cloudsql.backupRuns.create
Owner (roles/ owner)
Editor (roles/ editor)
Cloud SQL Admin (roles/ cloudsql.admin)
Cloud SQL Editor (roles/ cloudsql.editor)
Databases Admin (roles/ iam.databasesAdmin)
Dev Ops (roles/ iam.devOps)
Service agent roles
Warning: Don't grant service agent roles to any principals except service agents .
cloudsql.backupRuns.delete
Owner (roles/ owner)
Editor (roles/ editor)
Cloud SQL Admin (roles/ cloudsql.admin)
Databases Admin (roles/ iam.databasesAdmin)
Service agent roles
Warning: Don't grant service agent roles to any principals except service agents .
cloudsql.backupRuns.export
Owner (roles/ owner)
Editor (roles/ editor)
Viewer (roles/ viewer)
Cloud SQL Admin (roles/ cloudsql.admin)
Cloud SQL Editor (roles/ cloudsql.editor)
Cloud SQL Viewer (roles/ cloudsql.viewer)
Databases Admin (roles/ iam.databasesAdmin)
Dev Ops (roles/ iam.devOps)
Security Auditor (roles/ iam.securityAuditor)
Site Reliability Engineer (roles/ iam.siteReliabilityEngineer)
Support User (roles/ iam.supportUser)
Service agent roles
Warning: Don't grant service agent roles to any principals except service agents .
cloudsql.backupRuns.get
Owner (roles/ owner)
Editor (roles/ editor)
Viewer (roles/ viewer)
Cloud SQL Admin (roles/ cloudsql.admin)
Cloud SQL Editor (roles/ cloudsql.editor)
Cloud SQL Viewer (roles/ cloudsql.viewer)
Databases Admin (roles/ iam.databasesAdmin)
Dev Ops (roles/ iam.devOps)
Security Auditor (roles/ iam.securityAuditor)
Site Reliability Engineer (roles/ iam.siteReliabilityEngineer)
Support User (roles/ iam.supportUser)
Service agent roles
Warning: Don't grant service agent roles to any principals except service agents .
cloudsql.backupRuns.list
Owner (roles/ owner)
Editor (roles/ editor)
Viewer (roles/ viewer)
Cloud SQL Admin (roles/ cloudsql.admin)
Cloud SQL Editor (roles/ cloudsql.editor)
Cloud SQL Viewer (roles/ cloudsql.viewer)
Databases Admin (roles/ iam.databasesAdmin)
Dev Ops (roles/ iam.devOps)
Security Admin (roles/ iam.securityAdmin)
Security Auditor (roles/ iam.securityAuditor)
Security Reviewer (roles/ iam.securityReviewer)
Site Reliability Engineer (roles/ iam.siteReliabilityEngineer)
Support User (roles/ iam.supportUser)
Service agent roles
Warning: Don't grant service agent roles to any principals except service agents .
cloudsql.backupRuns.update
Owner (roles/ owner)
Editor (roles/ editor)
Cloud SQL Admin (roles/ cloudsql.admin)
Cloud SQL Editor (roles/ cloudsql.editor)
Databases Admin (roles/ iam.databasesAdmin)
Dev Ops (roles/ iam.devOps)
Service agent roles
Warning: Don't grant service agent roles to any principals except service agents .
cloudsql.databases.create
Owner (roles/ owner)
Editor (roles/ editor)
Cloud SQL Admin (roles/ cloudsql.admin)
Cloud SQL Editor (roles/ cloudsql.editor)
Databases Admin (roles/ iam.databasesAdmin)
Dev Ops (roles/ iam.devOps)
Service agent roles
Warning: Don't grant service agent roles to any principals except service agents .
cloudsql.databases.delete
Owner (roles/ owner)
Editor (roles/ editor)
Cloud SQL Admin (roles/ cloudsql.admin)
Databases Admin (roles/ iam.databasesAdmin)
Service agent roles
Warning: Don't grant service agent roles to any principals except service agents .
cloudsql.databases.get
Owner (roles/ owner)
Editor (roles/ editor)
Viewer (roles/ viewer)
Cloud SQL Admin (roles/ cloudsql.admin)
Cloud SQL Editor (roles/ cloudsql.editor)
Cloud SQL Viewer (roles/ cloudsql.viewer)
Databases Admin (roles/ iam.databasesAdmin)
Dev Ops (roles/ iam.devOps)
Security Auditor (roles/ iam.securityAuditor)
Site Reliability Engineer (roles/ iam.siteReliabilityEngineer)
Support User (roles/ iam.supportUser)
Service agent roles
Warning: Don't grant service agent roles to any principals except service agents .
