This page lists the IAM roles and permissions for Cloud DNS. To search through all roles and permissions, see the role and permission index.
Cloud DNS roles
| Role | Permissions | 
|---|---|
| DNS Administrator( Provides read-write access to all Cloud DNS resources. Lowest-level resources where you can grant this role: 
 | 
 
 
       
 
       
 
       
 
       
 
 
 
 
 
 
 
       
 
       
 
 
       
 
       
 
       
 
 
 | 
| DNS Peer( Access to target networks with DNS peering zones | 
 | 
| DNS Reader( Provides read-only access to all Cloud DNS resources. Lowest-level resources where you can grant this role: 
 | 
 
 
 
       
 
       
 
 
 
 
 
 
 
 
 
 
 
 
 
 | 
| Cloud DNS Service Agent( Gives Cloud DNS Service Agent access to Cloud Platform resources. | 
 
 
 
 
 
 
 | 
Cloud DNS permissions
| Permission | Included in roles | 
|---|---|
| 
 | 
          Owner ( 
          Editor ( 
          DNS Administrator ( 
          Network Administrator ( Service agent roles 
 | 
| 
 | 
          Owner ( 
          Editor ( 
          Viewer ( 
          DNS Administrator ( 
          DNS Reader ( 
          Network Administrator ( 
          Security Auditor ( 
          Support User ( Service agent roles 
 | 
| 
 | 
          Owner ( 
          Editor ( 
          Viewer ( 
          DNS Administrator ( 
          DNS Reader ( 
          Network Administrator ( 
          Security Admin ( 
          Security Auditor ( 
          Security Reviewer ( 
          Support User ( Service agent roles 
 | 
| 
 | 
          Owner ( 
          Editor ( 
          Viewer ( 
          DNS Administrator ( 
          DNS Reader ( 
          Network Administrator ( 
          Security Auditor ( 
          Support User ( Service agent roles 
 | 
| 
 | 
          Owner ( 
          Editor ( 
          Viewer ( 
          DNS Administrator ( 
          DNS Reader ( 
          Network Administrator ( 
          Security Admin ( 
          Security Auditor ( 
          Security Reviewer ( 
          Support User ( Service agent roles 
 | 
| 
 | 
          Owner ( 
          Editor ( 
          DNS Administrator ( 
          Network Administrator ( Service agent roles 
 | 
| 
 | 
          Owner ( 
          Editor ( 
          DNS Administrator ( 
          Network Administrator ( Service agent roles 
 | 
| 
 | 
          Owner ( 
          Editor ( 
          Viewer ( 
          DNS Administrator ( 
          DNS Reader ( 
          Network Administrator ( 
          Security Auditor ( 
          Support User ( Service agent roles 
 | 
| 
 | 
          Owner ( 
          Editor ( 
          Viewer ( 
          DNS Administrator ( 
          DNS Reader ( 
          Network Administrator ( 
          Security Admin ( 
          Security Auditor ( 
          Security Reviewer ( 
          Support User ( Service agent roles 
 | 
| 
 | 
          Owner ( 
          Editor ( 
          DNS Administrator ( 
          Network Administrator ( Service agent roles 
 | 
| 
 | 
          Owner ( 
          Editor ( 
          DNS Administrator ( 
          Network Administrator ( Service agent roles 
 | 
| 
 | 
          Owner ( 
          Editor ( 
          Viewer ( 
          Composer Shared VPC Agent ( 
          DNS Administrator ( 
          DNS Reader ( 
          Network Administrator ( 
          Security Auditor ( 
          Support User ( Service agent roles 
 | 
| 
 | 
          Owner ( 
          Editor ( 
          Viewer ( 
          DNS Administrator ( 
          Network Administrator ( 
          Security Admin ( 
          Security Auditor ( 
          Security Reviewer ( 
          Support User ( Service agent roles 
 | 
| 
 | 
          Owner ( 
          Editor ( 
          Viewer ( 
          Composer Shared VPC Agent ( 
          DNS Administrator ( 
          DNS Reader ( 
          Network Administrator ( 
          Security Admin ( 
          Security Auditor ( 
          Security Reviewer ( 
          Support User ( 
          Workload Manager Admin ( 
          Workload Manager Deployment Admin ( Service agent roles 
 | 
| 
 | 
          Owner ( 
          Security Admin ( | 
| 
 | 
          Owner ( 
          Editor ( 
          DNS Administrator ( 
          Network Administrator ( Service agent roles 
 | 
| 
 | 
          Owner ( 
          Editor ( 
          Kubernetes Engine Host Service Agent User ( 
          DNS Administrator ( 
          Network Administrator ( Service agent roles 
 | 
| 
 | 
          Owner ( 
          Editor ( 
          Kubernetes Engine Host Service Agent User ( 
          DNS Administrator ( 
          Network Administrator ( Service agent roles 
 | 
| 
 | 
          Owner ( 
          Editor ( 
          Kubernetes Engine Host Service Agent User ( 
          DNS Administrator ( 
          Network Administrator ( Service agent roles 
 | 
