Configuração do IAM para projetos do Data Connect

Para usar o Firebase Data Connect, atribua papéis do IAM que permitam gerenciar conectores, acessar o Cloud SQL e gerar SDKs. Verifique se a conta de serviço que executa o Data Connect tem as permissões necessárias.

Papéis granulares do IAM para Data Connect

Os papéis básicos e predefinidos do Firebase são mapeados para papéis de nível inferior do Data Connect. Consulte a tabela para ver o mapeamento.

Para gerenciar atribuições individuais de papéis do IAM para Data Connect em um nível mais granular, use o console Google Cloud.

Papel do IAM Permissões
firebasedataconnect.googleapis.com/admin

Administrador da API Firebase Data Connect

Essa função inclui o leitor da API Firebase Data Connect.
É equivalente a firebasedataconnect.*.

Isso é fornecido pelas funções de proprietário do Cloud, editor do Cloud,
administrador do Firebase e administrador do Firebase Develop.
Acesso completo aos recursos da API Firebase Data Connect, inclusive dados.

firebasedataconnect.googleapis.com/operations.delete
firebasedataconnect.googleapis.com/operations.cancel
firebasedataconnect.googleapis.com/services.create
firebasedataconnect.googleapis.com/services.update
firebasedataconnect.googleapis.com/services.delete
firebasedataconnect.googleapis.com/services.executeGraphql
firebasedataconnect.googleapis.com/services.executeGraphqlRead
firebasedataconnect.googleapis.com/schemas.create
firebasedataconnect.googleapis.com/schemas.update
firebasedataconnect.googleapis.com/schemas.delete
firebasedataconnect.googleapis.com/schemaRevisions.create
firebasedataconnect.googleapis.com/schemaRevisions.delete
firebasedataconnect.googleapis.com/connectors.create
firebasedataconnect.googleapis.com/connectors.update
firebasedataconnect.googleapis.com/connectors.delete
firebasedataconnect.googleapis.com/connectorRevisions.create
firebasedataconnect.googleapis.com/connectorRevisions.delete
firebasedataconnect.googleapis.com/viewer

Leitor da API Firebase Data Connect

É fornecido pelas funções de proprietário, editor,
leitor, administrador do Firebase, leitor do Firebase,
administrador de desenvolvimento do Firebase e leitor de desenvolvimento do Firebase do Cloud.
Acesso somente leitura aos recursos da API Firebase Data Connect. O papel não concede acesso aos dados.

cloudresourcemanager.googleapis.com/projects.list
cloudresourcemanager.googleapis.com/projects.get

firebasedataconnect.googleapis.com/operations.list
firebasedataconnect.googleapis.com/operations.get
firebasedataconnect.googleapis.com/locations.list
firebasedataconnect.googleapis.com/locations.get
firebasedataconnect.googleapis.com/services.list
firebasedataconnect.googleapis.com/services.get
firebasedataconnect.googleapis.com/schemas.list
firebasedataconnect.googleapis.com/schemas.get
firebasedataconnect.googleapis.com/schemaRevisions.list
firebasedataconnect.googleapis.com/schemaRevisions.get
firebasedataconnect.googleapis.com/connectors.list
firebasedataconnect.googleapis.com/connectors.get
firebasedataconnect.googleapis.com/connectorRevisions.list
firebasedataconnect.googleapis.com/connectorRevisions.get
firebasedataconnect.googleapis.com/dataAdmin

Administrador de dados da API Firebase Data Connect

Fornecido pelas funções de proprietário, editor,
administrador do Firebase e administrador de desenvolvimento do Firebase.
Acesso completo de leitura e gravação às fontes de dados.

firebasedataconnect.googleapis.com/services.executeGraphql
firebasedataconnect.googleapis.com/services.executeGraphqlRead
firebasedataconnect.googleapis.com/dataViewer

Leitor de dados da API Firebase Data Connect

Fornecido pelas funções de proprietário do Cloud, editor do Cloud,
administrador do Firebase e administrador de desenvolvimento do Firebase.
Acesso somente leitura a fontes de dados.

firebasedataconnect.googleapis.com/services.executeGraphqlRead