Configuring permissions to use cloudkit on public clouds
Use the cloudkit validate command to check permission needed to deploy
the cluster and verify cloud quota for cluster install.
The following permissions are required to run the cloudkit tool.
- GCP role permissions:Note: To run validate permission, GCP requires at least a browser role permission.
Artifact Registry Administrator Browser Cloud KMS CryptoKey Encrypter/Decrypter Compute Instance Admin (v1) Compute Network Admin Compute Security Admin DNS Administrator Service Account User Storage Admin Storage HMAC Key Admin - Azure role permissions:
Create an Azure service principle with sufficient privileges. The minimum required role is
Contributor,Storage Blob Data Owner. - IBM® Cloud role permissions:Create an IIBM Cloud API key with sufficient privileges. The API key must have access to an Access Group with the following service access roles.
VPC Infrastructure Services - Editor DNS Services - Manager Cloud Object Storage - Writer Resource Group - Viewer Context-Based Restrictions - Editor