Mit Sammlungen den Überblick behalten
Sie können Inhalte basierend auf Ihren Einstellungen speichern und kategorisieren.
IAM-Rollen und -Berechtigungen für Integration Connectors
Vordefinierte Rollen ermöglichen einen genau definierten Zugriff auf bestimmte Google Cloud-Ressourcen.
Vordefinierte Rollen werden von Google erstellt und verwaltet. Google aktualisiert seine Berechtigungen bei Bedarf automatisch, z. B. wenn Google Cloud neue Funktionen oder Dienste hinzufügt.
In der folgenden Tabelle sind alle vordefinierten IAM-Rollen für Integration Connectors aufgeführt:
Role
Permissions
Connector Admin
(roles/connectors.admin)
Full access to all resources of Connectors Service.
Custom Connector is a global resource which creates custom connector within the given target project. This role grants Admin access to Custom Connector resources
connectors.customConnectorVersions.*
connectors.customConnectorVersions.create
connectors.customConnectorVersions.delete
connectors.customConnectorVersions.get
connectors.customConnectorVersions.getIamPolicy
connectors.customConnectorVersions.list
connectors.customConnectorVersions.setIamPolicy
connectors.customConnectorVersions.update
connectors.customConnectors.*
connectors.customConnectors.create
connectors.customConnectors.delete
connectors.customConnectors.get
connectors.customConnectors.getIamPolicy
connectors.customConnectors.list
connectors.customConnectors.setIamPolicy
connectors.customConnectors.update
connectors.locations.*
connectors.locations.get
connectors.locations.list
Custom Connector Viewer
(roles/connectors.customConnectorViewer)
Custom Connector is a global resource which creates custom connector within the given target project. This role grants Read-only access to Custom Connector & Custom Connector Version resources.
connectors.customConnectorVersions.get
connectors.customConnectorVersions.getIamPolicy
connectors.customConnectorVersions.list
connectors.customConnectors.get
connectors.customConnectors.getIamPolicy
connectors.customConnectors.list
connectors.locations.*
connectors.locations.get
connectors.locations.list
Connectors Endpoint Attachment Admin
(roles/connectors.endpointAttachmentAdmin)
Endpoint Attachment is a regional resource which creates PSC connection endpoint for the given PSC Service Attachment. This role grants Admin access to Connectors Endpoint Attachment resources.
connectors.endpointAttachments.*
connectors.endpointAttachments.create
connectors.endpointAttachments.delete
connectors.endpointAttachments.get
connectors.endpointAttachments.getIamPolicy
connectors.endpointAttachments.list
connectors.endpointAttachments.setIamPolicy
connectors.endpointAttachments.update
connectors.locations.*
connectors.locations.get
connectors.locations.list
Connectors Endpoint Attachment Viewer
(roles/connectors.endpointAttachmentViewer)
Endpoint Attachment is a regional resource which creates PSC connection endpoint for the given PSC Service Attachment. This role grants Read-only access to Connectors Endpoint Attachment resources
connectors.endpointAttachments.get
connectors.endpointAttachments.getIamPolicy
connectors.endpointAttachments.list
connectors.locations.*
connectors.locations.get
connectors.locations.list
Connectors Event Subscriptions Admin
(roles/connectors.eventSubscriptionAdmin)
Event Subscription is a regional resource which creates subscriptions on events for a given connection within the given target project. This role grants Admin access to Connectors Subscription resources
connectors.eventSubscriptions.*
connectors.eventSubscriptions.create
connectors.eventSubscriptions.delete
connectors.eventSubscriptions.get
connectors.eventSubscriptions.list
connectors.eventSubscriptions.update
Connectors Event Subscriptions Viewer
(roles/connectors.eventSubscriptionViewer)
Event Subscription is a regional resource which creates subscriptions on events for a given connection within the given target project. This role grants Read-only access to Event Subscription resources.
