GKE Hub roles and permissions Stay organized with collections Save and categorize content based on your preferences.
This page lists the IAM roles and permissions for GKE Hub. Tosearch through all roles and permissions, see therole andpermission index.
GKE Hub roles
| Role | Permissions |
|---|---|
Fleet Admin (formerly GKE Hub Admin)( Full access to Fleet resources. |
|
GKE Connect Agent( Ability to set up GKE Connect between external clusters and Google. |
|
GKE Hub Cross Project Service Agent( Gives the GKE Hub service agent permission to manage the project for cross-project fleet registration. Warning: Do not grant service agent roles to any principals exceptservice agents. |
|
Fleet Editor (formerly GKE Hub Editor)( Edit access to Fleet resources. |
|
Connect Gateway Admin( Full access to Connect Gateway. |
|
Connect Gateway Editor( Edit access to Connect Gateway. |
|
Connect Gateway Reader( Read-only access to Connect Gateway. |
|
Fleet Scope Admin( Admin access to Fleet Scopes to set IAM Bindings and RBACRoleBindings. |
|
Fleet Scope Editor( Edit access to Namespaces under Fleet Scopes. |
|
Fleet Project-level Scope Editor( Role for project-level permissions for editor of Fleet Scopes. |
|
Fleet Scope Viewer( Viewer of Fleet Scopes and associated resources. |
|
Fleet Project-level Scope Viewer( Role for project-level permissions for viewer of Fleet Scopes. |
|
GKE Hub Service Agent( Gives the GKE Hub service agent access to Cloud Platform resources. Warning: Do not grant service agent roles to any principals exceptservice agents. |
|
Fleet Viewer (formerly GKE Hub Viewer)( Read-only access to Fleets and related resources. |
|
GKE Hub permissions
| Permission | Included in roles |
|---|---|
| Owner ( Velostrata Manager ( Velostrata Manager Connection Agent ( GKE Connect Agent ( Service agent roles Warning: Don't grant service agent roles to any principals exceptservice agents.
|
| Owner ( Editor ( Fleet Admin (formerly GKE Hub Admin) ( Fleet Editor (formerly GKE Hub Editor) ( Service agent roles Warning: Don't grant service agent roles to any principals exceptservice agents.
|
| Owner ( Editor ( Fleet Admin (formerly GKE Hub Admin) ( Fleet Editor (formerly GKE Hub Editor) ( Service agent roles Warning: Don't grant service agent roles to any principals exceptservice agents.
|
| Owner ( Editor ( Viewer ( Fleet Admin (formerly GKE Hub Admin) ( Fleet Editor (formerly GKE Hub Editor) ( Fleet Viewer (formerly GKE Hub Viewer) ( Support User ( Service agent roles Warning: Don't grant service agent roles to any principals exceptservice agents.
|
| Owner ( Editor ( Viewer ( Fleet Admin (formerly GKE Hub Admin) ( Fleet Editor (formerly GKE Hub Editor) ( Fleet Viewer (formerly GKE Hub Viewer) ( Security Admin ( Security Auditor ( Security Reviewer ( Support User ( Service agent roles Warning: Don't grant service agent roles to any principals exceptservice agents.
|
| Owner ( Editor ( Viewer ( Fleet Admin (formerly GKE Hub Admin) ( Fleet Editor (formerly GKE Hub Editor) ( Fleet Viewer (formerly GKE Hub Viewer) ( Security Admin ( Security Auditor ( Security Reviewer ( Support User ( Service agent roles Warning: Don't grant service agent roles to any principals exceptservice agents.
|
| Owner ( Fleet Admin (formerly GKE Hub Admin) ( Security Admin ( Service agent roles Warning: Don't grant service agent roles to any principals exceptservice agents.
|
| Owner ( Editor ( Fleet Admin (formerly GKE Hub Admin) ( Fleet Editor (formerly GKE Hub Editor) ( Service agent roles Warning: Don't grant service agent roles to any principals exceptservice agents.
|
| Owner ( Editor ( Fleet Admin (formerly GKE Hub Admin) ( Fleet Editor (formerly GKE Hub Editor) ( Service agent roles Warning: Don't grant service agent roles to any principals exceptservice agents.
