Autorisations compatibles avec les règles de refus

Vous pouvez utiliser certaines autorisations IAM (Identity and Access Management) dans les stratégies de refus, mais pas toutes.

Les règles de refus nécessitent le format d'autorisation IAM v2, qui est SERVICE_FQDN/RESOURCE.ACTION. La valeur de SERVICE_FQDN correspond généralement à la valeur de SERVICE_ID de l'API v1, suivie de .googleapis.com. Par exemple, l'autorisation permettant de supprimer un rôle est iam.googleapis.com/roles.delete. Les exceptions sont documentées sur cette page.

Autorisations compatibles

Le tableau suivant répertorie les autorisations pouvant être utilisées dans les règles de refus.

Saisissez le nom du service ou de l'autorisation que vous souhaitez trouver dans la zone de recherche :

Service Autorisations compatibles
Clés API

apikeys.googleapis.com/apiKeys.regenerate

apikeys.googleapis.com/apiKeys.revert

apikeys.googleapis.com/keys.create

apikeys.googleapis.com/keys.delete

apikeys.googleapis.com/keys.get

apikeys.googleapis.com/keys.getKeyString

apikeys.googleapis.com/keys.list

apikeys.googleapis.com/keys.lookup

apikeys.googleapis.com/keys.undelete

apikeys.googleapis.com/keys.update

BigQuery

bigquery.googleapis.com/bireservations.get

bigquery.googleapis.com/bireservations.update

bigquery.googleapis.com/capacityCommitments.create

bigquery.googleapis.com/capacityCommitments.delete

bigquery.googleapis.com/capacityCommitments.get

bigquery.googleapis.com/capacityCommitments.list

bigquery.googleapis.com/capacityCommitments.update

bigquery.googleapis.com/datasets.createTagBinding

bigquery.googleapis.com/datasets.delete

bigquery.googleapis.com/datasets.deleteTagBinding

bigquery.googleapis.com/datasets.setIamPolicy

bigquery.googleapis.com/jobs.delete

bigquery.googleapis.com/models.delete

bigquery.googleapis.com/reservationAssignments.create

bigquery.googleapis.com/reservationAssignments.delete

bigquery.googleapis.com/reservationAssignments.list

bigquery.googleapis.com/reservationAssignments.search

bigquery.googleapis.com/reservations.create

bigquery.googleapis.com/reservations.delete

bigquery.googleapis.com/reservations.get

bigquery.googleapis.com/reservations.list

bigquery.googleapis.com/reservations.update

bigquery.googleapis.com/routines.delete

bigquery.googleapis.com/rowAccessPolicies.create

bigquery.googleapis.com/rowAccessPolicies.delete

bigquery.googleapis.com/rowAccessPolicies.setIamPolicy

bigquery.googleapis.com/rowAccessPolicies.update

bigquery.googleapis.com/tables.deleteIndex

bigquery.googleapis.com/tables.deleteSnapshot

bigquery.googleapis.com/tables.setCategory

bigquery.googleapis.com/tables.setIamPolicy

Client Auth Config

clientauthconfig.googleapis.com/brands.create

clientauthconfig.googleapis.com/brands.delete

clientauthconfig.googleapis.com/brands.update

clientauthconfig.googleapis.com/clients.create

clientauthconfig.googleapis.com/clients.createSecret

clientauthconfig.googleapis.com/clients.delete

clientauthconfig.googleapis.com/clients.get

clientauthconfig.googleapis.com/clients.getWithSecret

clientauthconfig.googleapis.com/clients.listWithSecrets

clientauthconfig.googleapis.com/clients.undelete

clientauthconfig.googleapis.com/clients.update

Cloud Functions

cloudfunctions.googleapis.com/functions.create

cloudfunctions.googleapis.com/functions.delete

cloudfunctions.googleapis.com/functions.get

cloudfunctions.googleapis.com/functions.list

cloudfunctions.googleapis.com/functions.sourceCodeGet

cloudfunctions.googleapis.com/functions.sourceCodeSet

cloudfunctions.googleapis.com/functions.update

Resource Manager

cloudresourcemanager.googleapis.com/folders.create

cloudresourcemanager.googleapis.com/folders.delete

cloudresourcemanager.googleapis.com/folders.get

cloudresourcemanager.googleapis.com/folders.getIamPolicy

cloudresourcemanager.googleapis.com/folders.list

cloudresourcemanager.googleapis.com/folders.move

cloudresourcemanager.googleapis.com/folders.setIamPolicy

cloudresourcemanager.googleapis.com/folders.undelete

cloudresourcemanager.googleapis.com/folders.update

cloudresourcemanager.googleapis.com/organizations.get

cloudresourcemanager.googleapis.com/organizations.getIamPolicy

cloudresourcemanager.googleapis.com/organizations.setIamPolicy

cloudresourcemanager.googleapis.com/projects.create

cloudresourcemanager.googleapis.com/projects.createBillingAssignment

cloudresourcemanager.googleapis.com/projects.delete

cloudresourcemanager.googleapis.com/projects.deleteBillingAssignment

cloudresourcemanager.googleapis.com/projects.get

cloudresourcemanager.googleapis.com/projects.getIamPolicy

cloudresourcemanager.googleapis.com/projects.move

cloudresourcemanager.googleapis.com/projects.setIamPolicy

cloudresourcemanager.googleapis.com/projects.undelete

cloudresourcemanager.googleapis.com/projects.update

cloudresourcemanager.googleapis.com/projects.updateLiens

Compute Engine

compute.googleapis.com/acceleratorTypes.get

compute.googleapis.com/acceleratorTypes.list

compute.googleapis.com/addresses.create

compute.googleapis.com/addresses.createInternal

compute.googleapis.com/addresses.delete

compute.googleapis.com/addresses.deleteInternal

compute.googleapis.com/addresses.get

compute.googleapis.com/addresses.list

compute.googleapis.com/addresses.setLabels

compute.googleapis.com/addresses.use

compute.googleapis.com/addresses.useInternal

compute.googleapis.com/autoscalers.create

compute.googleapis.com/autoscalers.delete

compute.googleapis.com/autoscalers.get