| 
 | 
          Owner ( 
          Editor ( 
          Composer Shared VPC Agent ( 
          DNS Administrator ( 
          DNS Peer ( 
          Network Administrator ( Service agent roles 
 | 
| 
 | 
          Owner ( 
          Editor ( 
          DNS Administrator ( 
          Network Administrator ( Service agent roles 
 | 
| 
 | 
          Owner ( 
          Editor ( 
          DNS Administrator ( 
          Network Administrator ( Service agent roles 
 | 
| 
 | 
          Owner ( 
          Editor ( 
          DNS Administrator ( 
          Network Administrator ( Service agent roles 
 | 
| 
 | 
          Owner ( 
          Editor ( 
          Viewer ( 
          DNS Administrator ( 
          DNS Reader ( 
          Network Administrator ( 
          Security Auditor ( 
          Support User ( Service agent roles 
 | 
| 
 | 
          Owner ( 
          Editor ( 
          Viewer ( 
          DNS Administrator ( 
          DNS Reader ( 
          Network Administrator ( 
          Security Admin ( 
          Security Auditor ( 
          Security Reviewer ( 
          Support User ( Service agent roles 
 | 
| 
 | 
          Owner ( 
          Editor ( 
          DNS Administrator ( 
          Network Administrator ( Service agent roles 
 | 
| 
 | 
          Owner ( 
          Editor ( 
          Viewer ( 
          DNS Administrator ( 
          DNS Reader ( 
          Network Administrator ( 
          Security Auditor ( 
          Support User ( Service agent roles 
 | 
| 
 | 
          Owner ( 
          Editor ( 
          DNS Administrator ( 
          Network Administrator ( Service agent roles 
 | 
| 
 | 
          Owner ( 
          Editor ( 
          DNS Administrator ( 
          Network Administrator ( Service agent roles 
 | 
| 
 | 
          Owner ( 
          Editor ( 
          Viewer ( 
          DNS Administrator ( 
          DNS Reader ( 
          Network Administrator ( 
          Security Auditor ( 
          Support User ( Service agent roles 
 | 
| 
 | 
          Owner ( 
          Editor ( 
          Viewer ( 
          DNS Administrator ( 
          DNS Reader ( 
          Network Administrator ( 
          Security Admin ( 
          Security Auditor ( 
          Security Reviewer ( 
          Support User ( Service agent roles 
 | 
| 
 | 
          Owner ( 
          Editor ( 
          DNS Administrator ( 
          Network Administrator ( Service agent roles 
 | 
| 
 | 
          Owner ( 
          Editor ( 
          Kubernetes Engine Host Service Agent User ( 
          DNS Administrator ( 
          Network Administrator ( Service agent roles 
 | 
| 
 | 
          Owner ( 
          Editor ( 
          Kubernetes Engine Host Service Agent User ( 
          DNS Administrator ( 
          Network Administrator ( Service agent roles 
 | 
| 
 | 
          Owner ( 
          Editor ( 
          Viewer ( 
          Kubernetes Engine Host Service Agent User ( 
          DNS Administrator ( 
          DNS Reader ( 
          Network Administrator ( 
          Security Auditor ( 
          Support User ( Service agent roles 
 | 
| 
 | 
          Owner ( 
          Editor ( 
          Viewer ( 
          Kubernetes Engine Host Service Agent User ( 
          DNS Administrator ( 
          DNS Reader ( 
          Network Administrator ( 
          Security Admin ( 
          Security Auditor ( 
          Security Reviewer ( 
          Support User ( Service agent roles 
 | 
| 
 | 
          Owner ( 
          Editor ( 
          Kubernetes Engine Host Service Agent User ( 
          DNS Administrator ( 
          Network Administrator ( Service agent roles 
 | 
| 
 | 
          Owner ( 
          Editor ( 
          Kubernetes Engine Host Service Agent User ( 
          DNS Administrator ( 
          Network Administrator ( Service agent roles 
 | 
| 
 | 
          Owner ( 
          Editor ( 
          Kubernetes Engine Host Service Agent User ( 
          DNS Administrator ( 
          Network Administrator ( Service agent roles 
 | 
| 
 | 
          Owner ( 
          Editor ( 
          Viewer ( 
          Kubernetes Engine Host Service Agent User ( 
          DNS Administrator ( 
          DNS Reader ( 
          Network Administrator ( 
          Security Auditor ( 
          Support User ( Service agent roles 
 | 
| 
 | 
          Owner ( 
          Editor ( 
          Viewer ( 
          Kubernetes Engine Host Service Agent User ( 
          DNS Administrator ( 
          DNS Reader ( 
          Network Administrator ( 
          Security Admin ( 
          Security Auditor ( 
          Security Reviewer ( 
          Support User ( Service agent roles 
 | 
| 
 | 
          Owner ( 
          Editor ( 
          Kubernetes Engine Host Service Agent User ( 
          DNS Administrator ( 
          Network Administrator ( Service agent roles 
 |