This page lists the IAM roles and permissions for GKE Hub. To search through all roles and permissions, see the role and permission index.
GKE Hub roles
| Role | Permissions | 
|---|---|
| Fleet Admin (formerly GKE Hub Admin)( Full access to Fleet resources. | 
       
 
       
 
       
 
       
 
       
 
       
 
       
 
       
 
       
 
       
 
 
 | 
| GKE Connect Agent( Ability to set up GKE Connect between external clusters and Google. | 
 | 
| GKE Hub Cross Project Service Agent( Gives the GKE Hub service agent permission to manage the project for cross-project fleet registration. | 
 
 | 
| Fleet Editor (formerly GKE Hub Editor)( Edit access to Fleet resources. | 
 
 
 
 
 
 
       
 
       
 
       
 
       
 
 
 
 
 
 
 
 
       
 
       
 
       
 
 
 
 
 
 
 
 
 
 | 
| Connect Gateway Admin( Full access to Connect Gateway. | 
       
 
 
 | 
| Connect Gateway Editor( Edit access to Connect Gateway. | 
 
 
 
 
 
 
 
 | 
| Connect Gateway Reader( Read-only access to Connect Gateway. | 
 
 
 
 | 
| Fleet Scope Admin( Admin access to Fleet Scopes to set IAM Bindings and RBACRoleBindings. | 
 
 
 
 
       
 
 
 
 
 | 
| Fleet Scope Editor( Edit access to Namespaces under Fleet Scopes. | 
 
 
 
 
 
 
 
 
 | 
| Fleet Project-level Scope Editor( Role for project-level permissions for editor of Fleet Scopes. | 
 
 
 
 
 
 
 
 
 
 
 
 | 
| Fleet Scope Viewer( Viewer of Fleet Scopes and associated resources. | 
 
 
 
 
 
 
 | 
| Fleet Project-level Scope Viewer( Role for project-level permissions for viewer of Fleet Scopes. | 
 
 
 
 
 
 
 | 
| GKE Hub Service Agent( Gives the GKE Hub service agent access to Cloud Platform resources. | 
       
 
       
 
 
 
 
 
 
 
 
 
 
 
 
       
 
 
 
 
 
 
 
 
 
 
 
 
       
 
 
 
 
 
 
 
 
 
 
 
 
 
 
       
 
       
 
 
 
 
 
 
 
 
 
 | 
| Fleet Viewer (formerly GKE Hub Viewer)( Read-only access to Fleets and related resources. | 
 
 
 
 
 
