Stay organized with collections
Save and categorize content based on your preferences.
This page explains how to prepare your Identity and Access Management (IAM) permissions to effectively use Cloud DNS within GDC.
GDC offers IAM for granular access to specific GDC resources and prevents
unwanted access to other resources. IAM operates on the security principle of
least privilege and controls who can access given resources using IAM roles and
permissions.
A role is a collection of specific permissions mapped to certain actions on
resources and assigned to individual subjects, such as users, groups of users,
or service accounts. Therefore, you must have the proper IAM roles and
permissions to use managed DNS services in GDC.
The intended audience for this page is platform administrators and application
operators responsible for network administration and managing DNS for their
organization within GDC.
Get IAM permissions
To create DNS zones and records, you must have the necessary identity and access
roles. Ask your Project IAM Admin to grant you the roles:
Managed DNS Project Viewer (managed-dns-project-viewer) role: creates and
updates DNS zones and records.
Managed DNS Project Admin (managed-dns-project-admin) role: views existing
DNS zones and records.
[[["Easy to understand","easyToUnderstand","thumb-up"],["Solved my problem","solvedMyProblem","thumb-up"],["Other","otherUp","thumb-up"]],[["Hard to understand","hardToUnderstand","thumb-down"],["Incorrect information or sample code","incorrectInformationOrSampleCode","thumb-down"],["Missing the information/samples I need","missingTheInformationSamplesINeed","thumb-down"],["Other","otherDown","thumb-down"]],["Last updated 2025-09-03 UTC."],[],[],null,["# Prepare IAM permissions\n\n| **Preview:** This is a Preview feature that is available as-is and is not recommended for production environments. Google provides no Service-Level agreements (SLA) or technical support commitments for Preview features. For more information, see GDC's [feature stages](/distributed-cloud/hosted/docs/latest/gdch/resources/feature-stages).\n\nThis page explains how to prepare your Identity and Access Management (IAM) permissions to effectively use Cloud DNS within GDC.\n\nGDC offers IAM for granular access to specific GDC resources and prevents\nunwanted access to other resources. IAM operates on the security principle of\nleast privilege and controls who can access given resources using IAM roles and\npermissions.\n\nA role is a collection of specific permissions mapped to certain actions on\nresources and assigned to individual subjects, such as users, groups of users,\nor service accounts. Therefore, you must have the proper IAM roles and\npermissions to use managed DNS services in GDC.\n\nThe intended audience for this page is platform administrators and application\noperators responsible for network administration and managing DNS for their\norganization within GDC.\n\nGet IAM permissions\n-------------------\n\nTo create DNS zones and records, you must have the necessary identity and access\nroles. Ask your Project IAM Admin to grant you the roles:\n\n- Managed DNS Project Viewer (`managed-dns-project-viewer`) role: creates and updates DNS zones and records.\n- Managed DNS Project Admin (`managed-dns-project-admin`) role: views existing DNS zones and records.\n\nFor more information on these roles, see\n[Role definitions](/distributed-cloud/hosted/docs/latest/gdch/application/ao-user/iam/role-definitions).\n\nWhat's next\n-----------\n\n- [Create DNS zones](/distributed-cloud/hosted/docs/latest/gdch/platform/pa-user/dns/create-dns-zone)\n- [Create DNS records](/distributed-cloud/hosted/docs/latest/gdch/platform/pa-user/dns/create-dns-records)"]]