitoring.notificationChannelViewer
    name: roles/monitoring.uptimeCheckConfigEditor
    name: roles/monitoring.uptimeCheckConfigViewer
    name: roles/monitoring.viewer
    name: roles/orgpolicy.policyAdmin
    name: roles/orgpolicy.policyViewer
    name: roles/owner
    can list a project's namespaces.
    name: roles/proximitybeacon.attachmentEditor
    namespaces not owned by this project.
    name: roles/proximitybeacon.attachmentPublisher
    description: Can view all attachments under a namespace; no beacon or namespace permissions.
    name: roles/proximitybeacon.attachmentViewer
    or namespace permissions.
    name: roles/proximitybeacon.beaconEditor
    name: roles/pubsub.admin
    name: roles/pubsub.editor
    name: roles/pubsub.publisher
    name: roles/pubsub.subscriber
    name: roles/pubsub.viewer
    name: roles/recommender.computeAdmin
    name: roles/recommender.computeViewer
    name: roles/recommender.iamAdmin
    name: roles/recommender.iamViewer
    name: roles/redis.admin
    name: roles/redis.editor
    name: roles/redis.viewer
    name: roles/remotebuildexecution.actionCacheWriter
    name: roles/remotebuildexecution.artifactAdmin
    name: roles/remotebuildexecution.artifactCreator
    name: roles/remotebuildexecution.artifactViewer
    name: roles/remotebuildexecution.configurationAdmin
    name: roles/remotebuildexecution.configurationViewer
    name: roles/remotebuildexecution.logstreamWriter
    name: roles/remotebuildexecution.worker
    name: roles/resourcemanager.folderAdmin
    name: roles/resourcemanager.folderCreator
    name: roles/resourcemanager.folderEditor
    name: roles/resourcemanager.folderIamAdmin
    name: roles/resourcemanager.folderMover
    name: roles/resourcemanager.folderViewer
    name: roles/resourcemanager.lienModifier
    name: roles/resourcemanager.organizationAdmin
    name: roles/resourcemanager.organizationCreator
    name: roles/resourcemanager.organizationViewer
    name: roles/resourcemanager.projectCreator
    name: roles/resourcemanager.projectDeleter
    name: roles/resourcemanager.projectIamAdmin
    name: roles/resourcemanager.projectMover
    name: roles/run.admin
    name: roles/run.invoker
    name: roles/run.viewer
    name: roles/runtimeconfig.admin
    name: roles/securitycenter.admin
    name: roles/securitycenter.adminEditor
    name: roles/securitycenter.adminViewer
    name: roles/securitycenter.assetSecurityMarksWriter
    name: roles/securitycenter.assetsDiscoveryRunner
    name: roles/securitycenter.assetsViewer
    name: roles/securitycenter.findingSecurityMarksWriter
    name: roles/securitycenter.findingsEditor
    name: roles/securitycenter.findingsStateSetter
    name: roles/securitycenter.findingsViewer
    name: roles/securitycenter.sourcesAdmin
    name: roles/securitycenter.sourcesEditor
    name: roles/securitycenter.sourcesViewer
    name: roles/servicebroker.admin
    name: roles/servicebroker.operator
    name: roles/serviceconsumermanagement.tenancyUnitsAdmin
    name: roles/serviceconsumermanagement.tenancyUnitsViewer
    name: roles/servicemanagement.admin
    name: roles/servicemanagement.configEditor
    name: roles/servicemanagement.quotaAdmin
    name: roles/servicemanagement.quotaViewer
    name: roles/servicemanagement.serviceConsumer
    name: roles/servicemanagement.serviceController
    name: roles/servicenetworking.networksAdmin
    name: roles/serviceusage.apiKeysAdmin
    name: roles/serviceusage.apiKeysViewer
    name: roles/serviceusage.serviceUsageAdmin
    name: roles/serviceusage.serviceUsageConsumer
    name: roles/serviceusage.serviceUsageViewer
    name: roles/source.admin
    name: roles/source.reader
    name: roles/source.writer
    name: roles/spanner.admin
    name: roles/spanner.databaseAdmin
    name: roles/spanner.databaseReader
    name: roles/spanner.databaseUser
    name: roles/spanner.viewer
    name: roles/stackdriver.accounts.editor
    name: roles/stackdriver.accounts.viewer
    name: roles/stackdriver.resourceMaintenanceWindow.editor
    name: roles/stackdriver.resourceMaintenanceWindow.viewer
    name: roles/stackdriver.resourceMetadata.writer
    name: roles/storage.admin
    name: roles/storage.hmacKeyAdmin
    name: roles/storage.legacyBucketOwner
    name: roles/storage.legacyBucketReader
    name: roles/storage.legacyBucketWriter
    name: roles/storage.legacyObjectOwner
    name: roles/storage.legacyObjectReader
    name: roles/storage.objectAdmin
    name: roles/storage.objectCreator
    name: roles/storage.objectViewer
    name: roles/storagetransfer.admin
    name: roles/storagetransfer.user
    name: roles/storagetransfer.viewer
    name: roles/subscribewithgoogledeveloper.developer
    name: roles/threatdetection.editor
    name: roles/threatdetection.viewer
    name: roles/tpu.admin
    name: roles/tpu.viewer
    name: roles/viewer
    name: roles/vpaccess.user
    name: roles/vpaccess.viewer
    name: roles/vpcaccess.admin