cloudsql.databases.list
Owner (roles/ owner)
Editor (roles/ editor)
Viewer (roles/ viewer)
Cloud SQL Admin (roles/ cloudsql.admin)
Cloud SQL Editor (roles/ cloudsql.editor)
Cloud SQL Studio User (roles/ cloudsql.studioUser)
Cloud SQL Viewer (roles/ cloudsql.viewer)
Data Scientist (roles/ iam.dataScientist)
Databases Admin (roles/ iam.databasesAdmin)
Dev Ops (roles/ iam.devOps)
Security Admin (roles/ iam.securityAdmin)
Security Auditor (roles/ iam.securityAuditor)
Security Reviewer (roles/ iam.securityReviewer)
Site Reliability Engineer (roles/ iam.siteReliabilityEngineer)
Support User (roles/ iam.supportUser)
Service agent roles
Warning: Don't grant service agent roles to any principals except service agents .
cloudsql.databases.update
Owner (roles/ owner)
Editor (roles/ editor)
Cloud SQL Admin (roles/ cloudsql.admin)
Cloud SQL Editor (roles/ cloudsql.editor)
Databases Admin (roles/ iam.databasesAdmin)
Dev Ops (roles/ iam.devOps)
Service agent roles
Warning: Don't grant service agent roles to any principals except service agents .
cloudsql.instances.addServerCa
Owner (roles/ owner)
Editor (roles/ editor)
Cloud SQL Admin (roles/ cloudsql.admin)
Cloud SQL Editor (roles/ cloudsql.editor)
Databases Admin (roles/ iam.databasesAdmin)
Dev Ops (roles/ iam.devOps)
Service agent roles
Warning: Don't grant service agent roles to any principals except service agents .
cloudsql. instances. addServerCertificate
Owner (roles/ owner)
Editor (roles/ editor)
Cloud SQL Admin (roles/ cloudsql.admin)
Cloud SQL Editor (roles/ cloudsql.editor)
Databases Admin (roles/ iam.databasesAdmin)
Dev Ops (roles/ iam.devOps)
Service agent roles
Warning: Don't grant service agent roles to any principals except service agents .
cloudsql.instances.clone
Owner (roles/ owner)
Editor (roles/ editor)
Cloud SQL Admin (roles/ cloudsql.admin)
Databases Admin (roles/ iam.databasesAdmin)
Service agent roles
Warning: Don't grant service agent roles to any principals except service agents .
cloudsql.instances.connect
Owner (roles/ owner)
Editor (roles/ editor)
Cloud SQL Admin (roles/ cloudsql.admin)
Cloud SQL Client (roles/ cloudsql.client)
Cloud SQL Editor (roles/ cloudsql.editor)
DLP Organization Data Profiles Driver (roles/ dlp.orgdriver)
DLP Project Data Profiles Driver (roles/ dlp.projectdriver)
Data Scientist (roles/ iam.dataScientist)
Databases Admin (roles/ iam.databasesAdmin)
Dev Ops (roles/ iam.devOps)
Dataproc Metastore Managed Migration Admin (roles/ metastore.migrationAdmin)
Service agent roles
Warning: Don't grant service agent roles to any principals except service agents .
cloudsql.instances.create
Owner (roles/ owner)
Editor (roles/ editor)
Cloud SQL Admin (roles/ cloudsql.admin)
Databases Admin (roles/ iam.databasesAdmin)
Service agent roles
Warning: Don't grant service agent roles to any principals except service agents .
cloudsql. instances. createBackupDrBackup
Owner (roles/ owner)
Editor (roles/ editor)
Viewer (roles/ viewer)
Backup and DR Cloud SQL Operator (roles/ backupdr.cloudSqlOperator)
Cloud SQL Admin (roles/ cloudsql.admin)
Databases Admin (roles/ iam.databasesAdmin)
Support User (roles/ iam.supportUser)
Service agent roles
Warning: Don't grant service agent roles to any principals except service agents .