       
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 | 
GKE Hub permissions
| Permission | Included in roles | 
|---|---|
| 
 | 
          Owner ( 
          Velostrata Manager ( 
          Velostrata Manager Connection Agent ( 
          GKE Connect Agent ( Service agent roles 
 | 
| 
 | 
          Owner ( 
          Editor ( 
          Fleet Admin (formerly GKE Hub Admin) ( 
          Fleet Editor (formerly GKE Hub Editor) ( Service agent roles 
 | 
| 
 | 
          Owner ( 
          Editor ( 
          Fleet Admin (formerly GKE Hub Admin) ( 
          Fleet Editor (formerly GKE Hub Editor) ( Service agent roles 
 | 
| 
 | 
          Owner ( 
          Editor ( 
          Viewer ( 
          Fleet Admin (formerly GKE Hub Admin) ( 
          Fleet Editor (formerly GKE Hub Editor) ( 
          Fleet Viewer (formerly GKE Hub Viewer) ( 
          Support User ( Service agent roles 
 | 
| 
 | 
          Owner ( 
          Editor ( 
          Viewer ( 
          Fleet Admin (formerly GKE Hub Admin) ( 
          Fleet Editor (formerly GKE Hub Editor) ( 
          Fleet Viewer (formerly GKE Hub Viewer) ( 
          Security Admin ( 
          Security Auditor ( 
          Security Reviewer ( 
          Support User ( Service agent roles 
 | 
| 
 | 
          Owner ( 
          Editor ( 
          Viewer ( 
          Fleet Admin (formerly GKE Hub Admin) ( 
          Fleet Editor (formerly GKE Hub Editor) ( 
          Fleet Viewer (formerly GKE Hub Viewer) ( 
          Security Admin ( 
          Security Auditor ( 
          Security Reviewer ( 
          Support User ( Service agent roles 
 | 
| 
 | 
          Owner ( 
          Fleet Admin (formerly GKE Hub Admin) ( 
          Security Admin ( Service agent roles 
 | 
| 
 | 
          Owner ( 
          Editor ( 
          Fleet Admin (formerly GKE Hub Admin) ( 
          Fleet Editor (formerly GKE Hub Editor) ( Service agent roles 
 | 
| 
 | 
          Owner ( 
          Editor ( 
          Fleet Admin (formerly GKE Hub Admin) ( 
          Fleet Editor (formerly GKE Hub Editor) ( Service agent roles 
 | 
| 
 | 
          Owner ( 
          Editor ( 
          Fleet Admin (formerly GKE Hub Admin) ( 
          Fleet Editor (formerly GKE Hub Editor) ( Service agent roles 
 | 
| 
 | 
          Owner ( 
          Editor ( 
          Fleet Admin (formerly GKE Hub Admin) ( 
          Fleet Editor (formerly GKE Hub Editor) ( Service agent roles 
 | 
| 
 | 
          Owner ( 
          Editor ( 
          Viewer ( 
          Fleet Admin (formerly GKE Hub Admin) ( 
          Fleet Editor (formerly GKE Hub Editor) ( 
          Fleet Viewer (formerly GKE Hub Viewer) ( 
          Support User ( Service agent roles 
 | 
| 
 | 
          Owner ( 
          Editor ( 
          Viewer ( 
          Fleet Admin (formerly GKE Hub Admin) ( 
          Fleet Editor (formerly GKE Hub Editor) ( 
          Fleet Viewer (formerly GKE Hub Viewer) ( 
          Support User ( Service agent roles 
 | 
| 
 | 
          Owner ( 
          Editor ( 
          Fleet Admin (formerly GKE Hub Admin) ( 
          Fleet Editor (formerly GKE Hub Editor) ( Service agent roles 
 | 
| 
 | 
          Owner ( 
          Editor ( 
          Fleet Admin (formerly GKE Hub Admin) ( 
          Fleet Editor (formerly GKE Hub Editor) ( Service agent roles 
 | 
| 
 | 
          Owner ( 
          Editor ( 
          Connect Gateway Admin ( 
          Connect Gateway Editor ( 
          Fleet Project-level Scope Editor ( Service agent roles 
 | 
| 
 | 
          Owner ( 
          Editor ( 
          Viewer ( 
          Connect Gateway Admin ( 
          Connect Gateway Editor ( 
          Connect Gateway Reader ( 
          Fleet Project-level Scope Editor ( 
          Fleet Project-level Scope Viewer ( 
          Support User ( Service agent roles 
 | 
| 
 | 
          Owner ( 
          Editor ( 
          Viewer ( 
          Connect Gateway Admin ( 
          Connect Gateway Editor ( 