compute.googleapis.com/autoscalers.list

compute.googleapis.com/autoscalers.update

compute.googleapis.com/backendBuckets.addSignedUrlKey

compute.googleapis.com/backendBuckets.create

compute.googleapis.com/backendBuckets.delete

compute.googleapis.com/backendBuckets.deleteSignedUrlKey

compute.googleapis.com/backendBuckets.get

compute.googleapis.com/backendBuckets.getIamPolicy

compute.googleapis.com/backendBuckets.list

compute.googleapis.com/backendBuckets.setIamPolicy

compute.googleapis.com/backendBuckets.setSecurityPolicy

compute.googleapis.com/backendBuckets.update

compute.googleapis.com/backendBuckets.use

compute.googleapis.com/backendServices.addSignedUrlKey

compute.googleapis.com/backendServices.create

compute.googleapis.com/backendServices.delete

compute.googleapis.com/backendServices.deleteSignedUrlKey

compute.googleapis.com/backendServices.get

compute.googleapis.com/backendServices.getIamPolicy

compute.googleapis.com/backendServices.list

compute.googleapis.com/backendServices.setIamPolicy

compute.googleapis.com/backendServices.setSecurityPolicy

compute.googleapis.com/backendServices.update

compute.googleapis.com/backendServices.use

compute.googleapis.com/commitments.create

compute.googleapis.com/commitments.get

compute.googleapis.com/commitments.list

compute.googleapis.com/commitments.update

compute.googleapis.com/commitments.updateReservations

compute.googleapis.com/diskTypes.get

compute.googleapis.com/diskTypes.list

compute.googleapis.com/disks.addResourcePolicies

compute.googleapis.com/disks.create

compute.googleapis.com/disks.createSnapshot

compute.googleapis.com/disks.createTagBinding

compute.googleapis.com/disks.delete

compute.googleapis.com/disks.deleteTagBinding

compute.googleapis.com/disks.get

compute.googleapis.com/disks.getIamPolicy

compute.googleapis.com/disks.list

compute.googleapis.com/disks.listEffectiveTags

compute.googleapis.com/disks.listTagBindings

compute.googleapis.com/disks.removeResourcePolicies

compute.googleapis.com/disks.resize

compute.googleapis.com/disks.setIamPolicy

compute.googleapis.com/disks.setLabels

compute.googleapis.com/disks.startAsyncReplication

compute.googleapis.com/disks.stopAsyncReplication

compute.googleapis.com/disks.stopGroupAsyncReplication

compute.googleapis.com/disks.update

compute.googleapis.com/disks.use

compute.googleapis.com/disks.useReadOnly

compute.googleapis.com/externalVpnGateways.create

compute.googleapis.com/externalVpnGateways.delete

compute.googleapis.com/externalVpnGateways.get

compute.googleapis.com/externalVpnGateways.list

compute.googleapis.com/externalVpnGateways.setLabels

compute.googleapis.com/externalVpnGateways.use

compute.googleapis.com/firewallPolicies.cloneRules

compute.googleapis.com/firewallPolicies.create

compute.googleapis.com/firewallPolicies.delete

compute.googleapis.com/firewallPolicies.get

compute.googleapis.com/firewallPolicies.getIamPolicy

compute.googleapis.com/firewallPolicies.list

compute.googleapis.com/firewallPolicies.setIamPolicy

compute.googleapis.com/firewallPolicies.update

compute.googleapis.com/firewallPolicies.use

compute.googleapis.com/firewalls.create

compute.googleapis.com/firewalls.delete

compute.googleapis.com/firewalls.get

compute.googleapis.com/firewalls.list

compute.googleapis.com/firewalls.update

compute.googleapis.com/forwardingRules.create

compute.googleapis.com/forwardingRules.delete

compute.googleapis.com/forwardingRules.get

compute.googleapis.com/forwardingRules.list

compute.googleapis.com/forwardingRules.pscCreate

compute.googleapis.com/forwardingRules.pscDelete

compute.googleapis.com/forwardingRules.pscSetLabels

compute.googleapis.com/forwardingRules.pscUpdate

compute.googleapis.com/forwardingRules.setLabels

compute.googleapis.com/forwardingRules.setTarget

compute.googleapis.com/forwardingRules.update

compute.googleapis.com/forwardingRules.use

compute.googleapis.com/globalAddresses.create

compute.googleapis.com/globalAddresses.createInternal

compute.googleapis.com/globalAddresses.delete

compute.googleapis.com/globalAddresses.deleteInternal

compute.googleapis.com/globalAddresses.get

compute.googleapis.com/globalAddresses.list

compute.googleapis.com/globalAddresses.setLabels

compute.googleapis.com/globalAddresses.use

compute.googleapis.com/globalForwardingRules.create

compute.googleapis.com/globalForwardingRules.delete

compute.googleapis.com/globalForwardingRules.get

compute.googleapis.com/globalForwardingRules.list

compute.googleapis.com/globalForwardingRules.pscCreate

compute.googleapis.com/globalForwardingRules.pscDelete

compute.googleapis.com/globalForwardingRules.pscGet

compute.googleapis.com/globalForwardingRules.pscSetLabels

compute.googleapis.com/globalForwardingRules.pscUpdate

compute.googleapis.com/globalForwardingRules.setLabels

compute.googleapis.com/globalForwardingRules.setTarget

compute.googleapis.com/globalForwardingRules.update

compute.googleapis.com/globalNetworkEndpointGroups.attachNetworkEndpoints

compute.googleapis.com/globalNetworkEndpointGroups.create

compute.googleapis.com/globalNetworkEndpointGroups.delete

compute.googleapis.com/globalNetworkEndpointGroups.detachNetworkEndpoints

compute.googleapis.com/globalNetworkEndpointGroups.get

compute.googleapis.com/globalNetworkEndpointGroups.list

compute.googleapis.com/globalNetworkEndpointGroups.use

compute.googleapis.com/globalOperations.delete

compute.googleapis.com/globalOperations.get

compute.googleapis.com/globalOperations.getIamPolicy