cloudsql. instances. createTagBinding
Owner (roles/ owner)
Cloud SQL Admin (roles/ cloudsql.admin)
DLP Organization Data Profiles Driver (roles/ dlp.orgdriver)
DLP Project Data Profiles Driver (roles/ dlp.projectdriver)
Databases Admin (roles/ iam.databasesAdmin)
Tag User (roles/ resourcemanager.tagUser)
Service agent roles
Warning: Don't grant service agent roles to any principals except service agents .
cloudsql.instances.delete
Owner (roles/ owner)
Editor (roles/ editor)
Cloud SQL Admin (roles/ cloudsql.admin)
Databases Admin (roles/ iam.databasesAdmin)
Service agent roles
Warning: Don't grant service agent roles to any principals except service agents .
cloudsql. instances. deleteTagBinding
Owner (roles/ owner)
Cloud SQL Admin (roles/ cloudsql.admin)
DLP Organization Data Profiles Driver (roles/ dlp.orgdriver)
DLP Project Data Profiles Driver (roles/ dlp.projectdriver)
Databases Admin (roles/ iam.databasesAdmin)
Tag User (roles/ resourcemanager.tagUser)
Service agent roles
Warning: Don't grant service agent roles to any principals except service agents .
cloudsql. instances. demoteMaster
Owner (roles/ owner)
Editor (roles/ editor)
Cloud SQL Admin (roles/ cloudsql.admin)
Databases Admin (roles/ iam.databasesAdmin)
Service agent roles
Warning: Don't grant service agent roles to any principals except service agents .
cloudsql.instances.executeSql
Owner (roles/ owner)
Editor (roles/ editor)
Cloud SQL Admin (roles/ cloudsql.admin)
Cloud SQL Instance User (roles/ cloudsql.instanceUser)
Cloud SQL Studio User (roles/ cloudsql.studioUser)
DLP Organization Data Profiles Driver (roles/ dlp.orgdriver)
DLP Project Data Profiles Driver (roles/ dlp.projectdriver)
Data Scientist (roles/ iam.dataScientist)
Databases Admin (roles/ iam.databasesAdmin)
Service agent roles
Warning: Don't grant service agent roles to any principals except service agents .
cloudsql.instances.export
Owner (roles/ owner)
Editor (roles/ editor)
Viewer (roles/ viewer)
Cloud SQL Admin (roles/ cloudsql.admin)
Cloud SQL Editor (roles/ cloudsql.editor)
Cloud SQL Viewer (roles/ cloudsql.viewer)
Databases Admin (roles/ iam.databasesAdmin)
Dev Ops (roles/ iam.devOps)
Security Auditor (roles/ iam.securityAuditor)
Site Reliability Engineer (roles/ iam.siteReliabilityEngineer)
Support User (roles/ iam.supportUser)
Service agent roles
Warning: Don't grant service agent roles to any principals except service agents .
cloudsql.instances.failover
Owner (roles/ owner)
Editor (roles/ editor)
Cloud SQL Admin (roles/ cloudsql.admin)
Cloud SQL Editor (roles/ cloudsql.editor)
Databases Admin (roles/ iam.databasesAdmin)
Dev Ops (roles/ iam.devOps)
Service agent roles
Warning: Don't grant service agent roles to any principals except service agents .
cloudsql.instances.get
Owner (roles/ owner)
Editor (roles/ editor)
Viewer (roles/ viewer)
Backup and DR Cloud SQL Operator (roles/ backupdr.cloudSqlOperator)
Cloud SQL Admin (roles/ cloudsql.admin)
Cloud SQL Client (roles/ cloudsql.client)
Cloud SQL Editor (roles/ cloudsql.editor)
Cloud SQL Instance User (roles/ cloudsql.instanceUser)
Cloud SQL Studio User (roles/ cloudsql.studioUser)
Cloud SQL Viewer (roles/ cloudsql.viewer)
DLP Organization Data Profiles Driver (roles/ dlp.orgdriver)
DLP Project Data Profiles Driver (roles/ dlp.projectdriver)
Data Scientist (roles/ iam.dataScientist)
Databases Admin (roles/ iam.databasesAdmin)
Dev Ops (roles/ iam.devOps)
Security Auditor (roles/ iam.securityAuditor)
Site Reliability Engineer (roles/ iam.siteReliabilityEngineer)
Support User (roles/ iam.supportUser)
Dataproc Metastore Managed Migration Admin (roles/ metastore.migrationAdmin)
Service agent roles
Warning: Don't grant service agent roles to any principals except service agents .