connectors.eventSubscriptions.get
connectors.eventSubscriptions.list
Connector Invoker
(roles/connectors.invoker)
Full Access to invoke all operations on Connections.
connectors.actions.*
connectors.actions.execute
connectors.actions.list
connectors.connections.executeSqlQuery
connectors.entities.*
connectors.entities.create
connectors.entities.delete
connectors.entities.deleteEntitiesWithConditions
connectors.entities.get
connectors.entities.list
connectors.entities.update
connectors.entities.updateEntitiesWithConditions
connectors.entityTypes.list
Connector Event Listener
(roles/connectors.listener)
Full Access to listen events by connections.
connectors.connections.listenEvent
Connectors Managed Zone Admin
(roles/connectors.managedZoneAdmin)
Managed Zone is a global resource which creates Cloud DNS Peering Zone with the given target project. This role grants Admin access to Connectors Managed Zone resources
connectors.locations.*
connectors.locations.get
connectors.locations.list
connectors.managedZones.*
connectors.managedZones.create
connectors.managedZones.delete
connectors.managedZones.get
connectors.managedZones.getIamPolicy
connectors.managedZones.list
connectors.managedZones.setIamPolicy
connectors.managedZones.update
Connectors Managed Zone Viewer
(roles/connectors.managedZoneViewer)
Managed Zone is a global resource which creates Cloud DNS Peering Zone with the given target project. This role grants Read-only access to Connectors Managed Zone resources.
connectors.locations.*
connectors.locations.get
connectors.locations.list
connectors.managedZones.get
connectors.managedZones.getIamPolicy
connectors.managedZones.list
Connectors Platform Service Agent
(roles/connectors.serviceAgent)
Grants Connectors Platform service account to manage customer resources
[[["Leicht verständlich","easyToUnderstand","thumb-up"],["Mein Problem wurde gelöst","solvedMyProblem","thumb-up"],["Sonstiges","otherUp","thumb-up"]],[["Schwer verständlich","hardToUnderstand","thumb-down"],["Informationen oder Beispielcode falsch","incorrectInformationOrSampleCode","thumb-down"],["Benötigte Informationen/Beispiele nicht gefunden","missingTheInformationSamplesINeed","thumb-down"],["Problem mit der Übersetzung","translationIssue","thumb-down"],["Sonstiges","otherDown","thumb-down"]],["Zuletzt aktualisiert: 2025-08-29 (UTC)."],[[["\u003cp\u003ePredefined IAM roles for Integration Connectors offer granular control over access to Google Cloud resources, and are created and maintained by Google.\u003c/p\u003e\n"],["\u003cp\u003eThe Connector Admin role (\u003ccode\u003eroles/connectors.admin\u003c/code\u003e) grants full access to all resources within the Connectors Service.\u003c/p\u003e\n"],["\u003cp\u003eCustom Connector roles allow for admin or read-only access specifically to Custom Connector and Custom Connector Version resources within a project.\u003c/p\u003e\n"],["\u003cp\u003eThere are dedicated roles for managing endpoint attachments, event subscriptions, and managed zones, each providing either admin or viewer permissions to their respective resource types.\u003c/p\u003e\n"],["\u003cp\u003eRoles such as the Connector Invoker and Connector Event Listener provide permissions for invoking actions on connections and listening to events, respectively.\u003c/p\u003e\n"]]],[],null,["# IAM roles and permissions for Integration Connectors\n====================================================\n\n\nPredefined roles give granular access to specific Google Cloud resources.\nThese roles are created and maintained by Google. Google automatically updates their permissions\nas necessary, such as when Google Cloud adds new features or services.\nThe following table lists all the predefined IAM roles for Integration Connectors:\n\n\u003cbr /\u003e\n\n\nFor more information about predefined roles, see [Roles and permissions](/iam/docs/roles-overview). For help choosing the most appropriate predefined roles, see [Choose predefined roles](/iam/docs/choose-predefined-roles)."]]