Knative serving roles and permissions

This page lists the IAM roles and permissions for Knative serving. To search through all roles and permissions, see the role and permission index.

Knative serving roles

Knative serving offers the following service agent roles. Service agent roles should only be granted to service agents.

Role Permissions

KubeRun Events Control Plane Service Agent

(roles/kuberun.eventsControlPlaneServiceAgent)

Service account role used to setup authentication for the control plane used by KubeRun Events.

cloudscheduler.jobs.create

cloudscheduler.jobs.delete

cloudscheduler.jobs.get

logging.sinks.create

logging.sinks.delete

logging.sinks.get

pubsub.subscriptions.create

pubsub.subscriptions.delete

pubsub.subscriptions.get

pubsub.topics.attachSubscription

pubsub.topics.create

pubsub.topics.delete

pubsub.topics.get

pubsub.topics.getIamPolicy

pubsub.topics.setIamPolicy

resourcemanager.projects.get

storage.buckets.get

storage.buckets.update

KubeRun Events Data Plane Service Agent

(roles/kuberun.eventsDataPlaneServiceAgent)

Service account role used to setup authentication for the data plane used by KubeRun Events.

cloudtrace.traces.patch

monitoring.timeSeries.create

pubsub.subscriptions.consume

pubsub.subscriptions.get

pubsub.topics.get

pubsub.topics.publish

resourcemanager.projects.get

Knative serving permissions

There are no IAM permissions for this service.

Except as otherwise noted, the content of this page is licensed under the Creative Commons Attribution 4.0 License, and code samples are licensed under the Apache 2.0 License. For details, see the Google Developers Site Policies. Java is a registered trademark of Oracle and/or its affiliates.

Last updated 2026年08月28日 UTC.