cloudsql. instances. getDiskShrinkConfig
Owner (roles/ owner)
Editor (roles/ editor)
Viewer (roles/ viewer)
Cloud SQL Admin (roles/ cloudsql.admin)
Cloud SQL Editor (roles/ cloudsql.editor)
Cloud SQL Viewer (roles/ cloudsql.viewer)
Databases Admin (roles/ iam.databasesAdmin)
Dev Ops (roles/ iam.devOps)
Security Auditor (roles/ iam.securityAuditor)
Site Reliability Engineer (roles/ iam.siteReliabilityEngineer)
Support User (roles/ iam.supportUser)
Service agent roles
Warning: Don't grant service agent roles to any principals except service agents .
cloudsql.instances.import
Owner (roles/ owner)
Editor (roles/ editor)
Cloud SQL Admin (roles/ cloudsql.admin)
Databases Admin (roles/ iam.databasesAdmin)
Service agent roles
Warning: Don't grant service agent roles to any principals except service agents .
cloudsql.instances.list
Owner (roles/ owner)
Editor (roles/ editor)
Viewer (roles/ viewer)
Cloud SQL Admin (roles/ cloudsql.admin)
Cloud SQL Editor (roles/ cloudsql.editor)
Cloud SQL Viewer (roles/ cloudsql.viewer)
Databases Admin (roles/ iam.databasesAdmin)
Dev Ops (roles/ iam.devOps)
Security Admin (roles/ iam.securityAdmin)
Security Auditor (roles/ iam.securityAuditor)
Security Reviewer (roles/ iam.securityReviewer)
Site Reliability Engineer (roles/ iam.siteReliabilityEngineer)
Support User (roles/ iam.supportUser)
Service agent roles
Warning: Don't grant service agent roles to any principals except service agents .
Owner (roles/ owner)
Editor (roles/ editor)
Viewer (roles/ viewer)
Cloud SQL Admin (roles/ cloudsql.admin)
Cloud SQL Editor (roles/ cloudsql.editor)
Cloud SQL Viewer (roles/ cloudsql.viewer)
DLP Organization Data Profiles Driver (roles/ dlp.orgdriver)
DLP Project Data Profiles Driver (roles/ dlp.projectdriver)
Databases Admin (roles/ iam.databasesAdmin)
Dev Ops (roles/ iam.devOps)
Security Auditor (roles/ iam.securityAuditor)
Site Reliability Engineer (roles/ iam.siteReliabilityEngineer)
Support User (roles/ iam.supportUser)
Tag User (roles/ resourcemanager.tagUser)
Tag Viewer (roles/ resourcemanager.tagViewer)
Service agent roles
Warning: Don't grant service agent roles to any principals except service agents .
cloudsql. instances. listServerCas
Owner (roles/ owner)
Editor (roles/ editor)
Viewer (roles/ viewer)
Cloud SQL Admin (roles/ cloudsql.admin)
Cloud SQL Editor (roles/ cloudsql.editor)
Cloud SQL Viewer (roles/ cloudsql.viewer)
Databases Admin (roles/ iam.databasesAdmin)
Dev Ops (roles/ iam.devOps)
Security Auditor (roles/ iam.securityAuditor)
Site Reliability Engineer (roles/ iam.siteReliabilityEngineer)
Support User (roles/ iam.supportUser)
Service agent roles
Warning: Don't grant service agent roles to any principals except service agents .
cloudsql. instances. listServerCertificates
Owner (roles/ owner)
Editor (roles/ editor)
Viewer (roles/ viewer)
Cloud SQL Admin (roles/ cloudsql.admin)
Cloud SQL Editor (roles/ cloudsql.editor)
Cloud SQL Viewer (roles/ cloudsql.viewer)
Databases Admin (roles/ iam.databasesAdmin)
Dev Ops (roles/ iam.devOps)
Security Auditor (roles/ iam.securityAuditor)
Site Reliability Engineer (roles/ iam.siteReliabilityEngineer)
Support User (roles/ iam.supportUser)
Service agent roles
Warning: Don't grant service agent roles to any principals except service agents .
