This page lists the IAM roles and permissions for Binary Authorization. To search through all roles and permissions, see the role and permission index.
Binary Authorization roles
| Role | Permissions | 
|---|---|
| Binary Authorization Attestor Admin( Administrator of Binary Authorization Attestors | 
       
 
 
 | 
| Binary Authorization Attestor Editor( Editor of Binary Authorization Attestors | 
 
 
 
 
 
 
 
 | 
| Binary Authorization Attestor Image Verifier( Caller of Binary Authorization Attestors VerifyImageAttested | 
 
 
 
 
 | 
| Binary Authorization Attestor Viewer( Viewer of Binary Authorization Attestors | 
 
 
 
 | 
| Binary Authorization Policy Administrator( Administrator of Binary Authorization Policy | 
       
 
       
 
       
 
 
 | 
| Binary Authorization Policy Editor( Editor of Binary Authorization Policy | 
 
 
       
 
 
 
 
 
 | 
| Binary Authorization Policy Evaluator( Evaluator of Binary Authorization Policy | 
 
 
 
 
 
 
 | 
| Binary Authorization Policy Viewer( Viewer of Binary Authorization Policy | 
 
 
 
 
 
 | 
| Binary Authorization Service Agent( Can read Notes and Occurrences from the Container Analysis Service to find and verify signatures. | 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 | 
Binary Authorization permissions
| Permission | Included in roles | 
|---|---|
| 
 | 
          Owner ( 
          Editor ( 
          Binary Authorization Attestor Admin ( 
          Binary Authorization Attestor Editor ( Service agent roles 
 | 
| 
 | 
          Owner ( 
          Editor ( 
          Binary Authorization Attestor Admin ( 
          Binary Authorization Attestor Editor ( Service agent roles 
 | 
| 
 | 
          Owner ( 
          Editor ( 
          Viewer ( 
          Binary Authorization Attestor Admin ( 
          Binary Authorization Attestor Editor ( 
          Binary Authorization Attestor Image Verifier ( 
          Binary Authorization Attestor Viewer ( 
          Support User ( Service agent roles 
 | 
| 
 | 
          Owner ( 
          Editor ( 
          Viewer ( 
          Binary Authorization Attestor Admin ( 
          Security Admin ( 
          Security Auditor ( 
          Security Reviewer ( 
          Support User ( | 
| 
 | 
          Owner ( 
          Editor ( 
          Viewer ( 
          Binary Authorization Attestor Admin ( 
          Binary Authorization Attestor Editor ( 
          Binary Authorization Attestor Image Verifier ( 
          Binary Authorization Attestor Viewer ( 
          Security Admin ( 
          Security Auditor ( 
          Security Reviewer ( 
          Support User ( Service agent roles 
 | 
| 
 | 
          Owner ( 
          Binary Authorization Attestor Admin ( 
          Security Admin ( | 
| 
 | 
          Owner ( 
          Editor ( 
          Binary Authorization Attestor Admin ( 
          Binary Authorization Attestor Editor ( Service agent roles 
 | 
| 
 | 
          Owner ( 
          Editor ( 
          Viewer ( 
          Binary Authorization Attestor Admin ( 
          Binary Authorization Attestor Editor ( 
          Binary Authorization Attestor Image Verifier ( 
          Support User ( Service agent roles 
 | 
| 
 | 
          Owner ( 
          Editor ( 
          Viewer ( 
          Binary Authorization Policy Administrator ( 
          Binary Authorization Policy Editor ( 
          Binary Authorization Policy Viewer ( 
          Dev Ops ( 
          Support User ( | 
| 
 | 
          Owner ( 
          Editor ( 
          Viewer ( 
          Binary Authorization Policy Administrator ( 
          Dev Ops ( 
          Security Admin ( 
          Security Auditor ( 
          Security Reviewer ( 
          Support User ( | 
| 
 | 
          Owner ( 
          Binary Authorization Policy Administrator ( 
          Dev Ops ( 
          Security Admin ( | 
| 
 | 
          Owner ( 
          Editor ( 
          Binary Authorization Policy Administrator ( 
          Binary Authorization Policy Editor ( 
          Dev Ops ( | 
| 
 | 
          Owner ( 
          Editor ( 
          Binary Authorization Policy Administrator ( 
          Binary Authorization Policy Editor ( 
          Dev Ops ( | 
| 
 | 
          Owner ( 
          Editor ( 
          Binary Authorization Policy Administrator ( 
          Binary Authorization Policy Editor ( 
          Dev Ops ( | 
| 
 | 
          Owner ( 
          Editor ( 
          Viewer ( 
          Binary Authorization Policy Administrator ( 
          Binary Authorization Policy Editor ( 
          Binary Authorization Policy Evaluator ( 
          Dev Ops ( 
          Support User ( 
          Cloud Run Service Agent ( Service agent roles 
 | 
| 
 | 
          Owner ( 
          Editor ( 
          Viewer ( 
          Binary Authorization Policy Administrator ( 
          Binary Authorization Policy Editor ( 
          Binary Authorization Policy Evaluator ( 
          Binary Authorization Policy Viewer ( 
          Dev Ops ( 
          Support User ( Service agent roles 
 | 
| 
 | 
          Owner ( 
          Editor ( 
          Viewer ( 
          Binary Authorization Policy Administrator ( 
          Binary Authorization Policy Editor ( 
          Binary Authorization Policy Evaluator ( 
          Binary Authorization Policy Viewer ( 
          Dev Ops ( 
          Security Admin ( 
          Security Auditor ( 
          Security Reviewer ( 
          Support User ( Service agent roles 
 | 
| 
 | 
          Owner ( 
          Editor ( 
          Binary Authorization Policy Administrator ( 
          Binary Authorization Policy Editor ( 
          Dev Ops ( | 
| 
 | 
          Owner ( 
          Editor ( 
          Viewer ( 
          Binary Authorization Policy Administrator ( 
          Binary Authorization Policy Editor ( 
          Binary Authorization Policy Evaluator ( 
          Dev Ops ( 
          Support User ( 
          Cloud Run Service Agent ( Service agent roles 
 | 
| 
 | 
          Owner ( 
          Editor ( 
          Viewer ( 
          Binary Authorization Policy Administrator ( 
          Binary Authorization Policy Editor ( 
          Binary Authorization Policy Evaluator ( 
          Binary Authorization Policy Viewer ( 
          Dev Ops ( 
          Support User ( Service agent roles 
 | 
| 
 | 
          Owner ( 
          Editor ( 
          Viewer ( 
          Binary Authorization Policy Administrator ( 
          Dev Ops ( 
          Security Admin ( 
          Security Auditor ( 
          Security Reviewer ( 
          Support User ( | 
| 
 | 
          Owner ( 
          Binary Authorization Policy Administrator ( 
          Dev Ops ( 
          Security Admin ( | 
| 
 | 
          Owner ( 
          Editor ( 
          Binary Authorization Policy Administrator ( 
          Binary Authorization Policy Editor ( 
          Dev Ops ( |