Info |
---|
The article explains how to grant Cloudaware additional permissions, such as to Google Organizations or Google Billing accounts, and create a custom role for backups and tagging. Ensure you have the necessary permissions in Google Cloud. |
...
For Cloudaware to collectGoogle Organizations and related data, assign the role 'Viewer' to the service account added to Cloudaware. The following permissions are required:
Organization Role Viewer
Folder Viewer
Organization Viewer
Organization Policy Viewer
Project Viewer
Click Save SAVE.
Assign the 'Project Viewer' role on at the organization level for Cloudaware to automatically add and collect Google Projects within a Google Organization automatically.
...
billing accounts
For Cloudaware to collect Google Billing Accountsbilling accounts, assign the role 'Billing Account Viewer' to the service account* that has access to billing accounts in question.
1. Go to Billing.
...
Log in to the Google console. Go to
...
'
...
Billing' → 'MY BILLING ACCOUNTS'.
...
Select the
...
billing account by checking the check box. Click
...
ADD PRINCIPAL on the right to manage permissions.
...
Select the
...
role Billing Account Viewer →
...
SAVE.
...
*Note that the Google service account should be added to Cloudaware. See the guide
...
To use backups and tagging, create a custom role and assign it to the Cloudawareservice Cloudaware service account:
Log in to the Google console. Go to 'IAM & admin, select "Roles" and click +Create Role.
...
...
' → 'Roles' → +CREATE ROLE.
Set a meaningful name and description for the custom role, e.g. Cloudaware Custom Role. Set 'Role launch stage' as General Availability
...
.
Click +ADD PERMISSIONS. Select the following permissions:
For backups |
---|
|
For labels (tags) |
|
Click CREATE.
Assign the custom role to the service account: 'IAM & admin
...
' → IAM→ select the service account → click the pencil icon to edit principal → ADD ANOTHER ROLE → Custom → Cloudaware Custom Role → SAVE.