The resources created and IAM custom role permissions when opswitch integrates with Google Cloud are as follows:
Resources Created:
- Workload Identity Pool (starting with opswitch-wi)
- Workload Identity Provider (starting with opswitch-wi)
- Service Account (starting with opswitch-wi)
- IAM Custom Role
IAM Custom Role Permissions
Compute Engine
- compute.instances.get
- compute.instances.list
- compute.instances.stop
- compute.instances.start
- compute.instances.setMachineType
Cloud SQL
- cloudsql.instances.list
- cloudsql.instances.get
- cloudsql.instances.update
IAM
- iam.roles.get