Google Distributed Cloud (GDC) 空气隔离设备提供 Identity and Access Management (IAM),可让您授予对特定 GDC 空气隔离设备资源的细化访问权限,并防止对其他资源进行不必要的访问。IAM 遵循最小权限安全原则,并使用 IAM 角色和权限来控制哪些用户可以访问指定资源。
角色是指一组与资源上的特定操作相关联的特定权限,可分配给用户、用户群组或服务账号等各个正文。因此,您必须拥有适当的 IAM 角色和权限,才能在 GDC 空气隔离设备上使用 Vertex AI 服务。
[[["易于理解","easyToUnderstand","thumb-up"],["解决了我的问题","solvedMyProblem","thumb-up"],["其他","otherUp","thumb-up"]],[["很难理解","hardToUnderstand","thumb-down"],["信息或示例代码不正确","incorrectInformationOrSampleCode","thumb-down"],["没有我需要的信息/示例","missingTheInformationSamplesINeed","thumb-down"],["翻译问题","translationIssue","thumb-down"],["其他","otherDown","thumb-down"]],["最后更新时间 (UTC):2025-09-04。"],[],[],null,["# Prepare IAM permissions\n\nThis page describes all the roles and their respective permissions for using\nVertex AI services.\n\nGoogle Distributed Cloud (GDC) air-gapped appliance offers Identity and Access Management (IAM) for\ngranular access to specific GDC air-gapped appliance resources and prevents\nunwanted access to other resources. IAM operates on the security\nprinciple of least privilege and controls who can access given resources using\nIAM roles and permissions.\n\nA role is a collection of specific permissions mapped to certain actions on\nresources and assigned to individual subjects, such as users, groups of users,\nor service accounts. Therefore, you must have the proper IAM\nroles and permissions to use Vertex AI services on\nGDC air-gapped appliance.\n\nTo grant permissions or receive role access to resources, see\n[Grant and revoke access](/distributed-cloud/hosted/docs/latest/appliance/platform/pa-user/iam/set-up-role-bindings).\n| **Important:** If you can't access or use a Vertex AI service, contact your administrator to grant you the necessary roles. Request the appropriate permissions from your Project IAM Admin for a given project. If you require permissions at the organization level, ask your Organization IAM Admin instead.\n\nPredefined roles at the organization level\n------------------------------------------\n\nRequest the appropriate permissions from your Organization IAM Admin to set up\nVertex AI in an organization and manage the lifecycle of a\nproject that uses AI services.\n\nThe following table provides details about the permissions assigned to each\npredefined role:\n\nPredefined roles at the project level\n-------------------------------------\n\nRequest the appropriate permissions from your Project IAM Admin to use\nVertex AI services in a project. All Vertex AI\nroles must bind to the project namespace where you are using the service.\n\nThe following table provides details about the permissions assigned to each\npredefined role:"]]