Controllare l'accesso alla console di gestione dell'appliance con IAM

Questa pagina descrive i ruoli e le autorizzazioni IAM richiesti per Google Cloud Backup e RE. Quando aggiungi nuove entità al progetto, puoi utilizzare una policy Identity and Access Management (IAM) per assegnare all'entità uno o più ruoli IAM. Ogni ruolo IAM contiene autorizzazioni che concedono alle entità l'accesso per eseguire azioni specifiche su risorse specifiche. Per un elenco di riferimento delle autorizzazioni IAM che si applicano a Backup e RE, vedi Autorizzazioni IAM per Backup e DR.

In che modo IAM controlla l'accesso

Se un'entità (un utente, un gruppo o un account di servizio) chiama un' Google Cloud API, deve disporre delle autorizzazioni IAM appropriate per utilizzare la risorsa. Per concedere a un'entità le autorizzazioni richieste, devi assegnarle un ruolo IAM. Scopri di più sulle entità in IAM.

Tipi di ruoli IAM

Backup e RE hanno ruoli predefiniti che sono autorizzazioni raggruppate da assegnare a diverse entità. Gli utenti possono anche definire ruoli personalizzati che possono avere una combinazione di singole autorizzazioni per concedere l'accesso all'esecuzione di un'azione o di un flusso di lavoro specifico di Backup e DR.

Autorizzazioni IAM

Le autorizzazioni consentono agli utenti di eseguire azioni specifiche su risorse specifiche. Possono essere raggruppate per formare i ruoli. Ogni autorizzazione si riferisce a un'azione specifica che l'utente può eseguire o a un accesso di cui dispone.

Autorizzazioni a livello di progetto e di risorsa

Le autorizzazioni possono essere concesse a livello di progetto o di risorsa. Ad esempio, un amministratore di Backup e RE può scegliere di concedere solo determinate autorizzazioni a livello di bucket di archiviazione anziché all'intero progetto, a seconda della sua policy. La concessione di ruoli a livello di risorsa non influisce sui ruoli esistenti concessi a livello di progetto e viceversa.

Ruoli IAM predefiniti per Backup e RE

Backup e RE dispongono di un insieme di ruoli IAM predefiniti, descritti su questa pagina. Puoi anche creare ruoli personalizzati che contengono sottoinsiemi di autorizzazioni che corrispondono direttamente alle tue esigenze.

La tabella seguente descrive i ruoli IAM associati a Backup e RE ed elenca le autorizzazioni contenute in ogni ruolo. La descrizione di ogni autorizzazione è riportata nella sezione Autorizzazioni IAM per Backup e DR.

Role Permissions

(roles/backupdr.admin)

Provides full access to all Backup and DR resources.

backupdr.appliedAutoProtectionPolicies.*

  • backupdr.appliedAutoProtectionPolicies.authorize
  • backupdr.appliedAutoProtectionPolicies.list
  • backupdr.appliedAutoProtectionPolicies.viewMatchingResources

backupdr.autoProtectionBindings.*

  • backupdr.autoProtectionBindings.create
  • backupdr.autoProtectionBindings.delete
  • backupdr.autoProtectionBindings.get
  • backupdr.autoProtectionBindings.list

backupdr.autoProtectionPolicies.*

  • backupdr.autoProtectionPolicies.create
  • backupdr.autoProtectionPolicies.delete
  • backupdr.autoProtectionPolicies.get
  • backupdr.autoProtectionPolicies.list
  • backupdr.autoProtectionPolicies.update

