Meta tags:
description= How to create a service agent and grant it IAM roles.;
Headings (most frequently used words):
windows, linux, macos, or, cloud, shell, powershell, curl, service, and, roles, to, agents, gcloud, rest, cmd, exe, apis, explorer, browser, create, grant, required, console, terraform, stay, organized, with, collections, save, categorize, content, based, on, your, preferences, before, you, begin, identify, trigger, agent, creation, what, next, products, pricing, support, resources, engage, permissions,
Text of the page (most frequently used words):
the (334), #service (203), for (134), you (125), and (111), #agents (90), roles (78), that (76), gcloud (72), create (60), access (59), agent (59), cloud (56), role (49), grant (48), following (48), use (47), com (46), google (43), your (42), command (38), googleapis (37), account (37), policy (36), request (36), list (35), auth (35), identity (34), project (33), resource (33), with (31), iam (31), using (29), projects (29), can (28), each (28), services (28), response (27), 123456789012 (26), aiplatform (25), this (24), resource_type (24), endpoint (23), manage (22), policies (22), running (22), organization (22), terraform (21), allow (21), are (20), resource_id (20), api (20), example (20), resources (19), need (19), accounts (19), workload (19), cli (18), type (18), folder (18), granted (18), principal (18), all (17), user (17), active (17), want (17), execute (16), json (16), data (16), code (15), identities (15), method (15), headers (15), https (15), federation (15), page (14), note (14), token (14), automatically (14), organizations (14), folders (14), permissions (14), global (14), get (14), required (13), shell (13), created (13), workloadidentity (13), available (13), content (12), which (12), any (12), have (12), these (12), name (12), see (11), information (11), send (11), reference (11), application (11), expand (11), windows (11), like (11), before (11), custom (11), email (11), locations (11), body (10), apis (10), cred (10), print (10), authorization (10), bearer (10), assumes (10), logged (10), check (10), currently (10), login (10), init (10), curl (10), one (10), make (10), configuration (10), address (10), enable (10), workforce (10), samples (9), other (9), best (9), practices (9), version (9), contains (9), post (9), logs (9), ids (9), value (9), binding (9), serviceaccount (9), apply (9), console (9), will (9), where (9), resourcemanager (9), troubleshoot (9), configure (9), more (8), view (8), api_version (8), powershell (8), linux (8), macos (8), replacements (8), then (8), add (8), gcp (8), gserviceaccount (8), identify (8), creation (8), google_workload_identity_service_agent (8), operations (8), serviceproducers (8), state (8), level (8), usage (8), keys (8), pam (8), overview (8), about (7), thumb (7), managed (7), them (7), not (7), setiampolicy (7), select (7), granting (7), getiampolicy (7), trigger (7), run (7), permission (7), operation (7), also (7), serviceusage (7), limit (7), management (7), audit (7), 2026 (6), workloads (6), should (6), explorer (6), click (6), cloudresourcemanager (6), save (6), options (6), numeric (6), bigquery (6), default (6), condition (6), manager (6), job (6), container (6), serviceproducer (6), lists (6), from (6), number (6), endpoints (6), expression (6), their (6), admin (6), security (6), tools (6), oauth (6), logging (6), credentials (6), updated (5), learn (5), tool (5), invoke (5), webrequest (5), charset (5), utf (5), uri (5), object (5), named (5), into (5), http (5), url (5), alphanumeric (5), grants (5), primary (5), documentation (5), product (5), might (5), false (5), creating (5), record (5), generateserviceagents (5), filter (5), predefined (5), pipelines (5), temporary (5), boundary (5), functions (5), authenticate (5), português (4), español (4), understand (4), down (4), how (4), copy (4), right (4), requests (4), file (4), strings (4), rest (4), plan (4), after (4), target (4), member (4), associated (4), role_name (4), multiple (4), time (4), typically (4), don (4), specific (4), operation_name (4), resource_numeric_id (4), generate (4), ask (4), next_page_token (4), page_size (4), optional (4), storage (4), deny (4), short (4), lived (4), credential (4), elevated (4), delete (4), providers (4), users (4), microsoft (4), entra (4), sign (3), architecture (3), getting (3), system (3), products (3), under (3), details (3), control (3), returned (3), open (3), panel (3), opens (3), side (3), interact (3), complete (3), fields (3), browser (3), set (3), whose (3), write (3), members (3), vertex (3), bindings (3), owner (3), when (3), read (3), errors (3), section (3), google_project (3), remove (3), cmd (3), exe (3), below (3), needs (3), choose (3), function (3), based (3), those (3), some (3), because (3), aren (3), metadata (3), operationmetadata (3), createtime (3), 03t23 (3), verb (3), passthroughlro (3), requestedcancellation (3), apiversion (3), done (3), listed (3), field (3), identified (3), location (3), review (3), names (3), pagination (3), pagesize (3), pagetoken (3), results (3), quotes (3), contain (3), help (3), guides (3), networking (3), compute (3), monitor (3), scim (3), tags (3), related (3), key (3), gke (3), groups (3), 한국어 (2), 日本語 (2), עברית (2), brasil (2), italiano (2), indonesia (2), français (2), américa (2), latina (2), deutsch (2), english (2), terms (2), site (2), youtube (2), events (2), started (2), status (2), support (2), pricing (2), missing (2), last (2), utc (2), otherwise (2), licensed (2), license (2), feedback (2), explore (2), principals (2), next (2), store (2), paste (2), contenttype (2), infile (2), calling (2), already (2), project_number (2), customcodeserviceagent (2), policy_version (2), current (2), modify (2), pattern (2), update (2), execution (2), google_project_iam_member (2), added (2), service_agents (2), project_id (2), wanted (2), could (2), provider (2), basic (2), commands (2), search (2), must (2), they (2), properly (2), creates (2), necessary (2), 1775258415970 (2), 64e968f44b91a (2), 28fcf2f5 (2), 38367cfe (2), 982631253z (2), serviceagents (2), serviceagent (2), vtc (2), trainingclusterserviceagent (2), truncated (2), completed (2), return (2), were (2), was (2), 1775250941060 (2), 64e94d1baa76d (2), 1aa958f3 (2), 07b2ea9c (2), placeholder (2), skip (2), find (2), titles (2), greater (2), than (2), size (2), start (2), previous (2), include (2), maximum (2), quoting (2), filters (2), sandbox (2), but (2), library (2), through (2), repository (2), let (2), actual (2), resolve (2), revoke (2), prevent (2), revoked (2), sdk (2), languages (2), frameworks (2), infrastructure (2), costs (2), observability (2), monitoring (2), migration (2), industry (2), solutions (2), distributed (2), hybrid (2), multicloud (2), databases (2), analytics (2), hosting (2), development (2), error (2), messages (2), patterns (2), integration (2), controls (2), optimize (2), test (2), migrate (2), restrict (2), settings (2), entitlements (2), edit (2), conditions (2), conditional (2), types (2), legged (2), disable (2), integrate (2), pools (2), libraries (2), deployment (2), federate (2), load (2), applications (2), federated (2), oidc (2), saml (2), okta (2), cross (2), technology (2), areas (2), close (2), subscribe, newsletter, our, third, decade, climate, action, join, cookies, privacy, tech, twitter, blog, engage, training, certification, center, github, release, notes, community, forums, contact, sales, marketplace, easy, easytounderstand, solved, problem, solvedmyproblem, otherup, hard, hardtounderstand, incorrect, sample, incorrectinformationorsamplecode, missingtheinformationsamplesineed, otherdown, tell, except, noted, java, registered, trademark, oracle, its, affiliates, developers, apache, creative, commons, attribution, act, ways, what, treat, sent, representation, format, has, platform, etag, bwwkmjvelug, requestedpolicyversion, specify, most, recent, specifying, shows, looks, good, ensures, without, known, would, targeted, for_each, try, prefaced, 0123456789012, instead, follow, principle, least, privilege, includes, only, perform, give, enter, person_add, asked, addresses, endtime, 315225515z, true, generateserviceagentsresponse, containing, ongoing, indicting, 03t21, 367155118z, parent, provisioned, once, during, step, manually, keep, track, programmatically, provide, know, unique, organization_number, folder_number, indicates, determine, triggering, earlier, specified, ended, 200, retrieve, uses, replace, single, double, nested, escape, inner, unlimited, expressions, topic, additional, methods, able, long, exact, organizationadmin, folderadmin, projectiamadmin, viewer, serviceusageviewer, administrator, likely, serviceusageadmin, begin, refer, stores, copies, appear, stored, inconsistency, incorrectly, proactively, drift, between, doesn, ensure, declarative, framework, option, useful, strategies, asking, lets, hasn, been, yet, sometimes, behalf, categorize, preferences, stay, organized, collections, home, withcond, insights, history, analyze, privileged, secure, vpc, intelligence, securely, exfiltration, interfaces, restore, downscoped, boundaries, approve, withdraw, remediate, excessive, entitlement, export, setup, lint, limits, conditionally, changes, auditing, billing, grantable, suggestions, gemini, assistance, change, propagation, inheritance, own, deploy, built, managing, upload, public, rotation, download, customers, 509, certificates, kubernetes, directory, aws, azure, external, balancers, balancing, gce, engine, attach, undelete, authentication, impersonation, obtain, power, pingone, aic, pingfederate, large, provisioning, client, discover, free, main,
Text of the page (random words):
ices is greater than the page size the response also contains a pagination token the api endpoint is the value in the name field for each api endpoint that you will use make a list of the resources where you need to create that endpoint s service agents on the service agent reference page search for each api endpoint to find all service agents for that endpoint some endpoints might not have associated service agents you can skip triggering service agent creation for these endpoints for each of the endpoint s service agents use the service agent s email address to determine where you need to create the service agent the placeholder in a service agent s email address indicates where you need to create the service agent placeholder where to create the service agent project_number each project where you will use the service folder_number each folder where you will use the service organization_number each organization where you