|
| Owner ( Editor ( Fleet Admin (formerly GKE Hub Admin) ( Fleet Editor (formerly GKE Hub Editor) ( Service agent roles Warning: Don't grant service agent roles to any principals exceptservice agents.
|
| Owner ( Editor ( Fleet Admin (formerly GKE Hub Admin) ( Fleet Editor (formerly GKE Hub Editor) ( Service agent roles Warning: Don't grant service agent roles to any principals exceptservice agents.
|
| Owner ( Editor ( Viewer ( Fleet Admin (formerly GKE Hub Admin) ( Fleet Editor (formerly GKE Hub Editor) ( Fleet Viewer (formerly GKE Hub Viewer) ( Support User ( Service agent roles Warning: Don't grant service agent roles to any principals exceptservice agents.
|
| Owner ( Editor ( Viewer ( Fleet Admin (formerly GKE Hub Admin) ( Fleet Editor (formerly GKE Hub Editor) ( Fleet Viewer (formerly GKE Hub Viewer) ( Support User ( Service agent roles Warning: Don't grant service agent roles to any principals exceptservice agents.
|
| Owner ( Editor ( Fleet Admin (formerly GKE Hub Admin) ( Fleet Editor (formerly GKE Hub Editor) ( Service agent roles Warning: Don't grant service agent roles to any principals exceptservice agents.
|
| Owner ( Editor ( Fleet Admin (formerly GKE Hub Admin) ( Fleet Editor (formerly GKE Hub Editor) ( Service agent roles Warning: Don't grant service agent roles to any principals exceptservice agents.
|
| Owner ( Editor ( Connect Gateway Admin ( Connect Gateway Editor ( Fleet Project-level Scope Editor ( Service agent roles Warning: Don't grant service agent roles to any principals exceptservice agents.
|
| Owner ( Editor ( Viewer ( Connect Gateway Admin ( Connect Gateway Editor ( Connect Gateway Reader ( Fleet Project-level Scope Editor ( Fleet Project-level Scope Viewer ( Support User ( Service agent roles Warning: Don't grant service agent roles to any principals exceptservice agents.
|
| Owner ( Editor ( Viewer ( Connect Gateway Admin ( Connect Gateway Editor ( Connect Gateway Reader ( Fleet Project-level Scope Editor ( Fleet Project-level Scope Viewer ( Support User ( Service agent roles Warning: Don't grant service agent roles to any principals exceptservice agents.
|
| Owner ( Editor ( Connect Gateway Admin ( Connect Gateway Editor ( Fleet Project-level Scope Editor ( Service agent roles Warning: Don't grant service agent roles to any principals exceptservice agents.
|
| Owner ( Editor ( Connect Gateway Admin ( Connect Gateway Editor ( Fleet Project-level Scope Editor ( Service agent roles Warning: Don't grant service agent roles to any principals exceptservice agents.
|
| Owner ( Editor ( Connect Gateway Admin ( Connect Gateway Editor ( Fleet Project-level Scope Editor ( Service agent roles Warning: Don't grant service agent roles to any principals exceptservice agents.
|
| Owner ( Editor ( Connect Gateway Admin ( Service agent roles Warning: Don't grant service agent roles to any principals exceptservice agents.
|
| Owner ( Editor ( Viewer ( Fleet Admin (formerly GKE Hub Admin) ( Fleet Editor (formerly GKE Hub Editor) ( Fleet Viewer (formerly GKE Hub Viewer) ( Support User ( Service agent roles Warning: Don't grant service agent roles to any principals exceptservice agents.
|
| Owner ( Editor ( Viewer ( Fleet Admin (formerly GKE Hub Admin) ( Fleet Editor (formerly GKE Hub Editor) ( Fleet Viewer (formerly GKE Hub Viewer) ( Security Admin ( Security Auditor ( Security Reviewer ( Support User ( Service agent roles Warning: Don't grant service agent roles to any principals exceptservice agents.
|
| Owner ( Editor ( Fleet Admin (formerly GKE Hub Admin) ( Fleet Editor (formerly GKE Hub Editor) ( Service agent roles Warning: Don't grant service agent roles to any principals exceptservice agents.