backupdr.backupPlanAssociations.*

  • backupdr.backupPlanAssociations.createForAlloydbCluster
  • backupdr.backupPlanAssociations.createForCloudSqlInstance
  • backupdr.backupPlanAssociations.createForComputeDisk
  • backupdr.backupPlanAssociations.createForComputeInstance
  • backupdr.backupPlanAssociations.createForFilestoreInstance
  • backupdr.backupPlanAssociations.deleteForAlloydbCluster
  • backupdr.backupPlanAssociations.deleteForCloudSqlInstance
  • backupdr.backupPlanAssociations.deleteForComputeDisk
  • backupdr.backupPlanAssociations.deleteForComputeInstance
  • backupdr.backupPlanAssociations.deleteForFilestoreInstance
  • backupdr.backupPlanAssociations.fetchForAlloydbCluster
  • backupdr.backupPlanAssociations.fetchForCloudSqlInstance
  • backupdr.backupPlanAssociations.fetchForComputeDisk
  • backupdr.backupPlanAssociations.fetchForComputeInstance
  • backupdr.backupPlanAssociations.fetchForFilestoreInstance
  • backupdr.backupPlanAssociations.getForAlloydbCluster
  • backupdr.backupPlanAssociations.getForCloudSqlInstance
  • backupdr.backupPlanAssociations.getForComputeDisk
  • backupdr.backupPlanAssociations.getForComputeInstance
  • backupdr.backupPlanAssociations.getForFilestoreInstance
  • backupdr.backupPlanAssociations.list
  • backupdr.backupPlanAssociations.triggerBackupForAlloydbCluster
  • backupdr.backupPlanAssociations.triggerBackupForCloudSqlInstance
  • backupdr.backupPlanAssociations.triggerBackupForComputeDisk
  • backupdr.backupPlanAssociations.triggerBackupForComputeInstance
  • backupdr.backupPlanAssociations.triggerBackupForFilestoreInstance
  • backupdr.backupPlanAssociations.updateForAlloydbCluster
  • backupdr.backupPlanAssociations.updateForCloudSqlInstance
  • backupdr.backupPlanAssociations.updateForComputeDisk
  • backupdr.backupPlanAssociations.updateForComputeInstance
  • backupdr.backupPlanAssociations.updateForFilestoreInstance

backupdr.backupPlanRevisions.*

  • backupdr.backupPlanRevisions.get
  • backupdr.backupPlanRevisions.list

backupdr.backupPlans.*

  • backupdr.backupPlans.create
  • backupdr.backupPlans.delete
  • backupdr.backupPlans.get
  • backupdr.backupPlans.list
  • backupdr.backupPlans.update
  • backupdr.backupPlans.useForAlloydbCluster
  • backupdr.backupPlans.useForCloudSqlInstance
  • backupdr.backupPlans.useForComputeDisk
  • backupdr.backupPlans.useForComputeInstance
  • backupdr.backupPlans.useForFilestoreInstance

backupdr.backupVaults.*

  • backupdr.backupVaults.associate
  • backupdr.backupVaults.create
  • backupdr.backupVaults.createTagBinding
  • backupdr.backupVaults.delete
  • backupdr.backupVaults.deleteTagBinding
  • backupdr.backupVaults.get
  • backupdr.backupVaults.list
  • backupdr.backupVaults.listEffectiveTags
  • backupdr.backupVaults.listTagBindings
  • backupdr.backupVaults.update

backupdr.bindingMatchingResources.list

backupdr.bvbackups.*

  • backupdr.bvbackups.delete
  • backupdr.bvbackups.fetchForCloudSqlInstance
  • backupdr.bvbackups.fetchForComputeDisk
  • backupdr.bvbackups.fetchForComputeInstance
  • backupdr.bvbackups.get
  • backupdr.bvbackups.list
  • backupdr.bvbackups.restore
  • backupdr.bvbackups.update
  • backupdr.bvbackups.useReadOnlyForAlloydbCluster
  • backupdr.bvbackups.useReadOnlyForCloudSqlInstance
  • backupdr.bvbackups.useReadOnlyForFilestoreInstance

backupdr.bvdataSources.*

  • backupdr.bvdataSources.abandonBackup
  • backupdr.bvdataSources.fetchAccessToken
  • backupdr.bvdataSources.finalizeBackup
  • backupdr.bvdataSources.get
  • backupdr.bvdataSources.initiateBackup
  • backupdr.bvdataSources.list
  • backupdr.bvdataSources.remove
  • backupdr.bvdataSources.setInternalStatus
  • backupdr.bvdataSources.update
  • backupdr.bvdataSources.useReadOnlyForAlloydbCluster
  • backupdr.bvdataSources.useReadOnlyForCloudSqlInstance