will use the service for each endpoint record each unique resource where you need to create service agents for that endpoint trigger service agent creation after you know which service agents you need to create you can ask google cloud to create them when you ask google cloud to create service agents you provide it with a service and a resource then google cloud creates all service agents for that service and that resource during this step if you re using the gcloud cli or the rest api you can also create a list of the roles that need to be granted to each service agent you ll use this information to grant roles to the service agents if you re using terraform then you don t need to manually keep track of the required roles because you can reference the roles programmatically gcloud use the gcloud workload identity service agents generate command to create service agents for each endpoint and resource that you identified in identify service agents to create each time you run the command review the response for each role in the response record the email address of the service agent that the role should be granted to you will use this information to grant roles to the service agents before using any of the command data below make the following replacements endpoint the endpoint of the api that you want to create service agents for for example aiplatform googleapis com resource_type the type of resource that you want to create service agents for use project folder or organization resource_id the numeric id of the google cloud project folder or organization that you want to create service agents for for example 123456789012 you can create service agents for one resource at a time if you need to create service agents for multiple resources run the command once for each resource execute the following command linux macos or cloud shell gcloud workload identity service agents generate service endpoint location global resource_type resource_id windows powershell gcloud workload identity service agents generate service endpoint location global resource_type resource_id windows cmd exe gcloud workload identity service agents generate service endpoint location global resource_type resource_id the response contains a list of all of the service agents that were created for each service agent the response lists the resource it was created for the email address of the service agent the service that the service agent is associated with and the state of the service agent if the service agent is typically granted a specific role the response also lists that role the listed role is not automatically granted to the service agent for each role in the response record the email address of the service agent that the role should be granted to you will use this information to grant roles to the service agents the following is a truncated example of the response for creating service agents for aiplatform googleapis com provisioned service agents for aiplatform googleapis com under projects 123456789012 container projects 123456789012 principal serviceaccount service 123456789012 gcp sa aiplatform iam gserviceaccount com role roles aiplatform serviceagent serviceproducer aiplatform googleapis com state active container projects 123456789012 principal serviceaccount service 123456789012 gcp ri aiplatform iam gserviceaccount com serviceproducer aiplatform googleapis com state active container projects 123456789012 principal serviceaccount service 123456789012 gcp sa vertex vtc iam gserviceaccount com role roles aiplatform trainingclusterserviceagent serviceproducer aiplatform googleapis com state active terraform to learn how to apply or remove a terraform configuration see basic terraform commands for more information see the terraform provider reference documentation use the google_workload_identity_service_agent resource to trigger service agent creation for each endpoint and resource that you identified in identify service agents to create for example if you wanted to create all project level service agents for bigquery for the default project you could add the following code to your terraform configuration data google_project default create all project level bigquery googleapis com service agents resource google_workload_identity_service_agent primary parent projects data google_project default number locations global serviceproducers bigquery googleapis com rest for each endpoint that you need to create service agents for do the following create service agents for each resource that you identified in identify service agents to create before using any of the request data make the following replacements resource_type the type of resource that you want to create service agents for use projects folders or organizations resource_numeric_id the numeric id of the google cloud project folder or organization that you want to create service agents for for example 123456789012 you can create service agents for one resource at a time if you need to create service agents for multiple resources send one request for each resource endpoint the endpoint of the api that you want to create a service agent for for example aiplatform googleapis com http method and url post https workloadidentity googleapis com v1 resource_type resource_numeric_id locations global serviceproducers endpoint generateserviceagents