compute.googleapis.com/globalOperations.list

compute.googleapis.com/globalOperations.setIamPolicy

compute.googleapis.com/globalPublicDelegatedPrefixes.create

compute.googleapis.com/globalPublicDelegatedPrefixes.delete

compute.googleapis.com/globalPublicDelegatedPrefixes.get

compute.googleapis.com/globalPublicDelegatedPrefixes.list

compute.googleapis.com/globalPublicDelegatedPrefixes.updatePolicy

compute.googleapis.com/healthChecks.create

compute.googleapis.com/healthChecks.delete

compute.googleapis.com/healthChecks.get

compute.googleapis.com/healthChecks.list

compute.googleapis.com/healthChecks.update

compute.googleapis.com/healthChecks.use

compute.googleapis.com/healthChecks.useReadOnly

compute.googleapis.com/httpHealthChecks.create

compute.googleapis.com/httpHealthChecks.delete

compute.googleapis.com/httpHealthChecks.get

compute.googleapis.com/httpHealthChecks.list

compute.googleapis.com/httpHealthChecks.update

compute.googleapis.com/httpHealthChecks.use

compute.googleapis.com/httpHealthChecks.useReadOnly

compute.googleapis.com/httpsHealthChecks.create

compute.googleapis.com/httpsHealthChecks.delete

compute.googleapis.com/httpsHealthChecks.get

compute.googleapis.com/httpsHealthChecks.list

compute.googleapis.com/httpsHealthChecks.update

compute.googleapis.com/httpsHealthChecks.use

compute.googleapis.com/httpsHealthChecks.useReadOnly

compute.googleapis.com/images.create

compute.googleapis.com/images.createTagBinding

compute.googleapis.com/images.delete

compute.googleapis.com/images.deleteTagBinding

compute.googleapis.com/images.deprecate

compute.googleapis.com/images.get

compute.googleapis.com/images.getIamPolicy

compute.googleapis.com/images.list

compute.googleapis.com/images.listEffectiveTags

compute.googleapis.com/images.listTagBindings

compute.googleapis.com/images.setIamPolicy

compute.googleapis.com/images.setLabels

compute.googleapis.com/images.update

compute.googleapis.com/images.useReadOnly

compute.googleapis.com/instanceGroupManagers.create

compute.googleapis.com/instanceGroupManagers.delete

compute.googleapis.com/instanceGroupManagers.get

compute.googleapis.com/instanceGroupManagers.list

compute.googleapis.com/instanceGroupManagers.update

compute.googleapis.com/instanceGroups.create

compute.googleapis.com/instanceGroups.delete

compute.googleapis.com/instanceGroups.get

compute.googleapis.com/instanceGroups.list

compute.googleapis.com/instanceGroups.update

compute.googleapis.com/instanceGroups.use

compute.googleapis.com/instanceTemplates.create

compute.googleapis.com/instanceTemplates.delete

compute.googleapis.com/instanceTemplates.get

compute.googleapis.com/instanceTemplates.getIamPolicy

compute.googleapis.com/instanceTemplates.list

compute.googleapis.com/instanceTemplates.setIamPolicy

compute.googleapis.com/instanceTemplates.useReadOnly

compute.googleapis.com/instances.addAccessConfig

compute.googleapis.com/instances.addResourcePolicies

compute.googleapis.com/instances.attachDisk

compute.googleapis.com/instances.create

compute.googleapis.com/instances.createTagBinding

compute.googleapis.com/instances.delete

compute.googleapis.com/instances.deleteAccessConfig

compute.googleapis.com/instances.deleteTagBinding

compute.googleapis.com/instances.detachDisk

compute.googleapis.com/instances.get

compute.googleapis.com/instances.getEffectiveFirewalls

compute.googleapis.com/instances.getGuestAttributes

compute.googleapis.com/instances.getIamPolicy

compute.googleapis.com/instances.getScreenshot

compute.googleapis.com/instances.getSerialPortOutput

compute.googleapis.com/instances.getShieldedInstanceIdentity

compute.googleapis.com/instances.getShieldedVmIdentity

compute.googleapis.com/instances.list

compute.googleapis.com/instances.listEffectiveTags

compute.googleapis.com/instances.listReferrers

compute.googleapis.com/instances.listTagBindings

compute.googleapis.com/instances.osAdminLogin

compute.googleapis.com/instances.osLogin

compute.googleapis.com/instances.removeResourcePolicies

compute.googleapis.com/instances.reset

compute.googleapis.com/instances.resume

compute.googleapis.com/instances.sendDiagnosticInterrupt

compute.googleapis.com/instances.setDeletionProtection

compute.googleapis.com/instances.setDiskAutoDelete

compute.googleapis.com/instances.setIamPolicy

compute.googleapis.com/instances.setLabels

compute.googleapis.com/instances.setMachineResources

compute.googleapis.com/instances.setMachineType

compute.googleapis.com/instances.setMetadata

compute.googleapis.com/instances.setMinCpuPlatform

compute.googleapis.com/instances.setName

compute.googleapis.com/instances.setScheduling

compute.googleapis.com/instances.setServiceAccount

compute.googleapis.com/instances.setShieldedInstanceIntegrityPolicy

compute.googleapis.com/instances.setShieldedVmIntegrityPolicy

compute.googleapis.com/instances.setTags

compute.googleapis.com/instances.simulateMaintenanceEvent

compute.googleapis.com/instances.start

compute.googleapis.com/instances.startWithEncryptionKey

compute.googleapis.com/instances.stop

compute.googleapis.com/instances.suspend

compute.googleapis.com/instances.update

compute.googleapis.com/instances.updateAccessConfig

compute.googleapis.com/instances.updateDisplayDevice

compute.googleapis.com/instances.updateNetworkInterface

compute.googleapis.com/instances.updateSecurity

compute.googleapis.com/instances.updateShieldedInstanceConfig

compute.googleapis.com/instances.updateShieldedVmConfig