backupdr.compute.restoreFromBackupVault

backupdr.dataSourceReferences.*

  • backupdr.dataSourceReferences.fetchForAlloydbCluster
  • backupdr.dataSourceReferences.fetchForCloudSqlInstance
  • backupdr.dataSourceReferences.fetchForFilestoreInstance
  • backupdr.dataSourceReferences.getForAlloydbCluster
  • backupdr.dataSourceReferences.getForCloudSqlInstance
  • backupdr.dataSourceReferences.getForFilestoreInstance
  • backupdr.dataSourceReferences.list

backupdr.locations.*

  • backupdr.locations.get
  • backupdr.locations.list

backupdr.managementServers.*

  • backupdr.managementServers.access
  • backupdr.managementServers.accessSensitiveData
  • backupdr.managementServers.assignBackupPlans
  • backupdr.managementServers.backupAccess
  • backupdr.managementServers.create
  • backupdr.managementServers.createConnection
  • backupdr.managementServers.createDynamicProtection
  • backupdr.managementServers.createTagBinding
  • backupdr.managementServers.delete
  • backupdr.managementServers.deleteDynamicProtection
  • backupdr.managementServers.deleteTagBinding
  • backupdr.managementServers.get
  • backupdr.managementServers.getDynamicProtection
  • backupdr.managementServers.getIamPolicy
  • backupdr.managementServers.list
  • backupdr.managementServers.listDynamicProtection
  • backupdr.managementServers.listEffectiveTags
  • backupdr.managementServers.listTagBindings
  • backupdr.managementServers.manageApplications
  • backupdr.managementServers.manageBackupPlans
  • backupdr.managementServers.manageBackupServers
  • backupdr.managementServers.manageBackups
  • backupdr.managementServers.manageClones
  • backupdr.managementServers.manageExpiration
  • backupdr.managementServers.manageHosts
  • backupdr.managementServers.manageInternalACL
  • backupdr.managementServers.manageJobs
  • backupdr.managementServers.manageLiveClones
  • backupdr.managementServers.manageMigrations
  • backupdr.managementServers.manageMirroring
  • backupdr.managementServers.manageMounts
  • backupdr.managementServers.manageRestores
  • backupdr.managementServers.manageSensitiveData
  • backupdr.managementServers.manageStorage
  • backupdr.managementServers.manageSystem
  • backupdr.managementServers.manageWorkflows
  • backupdr.managementServers.refreshWorkflows
  • backupdr.managementServers.runWorkflows
  • backupdr.managementServers.setIamPolicy
  • backupdr.managementServers.testFailOvers
  • backupdr.managementServers.viewBackupPlans
  • backupdr.managementServers.viewBackupServers
  • backupdr.managementServers.viewReports
  • backupdr.managementServers.viewStorage
  • backupdr.managementServers.viewSystem
  • backupdr.managementServers.viewWorkflows

backupdr.operations.*

  • backupdr.operations.cancel
  • backupdr.operations.delete
  • backupdr.operations.get
  • backupdr.operations.list

backupdr.serviceConfig.initialize

backupdr.trial.*

  • backupdr.trial.end
  • backupdr.trial.get
  • backupdr.trial.subscribe

cloudkms.keyHandles.*

  • cloudkms.keyHandles.create
  • cloudkms.keyHandles.get
  • cloudkms.keyHandles.list

cloudkms.operations.get

cloudkms.projects.showEffectiveAutokeyConfig

resourcemanager.projects.get

resourcemanager.projects.list

(roles/backupdr.editor)

Editor role for backupdr

backupdr.appliedAutoProtectionPolicies.*

  • backupdr.appliedAutoProtectionPolicies.authorize
  • backupdr.appliedAutoProtectionPolicies.list
  • backupdr.appliedAutoProtectionPolicies.viewMatchingResources

backupdr.autoProtectionBindings.*

  • backupdr.autoProtectionBindings.create
  • backupdr.autoProtectionBindings.delete
  • backupdr.autoProtectionBindings.get
  • backupdr.autoProtectionBindings.list

backupdr.autoProtectionPolicies.*

  • backupdr.