[[["易于理解","easyToUnderstand","thumb-up"],["解决了我的问题","solvedMyProblem","thumb-up"],["其他","otherUp","thumb-up"]],[["很难理解","hardToUnderstand","thumb-down"],["信息或示例代码不正确","incorrectInformationOrSampleCode","thumb-down"],["没有我需要的信息/示例","missingTheInformationSamplesINeed","thumb-down"],["翻译问题","translationIssue","thumb-down"],["其他","otherDown","thumb-down"]],["最后更新时间 (UTC):2025-03-23。"],[],[],null,["# IAM permissions for Cloud Storage\n\nThe following tables list the [Identity and Access Management (IAM)](/storage/docs/access-control/iam)\npermissions that are associated with Cloud Storage. IAM\npermissions are [grouped into roles](/storage/docs/access-control/iam-roles), and you\n[assign roles to users and groups](/storage/docs/access-control/using-iam-permissions).\n\nBucket permissions\n------------------\n\nObject permissions\n------------------\n\n| **Note:** The `storage.objects.getIamPolicy` and `storage.objects.setIamPolicy` permissions don't apply to buckets with [uniform bucket-level access](/storage/docs/uniform-bucket-level-access) enabled.\n| **Note:** In order to replace existing objects, both `storage.objects.create` and `storage.objects.delete` permissions are required.\n\nFolder permissions\n------------------\n\n| **Note:** In order to rename folders, `storage.folders.rename` is required on the source bucket and `storage.folders.create` is required on the destination bucket.\n\nManaged folder permissions\n--------------------------\n\nAnywhere Cache permissions\n--------------------------\n\nStorage Intelligence permissions\n--------------------------------\n\nStorage Insights inventory report permissions\n---------------------------------------------\n\nStorage Insights dataset permissions\n------------------------------------\n\nStorage batch operations permissions\n------------------------------------\n\nLong-running operations permissions\n-----------------------------------\n\nHMAC key permissions\n--------------------\n\n| **Note:** HMAC key permissions apply at the project level only.\n\nMultipart upload permissions\n----------------------------\n\n| **Note:** In order to create or upload parts, you must have both the `storage.objects.create` and `storage.multipartUploads.create` permissions.\n\nWhat's next\n-----------\n\n- Learn about which IAM permissions are contained in each\n [Cloud Storage IAM role](/storage/docs/access-control/iam-roles).\n\n- [Assign IAM roles](/storage/docs/access-control/using-iam-permissions) at the project and bucket level.\n\n- See available [IAM references for Cloud Storage](/storage/docs/access-control/iam-reference),\n such as which IAM permissions allow users to perform actions\n with various tools and APIs.\n\n- For a list of other Google Cloud permissions, see\n [Support Level for Permissions in Custom Roles](/iam/docs/custom-roles-permissions-support)."]]