本页面介绍了执行特定安全 Web 代理操作所需的 Identity and Access Management (IAM) 权限。本文还介绍了如何创建自定义 IAM 角色,以及如何为该角色分配管理各种安全 Web 代理资源所需的权限。
权限
下表列出了在安全 Web 代理中执行特定操作所需的权限。如需了解详情,请参阅 IAM 权限参考文档。
| 操作 | 资源 | 权限(方法) |
|---|---|---|
| 创建政策 | 网关安全政策 | networksecurity.gatewaySecurityPolicies.create |
| 删除政策 | 网关安全政策 | networksecurity.gatewaySecurityPolicies.delete |
| 检索政策 | 网关安全政策 | networksecurity.gatewaySecurityPolicies.get |
| 列出政策 | 网关安全政策 | networksecurity.gatewaySecurityPolicies.list |
| 更新政策 | 网关安全政策 | networksecurity.gatewaySecurityPolicies.update |
| 创建规则 | 网关安全政策规则 | networksecurity.gatewaySecurityPolicyRules.create |
| 删除规则 | 网关安全政策规则 | networksecurity.gatewaySecurityPolicyRules.delete |
| 检索规则 | 网关安全政策规则 | networksecurity.gatewaySecurityPolicyRules.get |
| 列出规则 | 网关安全政策规则 | networksecurity.gatewaySecurityPolicyRules.list |
| 更新规则 | 网关安全政策规则 | networksecurity.gatewaySecurityPolicyRules.update |
| 检索操作 | 运维 | networksecurity.operations.get |
| 创建 TLS 检查政策 | TLS 检查政策 | networksecurity.tlsInspectionPolicies.create |
| 删除 TLS 检查政策 | TLS 检查政策 | networksecurity.tlsInspectionPolicies.delete |
| 检索 TLS 检查政策 | TLS 检查政策 | networksecurity.tlsInspectionPolicies.get |
| 列出 TLS 检查政策 | TLS 检查政策 | networksecurity.tlsInspectionPolicies.list |
| 更新 TLS 检查政策 | TLS 检查政策 | networksecurity.tlsInspectionPolicies.update |
| 将 TLS 检查政策附加到安全 Web 代理政策 | TLS 检查政策 | networksecurity.tlsInspectionPolicies.use |
| 创建网址列表 | 网址列表 | networksecurity.urlLists.create |
| 删除网址列表 | 网址列表 | networksecurity.urlLists.delete |
| 检索网址列表 | 网址列表 | networksecurity.urlLists.get |
| 列出所有网址列表 | 网址列表 | networksecurity.urlLists.list |
| 更新网址列表 | 网址列表 | networksecurity.urlLists.update |
| 将网址列表附加到安全 Web 代理规则 | 网址列表 | networksecurity.urlLists.use |
| 配置和管理安全 Web 代理实例 | 各种 Certificate Manager、Compute Engine、安全 Web 代理、Resource Manager 和 Cloud Monitoring 资源 |
|