compute.googleapis.com/instances.use

compute.googleapis.com/instances.useReadOnly

compute.googleapis.com/instantSnapshots.create

compute.googleapis.com/instantSnapshots.delete

compute.googleapis.com/instantSnapshots.get

compute.googleapis.com/instantSnapshots.getIamPolicy

compute.googleapis.com/instantSnapshots.list

compute.googleapis.com/instantSnapshots.setIamPolicy

compute.googleapis.com/instantSnapshots.setLabels

compute.googleapis.com/interconnectAttachments.create

compute.googleapis.com/interconnectAttachments.delete

compute.googleapis.com/interconnectAttachments.get

compute.googleapis.com/interconnectAttachments.list

compute.googleapis.com/interconnectAttachments.setLabels

compute.googleapis.com/interconnectAttachments.update

compute.googleapis.com/interconnectAttachments.use

compute.googleapis.com/interconnectLocations.get

compute.googleapis.com/interconnectLocations.list

compute.googleapis.com/interconnectRemoteLocations.get

compute.googleapis.com/interconnectRemoteLocations.list

compute.googleapis.com/interconnects.create

compute.googleapis.com/interconnects.delete

compute.googleapis.com/interconnects.get

compute.googleapis.com/interconnects.list

compute.googleapis.com/interconnects.setLabels

compute.googleapis.com/interconnects.update

compute.googleapis.com/interconnects.use

compute.googleapis.com/licenseCodes.get

compute.googleapis.com/licenseCodes.getIamPolicy

compute.googleapis.com/licenseCodes.list

compute.googleapis.com/licenseCodes.setIamPolicy

compute.googleapis.com/licenses.create

compute.googleapis.com/licenses.delete

compute.googleapis.com/licenses.get

compute.googleapis.com/licenses.getIamPolicy

compute.googleapis.com/licenses.list

compute.googleapis.com/licenses.setIamPolicy

compute.googleapis.com/machineImages.create

compute.googleapis.com/machineImages.delete

compute.googleapis.com/machineImages.get

compute.googleapis.com/machineImages.getIamPolicy

compute.googleapis.com/machineImages.list

compute.googleapis.com/machineImages.setIamPolicy

compute.googleapis.com/machineImages.useReadOnly

compute.googleapis.com/machineTypes.get

compute.googleapis.com/machineTypes.list

compute.googleapis.com/networkAttachments.create

compute.googleapis.com/networkAttachments.delete

compute.googleapis.com/networkAttachments.get

compute.googleapis.com/networkAttachments.list

compute.googleapis.com/networkEdgeSecurityServices.create

compute.googleapis.com/networkEdgeSecurityServices.delete

compute.googleapis.com/networkEdgeSecurityServices.get

compute.googleapis.com/networkEdgeSecurityServices.list

compute.googleapis.com/networkEndpointGroups.attachNetworkEndpoints

compute.googleapis.com/networkEndpointGroups.create

compute.googleapis.com/networkEndpointGroups.delete

compute.googleapis.com/networkEndpointGroups.detachNetworkEndpoints

compute.googleapis.com/networkEndpointGroups.get

compute.googleapis.com/networkEndpointGroups.getIamPolicy

compute.googleapis.com/networkEndpointGroups.list

compute.googleapis.com/networkEndpointGroups.setIamPolicy

compute.googleapis.com/networkEndpointGroups.use

compute.googleapis.com/networks.addPeering

compute.googleapis.com/networks.create

compute.googleapis.com/networks.delete

compute.googleapis.com/networks.get

compute.googleapis.com/networks.getEffectiveFirewalls

compute.googleapis.com/networks.getRegionEffectiveFirewalls

compute.googleapis.com/networks.list

compute.googleapis.com/networks.listPeeringRoutes

compute.googleapis.com/networks.mirror

compute.googleapis.com/networks.removePeering

compute.googleapis.com/networks.setFirewallPolicy

compute.googleapis.com/networks.switchToCustomMode

compute.googleapis.com/networks.update

compute.googleapis.com/networks.updatePeering

compute.googleapis.com/networks.updatePolicy

compute.googleapis.com/networks.use

compute.googleapis.com/networks.useExternalIp

compute.googleapis.com/nodeGroups.addNodes

compute.googleapis.com/nodeGroups.create

compute.googleapis.com/nodeGroups.delete

compute.googleapis.com/nodeGroups.deleteNodes

compute.googleapis.com/nodeGroups.get

compute.googleapis.com/nodeGroups.getIamPolicy

compute.googleapis.com/nodeGroups.list

compute.googleapis.com/nodeGroups.setIamPolicy

compute.googleapis.com/nodeGroups.setNodeTemplate

compute.googleapis.com/nodeGroups.simulateMaintenanceEvent

compute.googleapis.com/nodeGroups.update

compute.googleapis.com/nodeTemplates.create

compute.googleapis.com/nodeTemplates.delete

compute.googleapis.com/nodeTemplates.get

compute.googleapis.com/nodeTemplates.getIamPolicy

compute.googleapis.com/nodeTemplates.list

compute.googleapis.com/nodeTemplates.setIamPolicy

compute.googleapis.com/nodeTypes.get

compute.googleapis.com/nodeTypes.list

compute.googleapis.com/organizations.disableXpnHost

compute.googleapis.com/organizations.disableXpnResource

compute.googleapis.com/organizations.enableXpnHost

compute.googleapis.com/organizations.enableXpnResource

compute.googleapis.com/organizations.listAssociations

compute.googleapis.com/organizations.setFirewallPolicy

compute.googleapis.com/organizations.setSecurityPolicy

compute.googleapis.com/oslogin.updateExternalUser

compute.googleapis.com/packetMirrorings.create

compute.googleapis.com/packetMirrorings.delete

compute.googleapis.com/packetMirrorings.get

compute.googleapis.com/packetMirrorings.list

compute.googleapis.com/packetMirrorings.update

compute.googleapis.com/projects.get

compute.googleapis.com/projects.setCommonInstanceMetadata

compute.googleapis.com/projects.setDefaultNetworkTier

