API permissions required for Google Cloud Platform
Following are the permissions required for the roles that you need to create for Resiliency Manager and IMS for recovery to Google Cloud Platform data center.
Table: API Permissions required for role for Resiliency Manager
Service name | Permissions |
|---|---|
compute | compute.regions.list |
storage | storage.buckets.list |
Table: API Permissions required for role for IMS
Service name | Permission |
|---|---|
cloudkms | cloudkms.cryptoKeyVersions.list |
cloudkms.cryptoKeys.list | |
cloudkms.keyRings.list | |
compute | compute.addresses.list |
compute.diskTypes.list | |
compute.disks.create | |
compute.disks.createSnapshot | |
compute.disks.delete | |
compute.disks.list | |
compute.disks.use | |
compute.disks.get | |
compute.firewalls.list | |
compute.globalOperations.list | |
compute.images.create | |
compute.images.get | |
compute.images.useReadOnly | |
compute.instances.attachDisk | |
compute.instances.create | |
compute.instances.delete | |
compute.instances.detachDisk | |
compute.instances.get | |
compute.instances.list | |
compute.instances.setMetadata | |
compute.instances.setTags | |
compute.instances.start | |
compute.instances.stop | |
compute.machineTypes.list | |
compute.networks.list | |
compute.projects.get | |
compute.regionOperations.list | |
compute.snapshots.create | |
compute.snapshots.delete | |
compute.snapshots.list | |
compute.snapshots.useReadOnly | |
compute.subnetworks.list | |
compute.subnetworks.use | |
compute.zoneOperations.list | |
compute.zones.list | |
compute.addresses.useInternal | |
storage | storage.objects.create |
storage.objects.get |
Table: Permissions required to discover Shared VPC for a role for IMS on the host project.
Service name | Permission |
|---|---|
compute | compute.networks.list |
compute.firewalls.list | |
compute.addresses.list |
Note:
To share subnets from the host project with configured project, you need to add the Service Account associated with IMS as Principal and provide a Compute Network User role on the shared subnets.