|
| Owner ( Editor ( Fleet Admin (formerly GKE Hub Admin) ( Fleet Editor (formerly GKE Hub Editor) ( Service agent roles Warning: Don't grant service agent roles to any principals exceptservice agents.
|
| Owner ( Editor ( Viewer ( Fleet Admin (formerly GKE Hub Admin) ( Fleet Editor (formerly GKE Hub Editor) ( Fleet Viewer (formerly GKE Hub Viewer) ( Support User ( Service agent roles Warning: Don't grant service agent roles to any principals exceptservice agents.
|
| Owner ( Editor ( Viewer ( Fleet Admin (formerly GKE Hub Admin) ( Fleet Editor (formerly GKE Hub Editor) ( Fleet Viewer (formerly GKE Hub Viewer) ( Security Admin ( Security Auditor ( Security Reviewer ( Support User ( Service agent roles Warning: Don't grant service agent roles to any principals exceptservice agents.
|
| Owner ( Editor ( Fleet Admin (formerly GKE Hub Admin) ( Fleet Editor (formerly GKE Hub Editor) ( Service agent roles Warning: Don't grant service agent roles to any principals exceptservice agents.
|
| Owner ( Editor ( Fleet Admin (formerly GKE Hub Admin) ( Fleet Editor (formerly GKE Hub Editor) ( Service agent roles Warning: Don't grant service agent roles to any principals exceptservice agents.
|
| Owner ( Editor ( Fleet Admin (formerly GKE Hub Admin) ( Fleet Editor (formerly GKE Hub Editor) ( Service agent roles Warning: Don't grant service agent roles to any principals exceptservice agents.
|
| Owner ( Editor ( Viewer ( Fleet Admin (formerly GKE Hub Admin) ( Fleet Editor (formerly GKE Hub Editor) ( Fleet Viewer (formerly GKE Hub Viewer) ( Support User ( Service agent roles Warning: Don't grant service agent roles to any principals exceptservice agents.
|
| Owner ( Editor ( Viewer ( Fleet Admin (formerly GKE Hub Admin) ( Fleet Editor (formerly GKE Hub Editor) ( Fleet Viewer (formerly GKE Hub Viewer) ( Security Admin ( Security Auditor ( Security Reviewer ( Support User ( Service agent roles Warning: Don't grant service agent roles to any principals exceptservice agents.
|
| Owner ( Editor ( Fleet Admin (formerly GKE Hub Admin) ( Fleet Editor (formerly GKE Hub Editor) ( Service agent roles Warning: Don't grant service agent roles to any principals exceptservice agents.
|
| Owner ( Editor ( Fleet Admin (formerly GKE Hub Admin) ( Fleet Editor (formerly GKE Hub Editor) ( Service agent roles Warning: Don't grant service agent roles to any principals exceptservice agents.
|
| Owner ( Editor ( Fleet Admin (formerly GKE Hub Admin) ( Fleet Editor (formerly GKE Hub Editor) ( Service agent roles Warning: Don't grant service agent roles to any principals exceptservice agents.
|
| Owner ( Editor ( Viewer ( Fleet Admin (formerly GKE Hub Admin) ( Fleet Editor (formerly GKE Hub Editor) ( Fleet Viewer (formerly GKE Hub Viewer) ( Support User ( Service agent roles Warning: Don't grant service agent roles to any principals exceptservice agents.
|
| Owner ( Editor ( Viewer ( Fleet Admin (formerly GKE Hub Admin) ( Fleet Editor (formerly GKE Hub Editor) ( Connect Gateway Admin ( Connect Gateway Editor ( Connect Gateway Reader ( Fleet Project-level Scope Editor ( Fleet Project-level Scope Viewer ( Fleet Viewer (formerly GKE Hub Viewer) ( Support User ( Service agent roles Warning: Don't grant service agent roles to any principals exceptservice agents.
|
| Owner ( Editor ( Viewer ( Fleet Admin (formerly GKE Hub Admin) ( Fleet Editor (formerly GKE Hub Editor) ( Fleet Viewer (formerly GKE Hub Viewer) ( Security Admin ( Security Auditor ( Security Reviewer ( Support User ( Service agent roles Warning: Don't grant service agent roles to any principals exceptservice agents.