compute.googleapis.com/projects.setDefaultServiceAccount

compute.googleapis.com/projects.setUsageExportBucket

compute.googleapis.com/publicAdvertisedPrefixes.create

compute.googleapis.com/publicAdvertisedPrefixes.delete

compute.googleapis.com/publicAdvertisedPrefixes.get

compute.googleapis.com/publicAdvertisedPrefixes.list

compute.googleapis.com/publicAdvertisedPrefixes.update

compute.googleapis.com/publicAdvertisedPrefixes.updatePolicy

compute.googleapis.com/publicDelegatedPrefixes.create

compute.googleapis.com/publicDelegatedPrefixes.delete

compute.googleapis.com/publicDelegatedPrefixes.get

compute.googleapis.com/publicDelegatedPrefixes.list

compute.googleapis.com/publicDelegatedPrefixes.update

compute.googleapis.com/publicDelegatedPrefixes.updatePolicy

compute.googleapis.com/regionBackendServices.create

compute.googleapis.com/regionBackendServices.delete

compute.googleapis.com/regionBackendServices.get

compute.googleapis.com/regionBackendServices.getIamPolicy

compute.googleapis.com/regionBackendServices.list

compute.googleapis.com/regionBackendServices.setIamPolicy

compute.googleapis.com/regionBackendServices.setSecurityPolicy

compute.googleapis.com/regionBackendServices.update

compute.googleapis.com/regionBackendServices.use

compute.googleapis.com/regionFirewallPolicies.cloneRules

compute.googleapis.com/regionFirewallPolicies.create

compute.googleapis.com/regionFirewallPolicies.delete

compute.googleapis.com/regionFirewallPolicies.get

compute.googleapis.com/regionFirewallPolicies.getIamPolicy

compute.googleapis.com/regionFirewallPolicies.list

compute.googleapis.com/regionFirewallPolicies.setIamPolicy

compute.googleapis.com/regionFirewallPolicies.update

compute.googleapis.com/regionFirewallPolicies.use

compute.googleapis.com/regionHealthCheckServices.create

compute.googleapis.com/regionHealthCheckServices.delete

compute.googleapis.com/regionHealthCheckServices.get

compute.googleapis.com/regionHealthCheckServices.list

compute.googleapis.com/regionHealthCheckServices.update

compute.googleapis.com/regionHealthCheckServices.use

compute.googleapis.com/regionHealthChecks.create

compute.googleapis.com/regionHealthChecks.delete

compute.googleapis.com/regionHealthChecks.get

compute.googleapis.com/regionHealthChecks.list

compute.googleapis.com/regionHealthChecks.update

compute.googleapis.com/regionHealthChecks.use

compute.googleapis.com/regionNetworkEndpointGroups.attachNetworkEndpoints

compute.googleapis.com/regionNetworkEndpointGroups.create

compute.googleapis.com/regionNetworkEndpointGroups.delete

compute.googleapis.com/regionNetworkEndpointGroups.detachNetworkEndpoints

compute.googleapis.com/regionNetworkEndpointGroups.get

compute.googleapis.com/regionNetworkEndpointGroups.list

compute.googleapis.com/regionNetworkEndpointGroups.use

compute.googleapis.com/regionNotificationEndpoints.create

compute.googleapis.com/regionNotificationEndpoints.delete

compute.googleapis.com/regionNotificationEndpoints.get

compute.googleapis.com/regionNotificationEndpoints.list

compute.googleapis.com/regionNotificationEndpoints.update

compute.googleapis.com/regionNotificationEndpoints.use

compute.googleapis.com/regionOperations.delete

compute.googleapis.com/regionOperations.get

compute.googleapis.com/regionOperations.getIamPolicy

compute.googleapis.com/regionOperations.list

compute.googleapis.com/regionOperations.setIamPolicy

compute.googleapis.com/regionSecurityPolicies.create

compute.googleapis.com/regionSecurityPolicies.delete

compute.googleapis.com/regionSecurityPolicies.get

compute.googleapis.com/regionSecurityPolicies.list

compute.googleapis.com/regionSecurityPolicies.update

compute.googleapis.com/regionSecurityPolicies.use

compute.googleapis.com/regionSslCertificates.create

compute.googleapis.com/regionSslCertificates.delete

compute.googleapis.com/regionSslCertificates.get

compute.googleapis.com/regionSslCertificates.list

compute.googleapis.com/regionSslPolicies.create

compute.googleapis.com/regionSslPolicies.delete

compute.googleapis.com/regionSslPolicies.get

compute.googleapis.com/regionSslPolicies.list

compute.googleapis.com/regionSslPolicies.listAvailableFeatures

compute.googleapis.com/regionSslPolicies.update

compute.googleapis.com/regionSslPolicies.use

compute.googleapis.com/regionTargetHttpProxies.create

compute.googleapis.com/regionTargetHttpProxies.delete

compute.googleapis.com/regionTargetHttpProxies.get

compute.googleapis.com/regionTargetHttpProxies.list

compute.googleapis.com/regionTargetHttpProxies.setUrlMap

compute.googleapis.com/regionTargetHttpProxies.use

compute.googleapis.com/regionTargetHttpsProxies.create

compute.googleapis.com/regionTargetHttpsProxies.delete

compute.googleapis.com/regionTargetHttpsProxies.get

compute.googleapis.com/regionTargetHttpsProxies.list

compute.googleapis.com/regionTargetHttpsProxies.setSslCertificates

compute.googleapis.com/regionTargetHttpsProxies.setUrlMap

compute.googleapis.com/regionTargetHttpsProxies.update

compute.googleapis.com/regionTargetHttpsProxies.use

compute.googleapis.com/regionTargetTcpProxies.create

compute.googleapis.com/regionTargetTcpProxies.delete

compute.googleapis.com/regionTargetTcpProxies.get

compute.googleapis.com/regionTargetTcpProxies.list

compute.googleapis.com/regionTargetTcpProxies.use

compute.googleapis.com/regionUrlMaps.create

compute.googleapis.com/regionUrlMaps.delete

compute.googleapis.com/regionUrlMaps.get

compute.googleapis.com/regionUrlMaps.list