          Connect Gateway Reader ( 
          Fleet Project-level Scope Editor ( 
          Fleet Project-level Scope Viewer ( 
          Support User ( Service agent roles 
 | 
| 
 | 
          Owner ( 
          Editor ( 
          Connect Gateway Admin ( 
          Connect Gateway Editor ( 
          Fleet Project-level Scope Editor ( Service agent roles 
 | 
| 
 | 
          Owner ( 
          Editor ( 
          Connect Gateway Admin ( 
          Connect Gateway Editor ( 
          Fleet Project-level Scope Editor ( Service agent roles 
 | 
| 
 | 
          Owner ( 
          Editor ( 
          Connect Gateway Admin ( 
          Connect Gateway Editor ( 
          Fleet Project-level Scope Editor ( Service agent roles 
 | 
| 
 | 
          Owner ( 
          Editor ( 
          Connect Gateway Admin ( Service agent roles 
 | 
| 
 | 
          Owner ( 
          Editor ( 
          Viewer ( 
          Fleet Admin (formerly GKE Hub Admin) ( 
          Fleet Editor (formerly GKE Hub Editor) ( 
          Fleet Viewer (formerly GKE Hub Viewer) ( 
          Support User ( Service agent roles 
 | 
| 
 | 
          Owner ( 
          Editor ( 
          Viewer ( 
          Fleet Admin (formerly GKE Hub Admin) ( 
          Fleet Editor (formerly GKE Hub Editor) ( 
          Fleet Viewer (formerly GKE Hub Viewer) ( 
          Security Admin ( 
          Security Auditor ( 
          Security Reviewer ( 
          Support User ( Service agent roles 
 | 
| 
 | 
          Owner ( 
          Editor ( 
          Fleet Admin (formerly GKE Hub Admin) ( 
          Fleet Editor (formerly GKE Hub Editor) ( Service agent roles 
 | 
| 
 | 
          Owner ( 
          Editor ( 
          Fleet Admin (formerly GKE Hub Admin) ( 
          Fleet Editor (formerly GKE Hub Editor) ( Service agent roles 
 | 
| 
 | 
          Owner ( 
          Editor ( 
          Viewer ( 
          Fleet Admin (formerly GKE Hub Admin) ( 
          Fleet Editor (formerly GKE Hub Editor) ( 
          Fleet Viewer (formerly GKE Hub Viewer) ( 
          Support User ( Service agent roles 
 | 
| 
 | 
          Owner ( 
          Editor ( 
          Viewer ( 
          Fleet Admin (formerly GKE Hub Admin) ( 
          Fleet Editor (formerly GKE Hub Editor) ( 
          Fleet Viewer (formerly GKE Hub Viewer) ( 
          Security Admin ( 
          Security Auditor ( 
          Security Reviewer ( 
          Support User ( Service agent roles 
 | 
| 
 | 
          Owner ( 
          Editor ( 
          Fleet Admin (formerly GKE Hub Admin) ( 
          Fleet Editor (formerly GKE Hub Editor) ( Service agent roles 
 | 
| 
 | 
          Owner ( 
          Editor ( 
          Fleet Admin (formerly GKE Hub Admin) ( 
          Fleet Editor (formerly GKE Hub Editor) ( Service agent roles 
 | 
| 
 | 
          Owner ( 
          Editor ( 
          Fleet Admin (formerly GKE Hub Admin) ( 
          Fleet Editor (formerly GKE Hub Editor) ( Service agent roles 
 | 
| 
 | 
          Owner ( 
          Editor ( 
          Viewer ( 
          Fleet Admin (formerly GKE Hub Admin) ( 
          Fleet Editor (formerly GKE Hub Editor) ( 
          Fleet Viewer (formerly GKE Hub Viewer) ( 
          Support User ( Service agent roles 
 | 
| 
 | 
          Owner ( 
          Editor ( 
          Viewer ( 
          Fleet Admin (formerly GKE Hub Admin) ( 
          Fleet Editor (formerly GKE Hub Editor) ( 
          Fleet Viewer (formerly GKE Hub Viewer) ( 
          Security Admin ( 
          Security Auditor ( 
          Security Reviewer ( 
          Support User ( Service agent roles 
 | 
| 
 | 
          Owner ( 
          Editor ( 
          Fleet Admin (formerly GKE Hub Admin) ( 
          Fleet Editor (formerly GKE Hub Editor) ( Service agent roles 
 | 
| 
 | 
          Owner ( 
          Editor ( 
          Fleet Admin (formerly GKE Hub Admin) ( 
          Fleet Editor (formerly GKE Hub Editor) ( Service agent roles 
 | 
| 
 | 
          Owner ( 
          Editor ( 
