Overview

This table contains the required Google Cloud Platform (GCP) permissions to create a custom GCP role tailored for usage with Palette. When creating a custom role, ensure you include all the permissions listed below to prevent Palette from having issues when deploying a host cluster.

PermissionsDescription
compute.backendServices.createCreate backend services
compute.backendServices.deleteDelete backend services
compute.backendServices.getGet backend service information
compute.backendServices.listList backend services
compute.backendServices.updateUpdate backend services
compute.backendServices.useUse backend services
compute.disks.createCreate persistent disks
compute.firewalls.createCreate firewall rules
compute.firewalls.deleteDelete firewall rules
compute.firewalls.getGet firewall rule information
compute.firewalls.listList firewall rules
compute.globalAddresses.createCreate global addresses
compute.globalAddresses.deleteDelete global addresses
compute.globalAddresses.getGet global address information
compute.globalAddresses.listList global addresses
compute.globalAddresses.useUse global addresses
compute.globalForwardingRules.createCreate global forwarding rules
compute.globalForwardingRules.deleteDelete global forwarding rules
compute.globalForwardingRules.getGet global forwarding rule information
compute.globalForwardingRules.listList global forwarding rules
compute.healthChecks.createCreate health checks
compute.healthChecks.deleteDelete health checks
compute.healthChecks.getGet health check information
compute.healthChecks.listList health checks
compute.healthChecks.useReadOnlyUse health checks in read-only mode
compute.instanceGroups.createCreate instance groups
compute.instanceGroups.deleteDelete instance groups
compute.instanceGroups.getGet instance group information
compute.instanceGroups.listList instance groups
compute.instanceGroups.updateUpdate instance groups
compute.instanceGroups.useUse instance groups
compute.instances.createCreate instances
compute.instances.deleteDelete instances
compute.instances.getGet instance information
compute.instances.listList instances
compute.instances.setLabelsSet labels on instances
compute.instances.setMetadataSet metadata on instances
compute.instances.setServiceAccountSet service account on instances
compute.instances.setTagsSet tags on instances
compute.instances.useUse instances
compute.networks.createCreate networks
compute.networks.deleteDelete networks
compute.networks.getGet network information
compute.networks.listList networks
compute.networks.updatePolicyUpdate network policies
compute.regions.getGet region information
compute.regions.listList regions
compute.routers.createCreate routers
compute.routers.deleteDelete routers
compute.routers.getGet router information
compute.routes.deleteDelete routes
compute.routes.getGet route information
compute.routes.listList routes