cloudsql. instances. listTagBindings
Owner (roles/ owner)
Editor (roles/ editor)
Viewer (roles/ viewer)
Cloud SQL Admin (roles/ cloudsql.admin)
Cloud SQL Editor (roles/ cloudsql.editor)
Cloud SQL Viewer (roles/ cloudsql.viewer)
DLP Organization Data Profiles Driver (roles/ dlp.orgdriver)
DLP Project Data Profiles Driver (roles/ dlp.projectdriver)
Databases Admin (roles/ iam.databasesAdmin)
Dev Ops (roles/ iam.devOps)
Security Auditor (roles/ iam.securityAuditor)
Site Reliability Engineer (roles/ iam.siteReliabilityEngineer)
Support User (roles/ iam.supportUser)
Tag User (roles/ resourcemanager.tagUser)
Tag Viewer (roles/ resourcemanager.tagViewer)
Service agent roles
Warning: Don't grant service agent roles to any principals except service agents .
cloudsql.instances.login
Owner (roles/ owner)
Editor (roles/ editor)
Cloud SQL Admin (roles/ cloudsql.admin)
Cloud SQL Instance User (roles/ cloudsql.instanceUser)
Cloud SQL Studio User (roles/ cloudsql.studioUser)
DLP Organization Data Profiles Driver (roles/ dlp.orgdriver)
DLP Project Data Profiles Driver (roles/ dlp.projectdriver)
Data Scientist (roles/ iam.dataScientist)
Databases Admin (roles/ iam.databasesAdmin)
Dataproc Metastore Managed Migration Admin (roles/ metastore.migrationAdmin)
Service agent roles
Warning: Don't grant service agent roles to any principals except service agents .
cloudsql. instances. manageEncryption
Owner (roles/ owner)
Cloud SQL Admin (roles/ cloudsql.admin)
Databases Admin (roles/ iam.databasesAdmin)
Service agent roles
Warning: Don't grant service agent roles to any principals except service agents .
cloudsql.instances.migrate
Owner (roles/ owner)
Editor (roles/ editor)
Cloud SQL Admin (roles/ cloudsql.admin)
Cloud SQL Editor (roles/ cloudsql.editor)
Databases Admin (roles/ iam.databasesAdmin)
Dev Ops (roles/ iam.devOps)
Service agent roles
Warning: Don't grant service agent roles to any principals except service agents .
Owner (roles/ owner)
Editor (roles/ editor)
Cloud SQL Admin (roles/ cloudsql.admin)
Cloud SQL Editor (roles/ cloudsql.editor)
Databases Admin (roles/ iam.databasesAdmin)
Dev Ops (roles/ iam.devOps)
Service agent roles
Warning: Don't grant service agent roles to any principals except service agents .
cloudsql. instances. preCheckMajorVersionUpgrade
Owner (roles/ owner)
Editor (roles/ editor)
Viewer (roles/ viewer)
Cloud SQL Admin (roles/ cloudsql.admin)
Cloud SQL Editor (roles/ cloudsql.editor)
Cloud SQL Viewer (roles/ cloudsql.viewer)
Databases Admin (roles/ iam.databasesAdmin)
Dev Ops (roles/ iam.devOps)
Security Auditor (roles/ iam.securityAuditor)
Site Reliability Engineer (roles/ iam.siteReliabilityEngineer)
Support User (roles/ iam.supportUser)
Service agent roles
Warning: Don't grant service agent roles to any principals except service agents .
Owner (roles/ owner)
Editor (roles/ editor)
Cloud SQL Admin (roles/ cloudsql.admin)
Databases Admin (roles/ iam.databasesAdmin)
Service agent roles
Warning: Don't grant service agent roles to any principals except service agents .
cloudsql.instances.reencrypt
Owner (roles/ owner)
Editor (roles/ editor)
Cloud SQL Admin (roles/ cloudsql.admin)
Cloud SQL Editor (roles/ cloudsql.editor)
Databases Admin (roles/ iam.databasesAdmin)
Dev Ops (roles/ iam.devOps)
Service agent roles
Warning: Don't grant service agent roles to any principals except service agents .
cloudsql. instances. resetReplicaSize
Owner (roles/ owner)
Editor (roles/ editor)
Cloud SQL Admin (roles/ cloudsql.admin)
Cloud SQL Editor (roles/ cloudsql.editor)
Databases Admin (roles/ iam.databasesAdmin)
Dev Ops (roles/ iam.devOps)
Service agent roles
Warning: Don't grant service agent roles to any principals except service agents .