compute.googleapis.com/regionUrlMaps.update

compute.googleapis.com/regionUrlMaps.use

compute.googleapis.com/reservations.create

compute.googleapis.com/reservations.delete

compute.googleapis.com/reservations.get

compute.googleapis.com/reservations.list

compute.googleapis.com/reservations.resize

compute.googleapis.com/reservations.update

compute.googleapis.com/resourcePolicies.create

compute.googleapis.com/resourcePolicies.delete

compute.googleapis.com/resourcePolicies.get

compute.googleapis.com/resourcePolicies.getIamPolicy

compute.googleapis.com/resourcePolicies.list

compute.googleapis.com/resourcePolicies.setIamPolicy

compute.googleapis.com/resourcePolicies.use

compute.googleapis.com/resourcePolicies.useReadOnly

compute.googleapis.com/routers.create

compute.googleapis.com/routers.delete

compute.googleapis.com/routers.get

compute.googleapis.com/routers.list

compute.googleapis.com/routers.update

compute.googleapis.com/routers.use

compute.googleapis.com/routes.create

compute.googleapis.com/routes.delete

compute.googleapis.com/routes.get

compute.googleapis.com/routes.list

compute.googleapis.com/securityPolicies.addAssociation

compute.googleapis.com/securityPolicies.copyRules

compute.googleapis.com/securityPolicies.create

compute.googleapis.com/securityPolicies.delete

compute.googleapis.com/securityPolicies.get

compute.googleapis.com/securityPolicies.getIamPolicy

compute.googleapis.com/securityPolicies.list

compute.googleapis.com/securityPolicies.removeAssociation

compute.googleapis.com/securityPolicies.setIamPolicy

compute.googleapis.com/securityPolicies.setLabels

compute.googleapis.com/securityPolicies.update

compute.googleapis.com/securityPolicies.use

compute.googleapis.com/serviceAttachments.create

compute.googleapis.com/serviceAttachments.delete

compute.googleapis.com/serviceAttachments.get

compute.googleapis.com/serviceAttachments.getIamPolicy

compute.googleapis.com/serviceAttachments.list

compute.googleapis.com/serviceAttachments.setIamPolicy

compute.googleapis.com/serviceAttachments.update

compute.googleapis.com/serviceAttachments.use

compute.googleapis.com/snapshots.create

compute.googleapis.com/snapshots.createTagBinding

compute.googleapis.com/snapshots.delete

compute.googleapis.com/snapshots.deleteTagBinding

compute.googleapis.com/snapshots.get

compute.googleapis.com/snapshots.getIamPolicy

compute.googleapis.com/snapshots.list

compute.googleapis.com/snapshots.listEffectiveTags

compute.googleapis.com/snapshots.listTagBindings

compute.googleapis.com/snapshots.setIamPolicy

compute.googleapis.com/snapshots.setLabels

compute.googleapis.com/snapshots.useReadOnly

compute.googleapis.com/sslCertificates.create

compute.googleapis.com/sslCertificates.delete

compute.googleapis.com/sslCertificates.get

compute.googleapis.com/sslCertificates.list

compute.googleapis.com/sslPolicies.create

compute.googleapis.com/sslPolicies.delete

compute.googleapis.com/sslPolicies.get

compute.googleapis.com/sslPolicies.list

compute.googleapis.com/sslPolicies.listAvailableFeatures

compute.googleapis.com/sslPolicies.update

compute.googleapis.com/sslPolicies.use

compute.googleapis.com/subnetworks.create

compute.googleapis.com/subnetworks.delete

compute.googleapis.com/subnetworks.expandIpCidrRange

compute.googleapis.com/subnetworks.get

compute.googleapis.com/subnetworks.getIamPolicy

compute.googleapis.com/subnetworks.list

compute.googleapis.com/subnetworks.mirror

compute.googleapis.com/subnetworks.setIamPolicy

compute.googleapis.com/subnetworks.setPrivateIpGoogleAccess

compute.googleapis.com/subnetworks.update

compute.googleapis.com/subnetworks.use

compute.googleapis.com/subnetworks.useExternalIp

compute.googleapis.com/targetGrpcProxies.create

compute.googleapis.com/targetGrpcProxies.delete

compute.googleapis.com/targetGrpcProxies.get

compute.googleapis.com/targetGrpcProxies.list

compute.googleapis.com/targetGrpcProxies.update

compute.googleapis.com/targetGrpcProxies.use

compute.googleapis.com/targetHttpProxies.create

compute.googleapis.com/targetHttpProxies.delete

compute.googleapis.com/targetHttpProxies.get

compute.googleapis.com/targetHttpProxies.list

compute.googleapis.com/targetHttpProxies.setUrlMap

compute.googleapis.com/targetHttpProxies.update

compute.googleapis.com/targetHttpProxies.use

compute.googleapis.com/targetHttpsProxies.create

compute.googleapis.com/targetHttpsProxies.delete

compute.googleapis.com/targetHttpsProxies.get

compute.googleapis.com/targetHttpsProxies.list

compute.googleapis.com/targetHttpsProxies.setCertificateMap

compute.googleapis.com/targetHttpsProxies.setQuicOverride

compute.googleapis.com/targetHttpsProxies.setSslCertificates

compute.googleapis.com/targetHttpsProxies.setUrlMap

compute.googleapis.com/targetInstances.create

compute.googleapis.com/targetInstances.delete

compute.googleapis.com/targetInstances.get

compute.googleapis.com/targetInstances.list

compute.googleapis.com/targetInstances.use

compute.googleapis.com/targetPools.addHealthCheck

compute.googleapis.com/targetPools.addInstance

compute.googleapis.com/targetPools.create

compute.googleapis.com/targetPools.delete

compute.googleapis.com/targetPools.get

compute.googleapis.com/targetPools.list

compute.googleapis.com/targetPools.removeHealthCheck

compute.googleapis.com/targetPools.removeInstance

compute.googleapis.com/targetPools.update

compute.googleapis.com/targetPools.use

compute.googleapis.com/targetSslProxies.create