          Fleet Admin (formerly GKE Hub Admin) ( 
          Fleet Editor (formerly GKE Hub Editor) ( Service agent roles 
 | 
| 
 | 
          Owner ( 
          Editor ( 
          Viewer ( 
          Fleet Admin (formerly GKE Hub Admin) ( 
          Fleet Editor (formerly GKE Hub Editor) ( 
          Fleet Viewer (formerly GKE Hub Viewer) ( 
          Support User ( Service agent roles 
 | 
| 
 | 
          Owner ( 
          Editor ( 
          Viewer ( 
          Fleet Admin (formerly GKE Hub Admin) ( 
          Fleet Editor (formerly GKE Hub Editor) ( 
          Connect Gateway Admin ( 
          Connect Gateway Editor ( 
          Connect Gateway Reader ( 
          Fleet Project-level Scope Editor ( 
          Fleet Project-level Scope Viewer ( 
          Fleet Viewer (formerly GKE Hub Viewer) ( 
          Support User ( Service agent roles 
 | 
| 
 | 
          Owner ( 
          Editor ( 
          Viewer ( 
          Fleet Admin (formerly GKE Hub Admin) ( 
          Fleet Editor (formerly GKE Hub Editor) ( 
          Fleet Viewer (formerly GKE Hub Viewer) ( 
          Security Admin ( 
          Security Auditor ( 
          Security Reviewer ( 
          Support User ( Service agent roles 
 | 
| 
 | 
          Owner ( 
          Editor ( 
          Viewer ( 
          Fleet Admin (formerly GKE Hub Admin) ( 
          Fleet Editor (formerly GKE Hub Editor) ( 
          Fleet Viewer (formerly GKE Hub Viewer) ( 
          Security Admin ( 
          Security Auditor ( 
          Security Reviewer ( 
          Support User ( Service agent roles 
 | 
| 
 | 
          Owner ( 
          Fleet Admin (formerly GKE Hub Admin) ( 
          Security Admin ( Service agent roles 
 | 
| 
 | 
          Owner ( 
          Editor ( 
          Fleet Admin (formerly GKE Hub Admin) ( 
          Fleet Editor (formerly GKE Hub Editor) ( Service agent roles 
 | 
| 
 | 
          Owner ( 
          Editor ( 
          Fleet Admin (formerly GKE Hub Admin) ( 
          Fleet Editor (formerly GKE Hub Editor) ( 
          Fleet Scope Admin ( 
          Fleet Scope Editor ( Service agent roles 
 | 
| 
 | 
          Owner ( 
          Editor ( 
          Fleet Admin (formerly GKE Hub Admin) ( 
          Fleet Editor (formerly GKE Hub Editor) ( 
          Fleet Scope Admin ( 
          Fleet Scope Editor ( Service agent roles 
 | 
| 
 | 
          Owner ( 
          Editor ( 
          Viewer ( 
          Fleet Admin (formerly GKE Hub Admin) ( 
          Fleet Editor (formerly GKE Hub Editor) ( 
          Fleet Scope Admin ( 
          Fleet Scope Editor ( 
          Fleet Scope Viewer ( 
          Fleet Viewer (formerly GKE Hub Viewer) ( 
          Support User ( Service agent roles 
 | 
| 
 | 
          Owner ( 
          Editor ( 
          Viewer ( 
          Fleet Admin (formerly GKE Hub Admin) ( 
          Fleet Editor (formerly GKE Hub Editor) ( 
          Fleet Scope Admin ( 
          Fleet Scope Editor ( 
          Fleet Scope Viewer ( 
          Fleet Viewer (formerly GKE Hub Viewer) ( 
          Security Admin ( 
          Security Auditor ( 
          Security Reviewer ( 
          Support User ( Service agent roles 
 | 
| 
 | 
          Owner ( 
          Editor ( 
          Fleet Admin (formerly GKE Hub Admin) ( 
          Fleet Editor (formerly GKE Hub Editor) ( Service agent roles 
 | 
| 
 | 
          Owner ( 
          Editor ( 
          Fleet Admin (formerly GKE Hub Admin) ( 
          Fleet Editor (formerly GKE Hub Editor) ( Service agent roles 
 | 
| 
 | 
          Owner ( 
          Editor ( 
          Fleet Admin (formerly GKE Hub Admin) ( 
          Fleet Editor (formerly GKE Hub Editor) ( Service agent roles 
 | 
| 
 | 
          Owner ( 
          Editor ( 
          Viewer ( 
          Fleet Admin (formerly GKE Hub Admin) ( 
          Fleet Editor (formerly GKE Hub Editor) ( 
          Fleet Project-level Scope Editor ( 
          Fleet Viewer (formerly GKE Hub Viewer) ( 