|
| Owner ( Editor ( Viewer ( Fleet Admin (formerly GKE Hub Admin) ( Fleet Editor (formerly GKE Hub Editor) ( Fleet Viewer (formerly GKE Hub Viewer) ( Security Admin ( Security Auditor ( Security Reviewer ( Support User ( Service agent roles Warning: Don't grant service agent roles to any principals exceptservice agents.
|
| Owner ( Fleet Admin (formerly GKE Hub Admin) ( Security Admin ( Service agent roles Warning: Don't grant service agent roles to any principals exceptservice agents.
|
| Owner ( Editor ( Fleet Admin (formerly GKE Hub Admin) ( Fleet Editor (formerly GKE Hub Editor) ( Service agent roles Warning: Don't grant service agent roles to any principals exceptservice agents.
|
| Owner ( Editor ( Fleet Admin (formerly GKE Hub Admin) ( Fleet Editor (formerly GKE Hub Editor) ( Fleet Scope Admin ( Fleet Scope Editor ( Service agent roles Warning: Don't grant service agent roles to any principals exceptservice agents.
|
| Owner ( Editor ( Fleet Admin (formerly GKE Hub Admin) ( Fleet Editor (formerly GKE Hub Editor) ( Fleet Scope Admin ( Fleet Scope Editor ( Service agent roles Warning: Don't grant service agent roles to any principals exceptservice agents.
|
| Owner ( Editor ( Viewer ( Fleet Admin (formerly GKE Hub Admin) ( Fleet Editor (formerly GKE Hub Editor) ( Fleet Scope Admin ( Fleet Scope Editor ( Fleet Scope Viewer ( Fleet Viewer (formerly GKE Hub Viewer) ( Support User ( Service agent roles Warning: Don't grant service agent roles to any principals exceptservice agents.
|
| Owner ( Editor ( Viewer ( Fleet Admin (formerly GKE Hub Admin) ( Fleet Editor (formerly GKE Hub Editor) ( Fleet Scope Admin ( Fleet Scope Editor ( Fleet Scope Viewer ( Fleet Viewer (formerly GKE Hub Viewer) ( Security Admin ( Security Auditor ( Security Reviewer ( Support User ( Service agent roles Warning: Don't grant service agent roles to any principals exceptservice agents.
|
| Owner ( Editor ( Fleet Admin (formerly GKE Hub Admin) ( Fleet Editor (formerly GKE Hub Editor) ( Service agent roles Warning: Don't grant service agent roles to any principals exceptservice agents.
|
| Owner ( Editor ( Fleet Admin (formerly GKE Hub Admin) ( Fleet Editor (formerly GKE Hub Editor) ( Service agent roles Warning: Don't grant service agent roles to any principals exceptservice agents.
|
| Owner ( Editor ( Fleet Admin (formerly GKE Hub Admin) ( Fleet Editor (formerly GKE Hub Editor) ( Service agent roles Warning: Don't grant service agent roles to any principals exceptservice agents.
|
| Owner ( Editor ( Viewer ( Fleet Admin (formerly GKE Hub Admin) ( Fleet Editor (formerly GKE Hub Editor) ( Fleet Project-level Scope Editor ( Fleet Viewer (formerly GKE Hub Viewer) ( Support User ( Service agent roles Warning: Don't grant service agent roles to any principals exceptservice agents.
|
| Owner ( Editor ( Viewer ( Fleet Admin (formerly GKE Hub Admin) ( Fleet Editor (formerly GKE Hub Editor) ( Fleet Viewer (formerly GKE Hub Viewer) ( Security Admin ( Security Auditor ( Security Reviewer ( Support User ( Service agent roles Warning: Don't grant service agent roles to any principals exceptservice agents.
|
| Owner ( Editor ( Fleet Admin (formerly GKE Hub Admin) ( Fleet Editor (formerly GKE Hub Editor) ( Fleet Scope Admin ( Service agent roles Warning: Don't grant service agent roles to any principals exceptservice agents.