compute.googleapis.com/targetSslProxies.delete

compute.googleapis.com/targetSslProxies.get

compute.googleapis.com/targetSslProxies.list

compute.googleapis.com/targetSslProxies.setBackendService

compute.googleapis.com/targetSslProxies.setCertificateMap

compute.googleapis.com/targetSslProxies.setProxyHeader

compute.googleapis.com/targetSslProxies.setSslCertificates

compute.googleapis.com/targetSslProxies.setSslPolicy

compute.googleapis.com/targetSslProxies.use

compute.googleapis.com/targetTcpProxies.create

compute.googleapis.com/targetTcpProxies.delete

compute.googleapis.com/targetTcpProxies.get

compute.googleapis.com/targetTcpProxies.list

compute.googleapis.com/targetTcpProxies.update

compute.googleapis.com/targetTcpProxies.use

compute.googleapis.com/targetVpnGateways.create

compute.googleapis.com/targetVpnGateways.delete

compute.googleapis.com/targetVpnGateways.get

compute.googleapis.com/targetVpnGateways.list

compute.googleapis.com/targetVpnGateways.setLabels

compute.googleapis.com/targetVpnGateways.use

compute.googleapis.com/urlMaps.create

compute.googleapis.com/urlMaps.delete

compute.googleapis.com/urlMaps.get

compute.googleapis.com/urlMaps.invalidateCache

compute.googleapis.com/urlMaps.list

compute.googleapis.com/urlMaps.update

compute.googleapis.com/urlMaps.use

compute.googleapis.com/urlMaps.validate

compute.googleapis.com/vpnGateways.create

compute.googleapis.com/vpnGateways.delete

compute.googleapis.com/vpnGateways.get

compute.googleapis.com/vpnGateways.list

compute.googleapis.com/vpnGateways.setLabels

compute.googleapis.com/vpnGateways.use

compute.googleapis.com/vpnTunnels.create

compute.googleapis.com/vpnTunnels.delete

compute.googleapis.com/vpnTunnels.get

compute.googleapis.com/vpnTunnels.list

compute.googleapis.com/vpnTunnels.setLabels

compute.googleapis.com/zoneOperations.delete

compute.googleapis.com/zoneOperations.get

compute.googleapis.com/zoneOperations.getIamPolicy

compute.googleapis.com/zoneOperations.list

compute.googleapis.com/zoneOperations.setIamPolicy

compute.googleapis.com/zones.get

compute.googleapis.com/zones.list

Google Kubernetes Engine

container.googleapis.com/clusters.create

container.googleapis.com/clusters.delete

container.googleapis.com/clusters.get

container.googleapis.com/clusters.getCredentials

container.googleapis.com/clusters.list

container.googleapis.com/clusters.update

container.googleapis.com/operations.get

container.googleapis.com/operations.list

Dataflow

dataflow.googleapis.com/jobs.create

dataflow.googleapis.com/jobs.get

dataflow.googleapis.com/jobs.list

Cloud DNS

dns.googleapis.com/changes.create

dns.googleapis.com/changes.get

dns.googleapis.com/changes.list

dns.googleapis.com/dnsKeys.get

dns.googleapis.com/dnsKeys.list

dns.googleapis.com/managedZoneOperations.get

dns.googleapis.com/managedZoneOperations.list

dns.googleapis.com/managedZones.create

dns.googleapis.com/managedZones.delete

dns.googleapis.com/managedZones.get

dns.googleapis.com/managedZones.list

dns.googleapis.com/managedZones.update

dns.googleapis.com/policies.create

dns.googleapis.com/policies.delete

dns.googleapis.com/policies.get

dns.googleapis.com/policies.list

dns.googleapis.com/policies.update

dns.googleapis.com/projects.get

dns.googleapis.com/resourceRecordSets.create

dns.googleapis.com/resourceRecordSets.delete

dns.googleapis.com/resourceRecordSets.get

dns.googleapis.com/resourceRecordSets.list

dns.googleapis.com/resourceRecordSets.update

Identity and Access Management

iam.googleapis.com/roles.create

iam.googleapis.com/roles.delete

iam.googleapis.com/roles.get

iam.googleapis.com/roles.list

iam.googleapis.com/roles.undelete

iam.googleapis.com/roles.update

iam.googleapis.com/serviceAccountKeys.create

iam.googleapis.com/serviceAccountKeys.delete

iam.googleapis.com/serviceAccountKeys.disable

iam.googleapis.com/serviceAccountKeys.enable

iam.googleapis.com/serviceAccountKeys.get

iam.googleapis.com/serviceAccountKeys.list

iam.googleapis.com/serviceAccounts.create

iam.googleapis.com/serviceAccounts.delete

iam.googleapis.com/serviceAccounts.disable

iam.googleapis.com/serviceAccounts.enable

iam.googleapis.com/serviceAccounts.get

iam.googleapis.com/serviceAccounts.getAccessToken

iam.googleapis.com/serviceAccounts.getIamPolicy

iam.googleapis.com/serviceAccounts.getOpenIdToken

iam.googleapis.com/serviceAccounts.implicitDelegation

iam.googleapis.com/serviceAccounts.list

iam.googleapis.com/serviceAccounts.setIamPolicy

iam.googleapis.com/serviceAccounts.signBlob

iam.googleapis.com/serviceAccounts.signJwt

iam.googleapis.com/serviceAccounts.undelete

iam.googleapis.com/serviceAccounts.update

iam.googleapis.com/workloadIdentityPoolProviders.create

iam.googleapis.com/workloadIdentityPoolProviders.delete

iam.googleapis.com/workloadIdentityPoolProviders.get

iam.googleapis.com/workloadIdentityPoolProviders.list

iam.googleapis.com/workloadIdentityPoolProviders.undelete

iam.googleapis.com/workloadIdentityPoolProviders.update

iam.googleapis.com/workloadIdentityPools.create

iam.googleapis.com/workloadIdentityPools.delete

iam.googleapis.com/workloadIdentityPools.get

iam.googleapis.com/workloadIdentityPools.list

iam.googleapis.com/workloadIdentityPools.undelete

iam.googleapis.com/workloadIdentityPools.update

Service de règles d'organisation

orgpolicy.googleapis.com/policy.set

Security Command Center

securitycenter.googleapis.com/assets.group

securitycenter.googleapis.com/assets.list

securitycenter.googleapis.com/assets.listAssetPropertyNames