cloudsql. instances. resetSslConfig
Owner (roles/ owner)
Editor (roles/ editor)
Cloud SQL Admin (roles/ cloudsql.admin)
Databases Admin (roles/ iam.databasesAdmin)
Service agent roles
Warning: Don't grant service agent roles to any principals except service agents .
cloudsql.instances.restart
Owner (roles/ owner)
Editor (roles/ editor)
Cloud SQL Admin (roles/ cloudsql.admin)
Cloud SQL Editor (roles/ cloudsql.editor)
Databases Admin (roles/ iam.databasesAdmin)
Dev Ops (roles/ iam.devOps)
Service agent roles
Warning: Don't grant service agent roles to any principals except service agents .
cloudsql. instances. restoreBackup
Owner (roles/ owner)
Editor (roles/ editor)
Cloud SQL Admin (roles/ cloudsql.admin)
Databases Admin (roles/ iam.databasesAdmin)
Service agent roles
Warning: Don't grant service agent roles to any principals except service agents .
cloudsql. instances. rotateServerCa
Owner (roles/ owner)
Editor (roles/ editor)
Cloud SQL Admin (roles/ cloudsql.admin)
Cloud SQL Editor (roles/ cloudsql.editor)
Databases Admin (roles/ iam.databasesAdmin)
Dev Ops (roles/ iam.devOps)
Service agent roles
Warning: Don't grant service agent roles to any principals except service agents .
cloudsql. instances. rotateServerCertificate
Owner (roles/ owner)
Editor (roles/ editor)
Cloud SQL Admin (roles/ cloudsql.admin)
Cloud SQL Editor (roles/ cloudsql.editor)
Databases Admin (roles/ iam.databasesAdmin)
Dev Ops (roles/ iam.devOps)
Service agent roles
Warning: Don't grant service agent roles to any principals except service agents .
cloudsql. instances. startReplica
Owner (roles/ owner)
Editor (roles/ editor)
Cloud SQL Admin (roles/ cloudsql.admin)
Databases Admin (roles/ iam.databasesAdmin)
Service agent roles
Warning: Don't grant service agent roles to any principals except service agents .
cloudsql.instances.stopReplica
Owner (roles/ owner)
Editor (roles/ editor)
Cloud SQL Admin (roles/ cloudsql.admin)
Databases Admin (roles/ iam.databasesAdmin)
Service agent roles
Warning: Don't grant service agent roles to any principals except service agents .
cloudsql.instances.truncateLog
Owner (roles/ owner)
Editor (roles/ editor)
Cloud SQL Admin (roles/ cloudsql.admin)
Cloud SQL Editor (roles/ cloudsql.editor)
Databases Admin (roles/ iam.databasesAdmin)
Dev Ops (roles/ iam.devOps)
Service agent roles
Warning: Don't grant service agent roles to any principals except service agents .
cloudsql.instances.update
Owner (roles/ owner)
Editor (roles/ editor)
Cloud SQL Admin (roles/ cloudsql.admin)
Cloud SQL Editor (roles/ cloudsql.editor)
Databases Admin (roles/ iam.databasesAdmin)
Dev Ops (roles/ iam.devOps)
Service agent roles
Warning: Don't grant service agent roles to any principals except service agents .
cloudsql. instances. updateBackupDrConfig
Owner (roles/ owner)
Editor (roles/ editor)
Cloud SQL Admin (roles/ cloudsql.admin)
Databases Admin (roles/ iam.databasesAdmin)
Service agent roles
Warning: Don't grant service agent roles to any principals except service agents .
cloudsql.schemas.view
Owner (roles/ owner)
Editor (roles/ editor)
Viewer (roles/ viewer)
Cloud SQL Admin (roles/ cloudsql.admin)
Cloud SQL Editor (roles/ cloudsql.editor)
Cloud SQL Schema Viewer (roles/ cloudsql.schemaViewer)
Databases Admin (roles/ iam.databasesAdmin)
Dev Ops (roles/ iam.devOps)
Support User (roles/ iam.supportUser)
Service agent roles
Warning: Don't grant service agent roles to any principals except service agents .
cloudsql.sslCerts.create
Owner (roles/ owner)
Editor (roles/ editor)
Cloud SQL Admin (roles/ cloudsql.admin)
Databases Admin (roles/ iam.databasesAdmin)
Service agent roles
Warning: Don't grant service agent roles to any principals except service agents .