|
| Owner ( Editor ( Fleet Admin (formerly GKE Hub Admin) ( Fleet Editor (formerly GKE Hub Editor) ( Fleet Scope Admin ( Service agent roles Warning: Don't grant service agent roles to any principals exceptservice agents.
|
| Owner ( Editor ( Viewer ( Fleet Admin (formerly GKE Hub Admin) ( Fleet Editor (formerly GKE Hub Editor) ( Fleet Scope Admin ( Fleet Scope Editor ( Fleet Scope Viewer ( Fleet Viewer (formerly GKE Hub Viewer) ( Support User ( Service agent roles Warning: Don't grant service agent roles to any principals exceptservice agents.
|
| Owner ( Editor ( Viewer ( Fleet Admin (formerly GKE Hub Admin) ( Fleet Editor (formerly GKE Hub Editor) ( Fleet Scope Admin ( Fleet Scope Editor ( Fleet Scope Viewer ( Fleet Viewer (formerly GKE Hub Viewer) ( Security Admin ( Security Auditor ( Security Reviewer ( Support User ( Service agent roles Warning: Don't grant service agent roles to any principals exceptservice agents.
|
| Owner ( Editor ( Fleet Admin (formerly GKE Hub Admin) ( Fleet Editor (formerly GKE Hub Editor) ( Fleet Scope Admin ( Service agent roles Warning: Don't grant service agent roles to any principals exceptservice agents.
|
| Owner ( Editor ( Fleet Admin (formerly GKE Hub Admin) ( Fleet Editor (formerly GKE Hub Editor) ( Service agent roles Warning: Don't grant service agent roles to any principals exceptservice agents.
|
| Owner ( Editor ( Fleet Admin (formerly GKE Hub Admin) ( Fleet Editor (formerly GKE Hub Editor) ( Service agent roles Warning: Don't grant service agent roles to any principals exceptservice agents.
|
| Owner ( Editor ( Viewer ( Fleet Admin (formerly GKE Hub Admin) ( Fleet Editor (formerly GKE Hub Editor) ( Fleet Scope Admin ( Fleet Scope Editor ( Fleet Scope Viewer ( Fleet Viewer (formerly GKE Hub Viewer) ( Support User ( Service agent roles Warning: Don't grant service agent roles to any principals exceptservice agents.
|
| Owner ( Editor ( Viewer ( Fleet Admin (formerly GKE Hub Admin) ( Fleet Editor (formerly GKE Hub Editor) ( Fleet Scope Admin ( Fleet Scope Editor ( Fleet Scope Viewer ( Security Admin ( Security Auditor ( Security Reviewer ( Support User ( Service agent roles Warning: Don't grant service agent roles to any principals exceptservice agents.
|
| Owner ( Editor ( Viewer ( Fleet Admin (formerly GKE Hub Admin) ( Fleet Editor (formerly GKE Hub Editor) ( Fleet Viewer (formerly GKE Hub Viewer) ( Security Admin ( Security Auditor ( Security Reviewer ( Support User ( Service agent roles Warning: Don't grant service agent roles to any principals exceptservice agents.
|
| Owner ( Editor ( Viewer ( Fleet Admin (formerly GKE Hub Admin) ( Fleet Editor (formerly GKE Hub Editor) ( Fleet Scope Admin ( Fleet Scope Editor ( Fleet Scope Viewer ( Fleet Viewer (formerly GKE Hub Viewer) ( Support User ( Service agent roles Warning: Don't grant service agent roles to any principals exceptservice agents.
|
| Owner ( Fleet Admin (formerly GKE Hub Admin) ( Fleet Scope Admin ( Security Admin ( |
| Owner ( Editor ( Fleet Admin (formerly GKE Hub Admin) ( Fleet Editor (formerly GKE Hub Editor) ( Service agent roles Warning: Don't grant service agent roles to any principals exceptservice agents.
|
Except as otherwise noted, the content of this page is licensed under theCreative Commons Attribution 4.0 License, and code samples are licensed under theApache 2.0 License. For details, see theGoogle Developers Site Policies. Java is a registered trademark of Oracle and/or its affiliates.
Last updated 2025-12-15 UTC.