securitycenter.googleapis.com/assets.runDiscovery

securitycenter.googleapis.com/assetsecuritymarks.update

securitycenter.googleapis.com/containerthreatdetectionsettings.calculate

securitycenter.googleapis.com/containerthreatdetectionsettings.get

securitycenter.googleapis.com/containerthreatdetectionsettings.update

securitycenter.googleapis.com/eventthreatdetectionsettings.calculate

securitycenter.googleapis.com/eventthreatdetectionsettings.get

securitycenter.googleapis.com/eventthreatdetectionsettings.update

securitycenter.googleapis.com/findings.bulkMuteUpdate

securitycenter.googleapis.com/findings.group

securitycenter.googleapis.com/findings.list

securitycenter.googleapis.com/findings.listFindingPropertyNames

securitycenter.googleapis.com/findings.setMute

securitycenter.googleapis.com/findings.setState

securitycenter.googleapis.com/findings.setWorkflowState

securitycenter.googleapis.com/findings.update

securitycenter.googleapis.com/findingsecuritymarks.update

securitycenter.googleapis.com/muteconfigs.create

securitycenter.googleapis.com/muteconfigs.delete

securitycenter.googleapis.com/muteconfigs.get

securitycenter.googleapis.com/muteconfigs.list

securitycenter.googleapis.com/muteconfigs.update

securitycenter.googleapis.com/notificationconfig.create

securitycenter.googleapis.com/notificationconfig.delete

securitycenter.googleapis.com/notificationconfig.get

securitycenter.googleapis.com/notificationconfig.list

securitycenter.googleapis.com/notificationconfig.update

securitycenter.googleapis.com/organizationsettings.get

securitycenter.googleapis.com/organizationsettings.update

securitycenter.googleapis.com/securitycentersettings.get

securitycenter.googleapis.com/securitycentersettings.update

securitycenter.googleapis.com/securityhealthanalyticscustommodules.create

securitycenter.googleapis.com/securityhealthanalyticscustommodules.delete

securitycenter.googleapis.com/securityhealthanalyticscustommodules.get

securitycenter.googleapis.com/securityhealthanalyticscustommodules.list

securitycenter.googleapis.com/securityhealthanalyticscustommodules.test

securitycenter.googleapis.com/securityhealthanalyticscustommodules.update

securitycenter.googleapis.com/securityhealthanalyticssettings.calculate

securitycenter.googleapis.com/securityhealthanalyticssettings.get

securitycenter.googleapis.com/securityhealthanalyticssettings.update

securitycenter.googleapis.com/sources.get

securitycenter.googleapis.com/sources.getIamPolicy

securitycenter.googleapis.com/sources.list

securitycenter.googleapis.com/sources.setIamPolicy

securitycenter.googleapis.com/sources.update

securitycenter.googleapis.com/subscription.get

securitycenter.googleapis.com/userinterfacemetadata.get

securitycenter.googleapis.com/websecurityscannersettings.calculate

securitycenter.googleapis.com/websecurityscannersettings.get

securitycenter.googleapis.com/websecurityscannersettings.update

Service Networking

servicenetworking.googleapis.com/operations.get

servicenetworking.googleapis.com/services.addPeering

servicenetworking.googleapis.com/services.createPeeredDnsDomain

servicenetworking.googleapis.com/services.deleteConnection

servicenetworking.googleapis.com/services.deletePeeredDnsDomain

servicenetworking.googleapis.com/services.disableVpcServiceControls

servicenetworking.googleapis.com/services.enableVpcServiceControls

servicenetworking.googleapis.com/services.get

servicenetworking.googleapis.com/services.listPeeredDnsDomains

Service Usage

serviceusage.googleapis.com/operations.cancel

serviceusage.googleapis.com/operations.delete

serviceusage.googleapis.com/operations.get

serviceusage.googleapis.com/operations.list

serviceusage.googleapis.com/quotas.get

serviceusage.googleapis.com/quotas.update

serviceusage.googleapis.com/services.disable

serviceusage.googleapis.com/services.enable

serviceusage.googleapis.com/services.get

serviceusage.googleapis.com/services.list

serviceusage.googleapis.com/services.use

Cloud Storage

storage.googleapis.com/buckets.create

storage.googleapis.com/buckets.createTagBinding

storage.googleapis.com/buckets.delete

storage.googleapis.com/buckets.deleteTagBinding

storage.googleapis.com/buckets.get

storage.googleapis.com/buckets.getIamPolicy

storage.googleapis.com/buckets.list

storage.googleapis.com/buckets.listTagBindings

storage.googleapis.com/buckets.setIamPolicy

storage.googleapis.com/buckets.update

storage.googleapis.com/hmacKeys.create

storage.googleapis.com/hmacKeys.delete

storage.googleapis.com/hmacKeys.get

storage.googleapis.com/hmacKeys.list

storage.googleapis.com/hmacKeys.update

storage.googleapis.com/multipartUploads.abort

storage.googleapis.com/multipartUploads.create

storage.googleapis.com/multipartUploads.list

storage.googleapis.com/multipartUploads.listParts

storage.googleapis.com/objects.create

storage.googleapis.com/objects.delete

storage.googleapis.com/objects.get

storage.googleapis.com/objects.getIamPolicy

storage.googleapis.com/objects.list

storage.googleapis.com/objects.setIamPolicy

storage.googleapis.com/objects.update

Accès au VPC sans serveur

vpcaccess.googleapis.com/connectors.create

vpcaccess.googleapis.com/connectors.delete

vpcaccess.googleapis.com/connectors.get

vpcaccess.googleapis.com/connectors.list

vpcaccess.googleapis.com/connectors.update

vpcaccess.googleapis.com/connectors.use

vpcaccess.googleapis.com/locations.list

vpcaccess.googleapis.com/operations.get

vpcaccess.googleapis.com/operations.list