App Hub IAM roles and permissions
Stay organized with collections
Save and categorize content based on your preferences.
App Hub provides the following Identity and Access Management (IAM) roles:
- App Hub Admin (
roles/apphub.admin): get full access to App Hub settings. - App Hub Editor (
roles/apphub.editor): create and manage applications, services, and workloads. - App Hub Viewer (
roles/apphub.viewer): view applications, services, and workloads.
Grant appropriate App Hub IAM roles to users or groups who will manage or view applications within the application management boundary. To grant roles, you can use the IAM page in the Google Cloud console or the Google Cloud CLI. For detailed instructions, see Manage access to projects, folders, and organizations.
App Hub roles
The following table describes App Hub IAM roles and their typical responsibilities:
Role |
Description |
Purpose |
|---|---|---|
App Hub Admin |
Use projects or folders to create applications, attach service projects to a host project, update application attributes, register services and workloads, update service and workload attributes, and delegate application control to the App Hub Editor. |
|
App Hub Editor |
Create and update applications, register and unregister services and workloads, and update attributes. |
|
App Hub Viewer |
View services, workloads, applications, and their attributes. |
|
App Hub permissions
The following table lists the permissions that each App Hub IAM role has:
App Hub Admin
(roles/)
Full access to App Hub resources.
apphub.*
apphub.applications.createapphub.applications.deleteapphub.applications.getapphub.applications. getIamPolicy apphub.applications.listapphub.applications. setIamPolicy apphub.applications.updateapphub.boundaries.attachapphub.boundaries.getapphub.boundaries.updateapphub.discoveredServices.getapphub.discoveredServices.listapphub.discoveredServices. register apphub.discoveredWorkloads.getapphub.discoveredWorkloads. list apphub.discoveredWorkloads. register apphub.extendedMetadataSchemas. get apphub.extendedMetadataSchemas. list apphub.locations.getapphub.locations.listapphub.operations.cancelapphub.operations.deleteapphub.operations.getapphub.operations.listapphub.serviceProjectAttachments. attach apphub.serviceProjectAttachments. create apphub.serviceProjectAttachments. delete apphub.serviceProjectAttachments. detach apphub.serviceProjectAttachments. get apphub.serviceProjectAttachments. list apphub.serviceProjectAttachments. lookup apphub.services.createapphub.services.deleteapphub.services.getapphub.services.listapphub.services.updateapphub.workloads.createapphub.workloads.deleteapphub.workloads.getapphub.workloads.listapphub.workloads.update
resourcemanager.projects.get
resourcemanager.projects.list
App Hub Editor
(roles/)
Edit access to App Hub resources.
apphub.applications.create
apphub.applications.delete
apphub.applications.get
apphub.applications.list
apphub.applications.update
apphub.boundaries.get
apphub.discoveredServices.*
apphub.discoveredServices.getapphub.discoveredServices.listapphub.discoveredServices. register
apphub.discoveredWorkloads.*
apphub.discoveredWorkloads.getapphub.discoveredWorkloads. list apphub.discoveredWorkloads. register
apphub.
apphub.extendedMetadataSchemas. get apphub.extendedMetadataSchemas. list
apphub.locations.*
apphub.locations.getapphub.locations.list
apphub.operations.*
apphub.operations.cancelapphub.operations.deleteapphub.operations.getapphub.operations.list
apphub.
apphub.services.*
apphub.services.createapphub.services.deleteapphub.services.getapphub.services.listapphub.services.update
apphub.workloads.*
apphub.workloads.createapphub.workloads.deleteapphub.workloads.getapphub.workloads.listapphub.workloads.update
resourcemanager.projects.get
resourcemanager.projects.list
App Hub Viewer
(roles/)
View access to App Hub resources.
apphub.applications.get
apphub.applications.list
apphub.boundaries.get
apphub.discoveredServices.get
apphub.discoveredServices.list
apphub.discoveredWorkloads.get
apphub.
apphub.
apphub.extendedMetadataSchemas. get apphub.extendedMetadataSchemas. list
apphub.locations.*
apphub.locations.getapphub.locations.list
apphub.operations.get
apphub.operations.list
apphub.
apphub.services.get
apphub.services.list
apphub.workloads.get
apphub.workloads.list
resourcemanager.projects.get
resourcemanager.projects.list
For more information about IAM permissions, see Find the right predefined roles and IAM roles and permissions index.