Configuring permissions to use cloudkit on public clouds

Use the cloudkit validate command to check permission needed to deploy the cluster and verify cloud quota for cluster install.

The following permissions are required to run the cloudkit tool.
  • GCP role permissions:
    Note: To run validate permission, GCP requires at least a browser role permission.
    Artifact Registry Administrator  
    Browser  
    Cloud KMS CryptoKey Encrypter/Decrypter  
    Compute Instance Admin (v1)  
    Compute Network Admin  
    Compute Security Admin  
    DNS Administrator  
    Service Account User  
    Storage Admin  
    Storage HMAC Key Admin
  • Azure role permissions:

    Create an Azure service principle with sufficient privileges. The minimum required role is Contributor, Storage Blob Data Owner.

  • IBM® Cloud role permissions:
    Create an IIBM Cloud API key with sufficient privileges. The API key must have access to an Access Group with the following service access roles.
    VPC Infrastructure Services - Editor 
    DNS Services - Manager 
    Cloud Object Storage - Writer 
    Resource Group - Viewer
    Context-Based Restrictions - Editor