          Support User ( Service agent roles 
 | 
| 
 | 
          Owner ( 
          Editor ( 
          Viewer ( 
          Fleet Admin (formerly GKE Hub Admin) ( 
          Fleet Editor (formerly GKE Hub Editor) ( 
          Fleet Viewer (formerly GKE Hub Viewer) ( 
          Security Admin ( 
          Security Auditor ( 
          Security Reviewer ( 
          Support User ( Service agent roles 
 | 
| 
 | 
          Owner ( 
          Editor ( 
          Fleet Admin (formerly GKE Hub Admin) ( 
          Fleet Editor (formerly GKE Hub Editor) ( 
          Fleet Scope Admin ( Service agent roles 
 | 
| 
 | 
          Owner ( 
          Editor ( 
          Fleet Admin (formerly GKE Hub Admin) ( 
          Fleet Editor (formerly GKE Hub Editor) ( 
          Fleet Scope Admin ( Service agent roles 
 | 
| 
 | 
          Owner ( 
          Editor ( 
          Viewer ( 
          Fleet Admin (formerly GKE Hub Admin) ( 
          Fleet Editor (formerly GKE Hub Editor) ( 
          Fleet Scope Admin ( 
          Fleet Scope Editor ( 
          Fleet Scope Viewer ( 
          Fleet Viewer (formerly GKE Hub Viewer) ( 
          Support User ( Service agent roles 
 | 
| 
 | 
          Owner ( 
          Editor ( 
          Viewer ( 
          Fleet Admin (formerly GKE Hub Admin) ( 
          Fleet Editor (formerly GKE Hub Editor) ( 
          Fleet Scope Admin ( 
          Fleet Scope Editor ( 
          Fleet Scope Viewer ( 
          Fleet Viewer (formerly GKE Hub Viewer) ( 
          Security Admin ( 
          Security Auditor ( 
          Security Reviewer ( 
          Support User ( Service agent roles 
 | 
| 
 | 
          Owner ( 
          Editor ( 
          Fleet Admin (formerly GKE Hub Admin) ( 
          Fleet Editor (formerly GKE Hub Editor) ( 
          Fleet Scope Admin ( Service agent roles 
 | 
| 
 | 
          Owner ( 
          Editor ( 
          Fleet Admin (formerly GKE Hub Admin) ( 
          Fleet Editor (formerly GKE Hub Editor) ( Service agent roles 
 | 
| 
 | 
          Owner ( 
          Editor ( 
          Fleet Admin (formerly GKE Hub Admin) ( 
          Fleet Editor (formerly GKE Hub Editor) ( Service agent roles 
 | 
| 
 | 
          Owner ( 
          Editor ( 
          Viewer ( 
          Fleet Admin (formerly GKE Hub Admin) ( 
          Fleet Editor (formerly GKE Hub Editor) ( 
          Fleet Scope Admin ( 
          Fleet Scope Editor ( 
          Fleet Scope Viewer ( 
          Fleet Viewer (formerly GKE Hub Viewer) ( 
          Support User ( Service agent roles 
 | 
| 
 | 
          Owner ( 
          Editor ( 
          Viewer ( 
          Fleet Admin (formerly GKE Hub Admin) ( 
          Fleet Editor (formerly GKE Hub Editor) ( 
          Fleet Scope Admin ( 
          Fleet Scope Editor ( 
          Fleet Scope Viewer ( 
          Security Admin ( 
          Security Auditor ( 
          Security Reviewer ( 
          Support User ( Service agent roles 
 | 
| 
 | 
          Owner ( 
          Editor ( 
          Viewer ( 
          Fleet Admin (formerly GKE Hub Admin) ( 
          Fleet Editor (formerly GKE Hub Editor) ( 
          Fleet Viewer (formerly GKE Hub Viewer) ( 
          Security Admin ( 
          Security Auditor ( 
          Security Reviewer ( 
          Support User ( Service agent roles 
 | 
| 
 | 
          Owner ( 
          Editor ( 
          Viewer ( 
          Fleet Admin (formerly GKE Hub Admin) ( 
          Fleet Editor (formerly GKE Hub Editor) ( 
          Fleet Scope Admin ( 
          Fleet Scope Editor ( 
          Fleet Scope Viewer ( 
          Fleet Viewer (formerly GKE Hub Viewer) ( 
          Support User ( Service agent roles 
 | 
| 
 | 
          Owner ( 
          Fleet Admin (formerly GKE Hub Admin) ( 
          Fleet Scope Admin ( 
          Security Admin ( | 
| 
 | 
          Owner ( 
          Editor ( 
          Fleet Admin (formerly GKE Hub Admin) ( 
          Fleet Editor (formerly GKE Hub Editor) ( Service agent roles 
 |