Permissões e papéis do IAM

Esta página se aplica à Apigee e à Apigee híbrida.

É possível visualizar e conceder papéis usando o painel de permissões na página IAM e administrador > IAM do projeto do Google Cloud.

Acessar IAM e administrador

A tabela a seguir lista os papéis e as permissões correspondentes necessárias para criar e gerenciar recursos do hub de APIs.

Nome do papel do IAM Descrição Permissões necessárias
Leitor do hub da API do Cloud Esse papel pode visualizar todos os recursos do hub de API
  • apihub.googleapis.com/locations.searchResources
  • apihub.googleapis.com/apis.list
  • apihub.googleapis.com/apis.get
  • apihub.googleapis.com/specs.list
  • apihub.googleapis.com/specs.get
  • apihub.googleapis.com/apiOperations.list
  • apihub.googleapis.com/apiOperations.get
  • apihub.googleapis.com/versions.list
  • apihub.googleapis.com/versions.get
  • apihub.googleapis.com/deployments.list
  • apihub.googleapis.com/deployments.get
  • apihub.googleapis.com/attributes.list
  • apihub.googleapis.com/attributes.get
  • apihub.googleapis.com/definitions.list
  • apihub.googleapis.com/definitions.get
  • apihub.googleapis.com/definitions.get
  • apihub.googleapis.com/externalApis.get
  • apihub.googleapis.com/externalApis.list
  • apihub.googleapis.com/dependencies.get
  • apihub.googleapis.com/dependencies.list
  • apihub.googleapis.com/plugins.get
  • apihub.googleapis.com/plugins.list
  • apihub.googleapis.com/runTimeProjectAttachments.get
  • apihub.googleapis.com/runTimeProjectAttachments.list
  • apihub.googleapis.com/hostProjectRegistrations.list
  • apihub.googleapis.com/hostProjectRegistrations.get
  • apihub.googleapis.com/apiHubInstances.get
  • apihub.googleapis.com/apiHubInstances.list
  • apihub.googleapis.com/styleGuides.get
  • cloudresourcemanager.googleapis.com/projects.get
  • cloudresourcemanager.googleapis.com/projects.list
Administrador de plug-ins do hub da API do Cloud Todas as permissões relacionadas a plug-ins
  • cloudresourcemanager.googleapis.com/projects.get
  • cloudresourcemanager.googleapis.com/projects.list
  • apihub.googleapis.com/plugins.get
  • apihub.googleapis.com/plugins.list
  • apihub.googleapis.com/plugins.enable
  • apihub.googleapis.com/plugins.disable
  • apihub.googleapis.com/specs.lint
  • apihub.googleapis.com/styleGuides.get
  • apihub.googleapis.com/styleGuides.update
Editor do hub de APIs do Cloud Papel de editor para recursos Além das permissões do papel Cloud API hub viewer, ele tem as seguintes permissões:
  • apihub.googleapis.com/apis.create
  • apihub.googleapis.com/apis.update
  • apihub.googleapis.com/apis.delete
  • apihub.googleapis.com/versions.create
  • apihub.googleapis.com/versions.update
  • apihub.googleapis.com/versions.delete
  • apihub.googleapis.com/specs.create
  • apihub.googleapis.com/specs.update
  • apihub.googleapis.com/specs.delete
  • apihub.googleapis.com/deployments.create
  • apihub.googleapis.com/deployments.update
  • apihub.googleapis.com/deployments.delete
  • apihub.googleapis.com/specs.lint
Administrador de provisionamento do hub da API do Cloud Todas as permissões relacionadas a provisionamento
  • cloudresourcemanager.googleapis.com/projects.get
  • cloudresourcemanager.googleapis.com/projects.list
  • apihub.googleapis.com/hostProjectRegistrations.list
  • apihub.googleapis.com/hostProjectRegistrations.get
  • apihub.googleapis.com/hostProjectRegistrations.create
  • apihub.googleapis.com/hostProjectRegistrations.register
  • apihub.googleapis.com/hostProjectRegistrations.delete
  • apihub.googleapis.com/runTimeProjectAttachments.list
  • apihub.googleapis.com/runTimeProjectAttachments.get
  • apihub.googleapis.com/runTimeProjectAttachments.lookup
  • apihub.googleapis.com/runTimeProjectAttachments.create
  • apihub.googleapis.com/runTimeProjectAttachments.attach
  • apihub.googleapis.com/runTimeProjectAttachments.delete
  • apihub.googleapis.com/apiHubInstances.get
  • apihub.googleapis.com/apiHubInstances.list
  • apihub.googleapis.com/apiHubInstances.create
  • apihub.googleapis.com/apiHubInstances.delete
Administrador de atributos do hub da API do Cloud Todas as permissões relacionadas a atributos
  • cloudresourcemanager.googleapis.com/projects.get
  • cloudresourcemanager.googleapis.com/projects.list
  • apihub.googleapis.com/attributes.create
  • apihub.googleapis.com/attributes.update
  • apihub.googleapis.com/attributes.delete
  • apihub.googleapis.com/attributes.list
  • apihub.googleapis.com/attributes.get
Administrador do hub de APIs do Cloud Todas as permissões

Esse papel tem todas as permissões dos seguintes papéis:

  • Editor do hub de APIs do Cloud
  • Administrador de atributos do hub da API do Cloud
  • Administrador de provisionamento do hub da API do Cloud
  • Administrador de plug-ins do hub da API do Cloud