Access control with IAM
Container Analysis Service Agent
(roles/)
Gives Container Analysis API the access it needs to function
artifactregistry.
artifactregistry.
artifactregistry.
artifactregistry.dockerimages. get artifactregistry.dockerimages. list
artifactregistry.
artifactregistry.files.get
artifactregistry.files.list
artifactregistry.locations.*
artifactregistry.locations.getartifactregistry.locations. list
artifactregistry.
artifactregistry.mavenartifacts. get artifactregistry.mavenartifacts. list
artifactregistry.npmpackages.*
artifactregistry.npmpackages. get artifactregistry.npmpackages. list
artifactregistry.packages.get
artifactregistry.packages.list
artifactregistry.
artifactregistry.
artifactregistry.pythonpackages. get artifactregistry.pythonpackages. list
artifactregistry.
artifactregistry.
artifactregistry.
artifactregistry.
artifactregistry.
artifactregistry.
artifactregistry.
artifactregistry.rules.get
artifactregistry.rules.list
artifactregistry.tags.get
artifactregistry.tags.list
artifactregistry.versions.get
artifactregistry.versions.list
containeranalysis.notes.list
containeranalysis.
containeranalysis.
containeranalysis.
containeranalysis.
containeranalysis.
pubsub.
pubsub.schemas.attach
pubsub.schemas.commit
pubsub.schemas.create
pubsub.schemas.delete
pubsub.schemas.get
pubsub.schemas.list
pubsub.schemas.listRevisions
pubsub.schemas.rollback
pubsub.schemas.validate
pubsub.snapshots.create
pubsub.snapshots.delete
pubsub.snapshots.get
pubsub.snapshots.list
pubsub.
pubsub.
pubsub.snapshots.seek
pubsub.snapshots.update
pubsub.subscriptions.consume
pubsub.subscriptions.create
pubsub.subscriptions.delete
pubsub.subscriptions.get
pubsub.subscriptions.list
pubsub.
pubsub.
pubsub.subscriptions.update
pubsub.
pubsub.topics.create
pubsub.topics.delete
pubsub.
pubsub.topics.get
pubsub.topics.list
pubsub.
pubsub.topics.listTagBindings
pubsub.topics.publish
pubsub.topics.update
pubsub.topics.updateTag
resourcemanager.projects.get
resourcemanager.projects.list
serviceusage.
serviceusage.
serviceusage.
serviceusage.groups.*
serviceusage.groups.listserviceusage.groups. listExpandedMembers serviceusage.groups. listMembers
serviceusage.quotas.get
serviceusage.services.get
serviceusage.services.list
serviceusage.values.test
storage.objects.get
storage.objects.list
Container Analysis Admin
(roles/)
Access to all Container Analysis resources.
containeranalysis.
containeranalysis.notes.create
containeranalysis.notes.delete
containeranalysis.notes.get
containeranalysis.
containeranalysis.notes.list
containeranalysis.
containeranalysis.notes.update
containeranalysis.
containeranalysis.occurrences. create containeranalysis.occurrences. delete containeranalysis.occurrences. get containeranalysis.occurrences. getIamPolicy containeranalysis.occurrences. list containeranalysis.occurrences. setIamPolicy containeranalysis.occurrences. update
resourcemanager.projects.get
resourcemanager.projects.list
Container Analysis Notes Attacher
(roles/)
Can attach Container Analysis Occurrences to Notes.
containeranalysis.
containeranalysis.notes.get
Container Analysis Notes Editor
(roles/)
Can edit Container Analysis Notes.
containeranalysis.
containeranalysis.notes.create
containeranalysis.notes.delete
containeranalysis.notes.get
containeranalysis.notes.list
containeranalysis.notes.update
resourcemanager.projects.get
resourcemanager.projects.list
Container Analysis Occurrences for Notes Viewer
(roles/)
Can view all Container Analysis Occurrences attached to a Note.
containeranalysis.notes.get
containeranalysis.
Container Analysis Notes Viewer
(roles/)
Can view Container Analysis Notes.
containeranalysis.notes.get
containeranalysis.notes.list
resourcemanager.projects.get
resourcemanager.projects.list
Container Analysis Occurrences Editor
(roles/)
Can edit Container Analysis Occurrences.
containeranalysis.
containeranalysis.
containeranalysis.
containeranalysis.
containeranalysis.
resourcemanager.projects.get
resourcemanager.projects.list
Container Analysis Occurrences Viewer
(roles/)
Can view Container Analysis Occurrences.
containeranalysis.
containeranalysis.
resourcemanager.projects.get
resourcemanager.projects.list