cloudsql.sslCerts.delete
Owner (roles/ owner)
Editor (roles/ editor)
Cloud SQL Admin (roles/ cloudsql.admin)
Databases Admin (roles/ iam.databasesAdmin)
Service agent roles
Warning: Don't grant service agent roles to any principals except service agents .
cloudsql.sslCerts.get
Owner (roles/ owner)
Editor (roles/ editor)
Viewer (roles/ viewer)
Cloud SQL Admin (roles/ cloudsql.admin)
Cloud SQL Editor (roles/ cloudsql.editor)
Cloud SQL Viewer (roles/ cloudsql.viewer)
Databases Admin (roles/ iam.databasesAdmin)
Dev Ops (roles/ iam.devOps)
Security Auditor (roles/ iam.securityAuditor)
Site Reliability Engineer (roles/ iam.siteReliabilityEngineer)
Support User (roles/ iam.supportUser)
Service agent roles
Warning: Don't grant service agent roles to any principals except service agents .
cloudsql.sslCerts.list
Owner (roles/ owner)
Editor (roles/ editor)
Viewer (roles/ viewer)
Cloud SQL Admin (roles/ cloudsql.admin)
Cloud SQL Editor (roles/ cloudsql.editor)
Cloud SQL Viewer (roles/ cloudsql.viewer)
Databases Admin (roles/ iam.databasesAdmin)
Dev Ops (roles/ iam.devOps)
Security Admin (roles/ iam.securityAdmin)
Security Auditor (roles/ iam.securityAuditor)
Security Reviewer (roles/ iam.securityReviewer)
Site Reliability Engineer (roles/ iam.siteReliabilityEngineer)
Support User (roles/ iam.supportUser)
Service agent roles
Warning: Don't grant service agent roles to any principals except service agents .
cloudsql.users.create
Owner (roles/ owner)
Editor (roles/ editor)
Cloud SQL Admin (roles/ cloudsql.admin)
Databases Admin (roles/ iam.databasesAdmin)
Service agent roles
Warning: Don't grant service agent roles to any principals except service agents .
cloudsql.users.delete
Owner (roles/ owner)
Editor (roles/ editor)
Cloud SQL Admin (roles/ cloudsql.admin)
Databases Admin (roles/ iam.databasesAdmin)
Service agent roles
Warning: Don't grant service agent roles to any principals except service agents .
cloudsql.users.get
Owner (roles/ owner)
Editor (roles/ editor)
Viewer (roles/ viewer)
Cloud SQL Admin (roles/ cloudsql.admin)
Cloud SQL Editor (roles/ cloudsql.editor)
Cloud SQL Viewer (roles/ cloudsql.viewer)
Databases Admin (roles/ iam.databasesAdmin)
Dev Ops (roles/ iam.devOps)
Security Auditor (roles/ iam.securityAuditor)
Site Reliability Engineer (roles/ iam.siteReliabilityEngineer)
Support User (roles/ iam.supportUser)
Service agent roles
Warning: Don't grant service agent roles to any principals except service agents .
cloudsql.users.list
Owner (roles/ owner)
Editor (roles/ editor)
Viewer (roles/ viewer)
Cloud SQL Admin (roles/ cloudsql.admin)
Cloud SQL Editor (roles/ cloudsql.editor)
Cloud SQL Studio User (roles/ cloudsql.studioUser)
Cloud SQL Viewer (roles/ cloudsql.viewer)
Data Scientist (roles/ iam.dataScientist)
Databases Admin (roles/ iam.databasesAdmin)
Dev Ops (roles/ iam.devOps)
Security Admin (roles/ iam.securityAdmin)
Security Auditor (roles/ iam.securityAuditor)
Security Reviewer (roles/ iam.securityReviewer)
Site Reliability Engineer (roles/ iam.siteReliabilityEngineer)
Support User (roles/ iam.supportUser)
Service agent roles
Warning: Don't grant service agent roles to any principals except service agents .
cloudsql.users.update
Owner (roles/ owner)
Editor (roles/ editor)
Cloud SQL Admin (roles/ cloudsql.admin)
Databases Admin (roles/ iam.databasesAdmin)
Service agent roles
Warning: Don't grant service agent roles to any principals except service agents .