to send your request expand one of these options curl linux macos or cloud shell note the following command assumes that you have logged in to the gcloud cli with your user account by running gcloud init or gcloud auth login or by using cloud shell which automatically logs you into the gcloud cli you can check the currently active account by running gcloud auth list execute the following command curl x post h authorization bearer gcloud auth print access token h content type application json charset utf 8 d https workloadidentity googleapis com v1 resource_type resource_numeric_id locations global serviceproducers endpoint generateserviceagents powershell windows note the following command assumes that you have logged in to the gcloud cli with your user account by running gcloud init or gcloud auth login you can check the currently active account by running gcloud auth list execute the following command cred gcloud auth print access token headers authorization bearer cred invoke webrequest method post headers headers uri https workloadidentity googleapis com v1 resource_type resource_numeric_id locations global serviceproducers endpoint generateserviceagents select object expand content the response contains an operation indicting the status of your request for example name projects 123456789012 locations global operations operation 1775250941060 64e94d1baa76d 1aa958f3 07b2ea9c metadata type type googleapis com google cloud workloadidentity v1 operationmetadata createtime 2026 04 03t21 15 41 367155118z target projects 123456789012 locations global serviceproducers bigquery googleapis com verb passthroughlro requestedcancellation false apiversion v1 done false get the response from the completed operation for each role in the response record the email address of the service agent that the role should be granted to you will use this information to grant roles to the service agents before using any of the request data make the following replacements operation_name the name of a generateserviceagents operation copy this value from the name field of a serviceproducers generateserviceagents response for example projects 123456789012 locations global operations operation 1775250941060 64e94d1baa76d 1aa958f3 07b2ea9c project_id your google cloud project id project ids are alphanumeric strings like my project http method and url get https workloadidentity googleapis com v1 operation_name to send your request expand one of these options curl linux macos or cloud shell note the following command assumes that you have logged in to the gcloud cli with your user account by running gcloud init or gcloud auth login or by using cloud shell which automatically logs you into the gcloud cli you can check the currently active account by running gcloud auth list execute the following command curl x get h authorization bearer gcloud auth print access token https workloadidentity googleapis com v1 operation_name powershell windows note the following command assumes that you have logged in to the gcloud cli with your user account by running gcloud init or gcloud auth login you can check the currently active account by running gcloud auth list execute the following command cred gcloud auth print access token headers authorization bearer cred invoke webrequest method get headers headers uri https workloadidentity googleapis com v1 operation_name select object expand content apis explorer browser open the method reference page the apis explorer panel opens on the right side of the page you can interact with this tool to send requests complete any required fields and click execute ongoing operations return a response like the following name projects 123456789012 locations global operations operation 1775258415970 64e968f44b91a 28fcf2f5 38367cfe metadata type type googleapis com google cloud workloadidentity v1 operationmetadata createtime 2026 04 03t23 20 15 982631253z target projects 123456789012 locations global serviceproducers aiplatform googleapis com verb passthroughlro requestedcancellation false apiversion v1 done false completed operations return a response containing a list of service agents that were created for each service agent the response lists the resource it was created for the email address of the service agent the service that the service agent is associated with and the state of the service agent if the service agent is typically granted a specific role the response also lists that role the listed role is not automatically granted to the service agent for each role in the response record the email address of the service agent that the role should be granted to you will use this information to grant roles to the service agents the following is a truncated example of the response for creating service agents for aiplatform googleapis com name projects 123456789012 locations global operations operation 1775258415970 64e968f44b91a 28fcf2f5 38367cfe metadata type type googleapis com google cloud workloadidentity v1 operationmetadata createtime 2026 04 03t23 20 15 982631253z endtime 2026 04 03t23 20 17 315225515z target projects 123456789012 locations global serviceproducers aiplatform googleapis com verb passthroughlro requestedcancellation false apiversion v1 done true response type type googleapis com google cloud workloadidentity v1 generateserviceagentsresponse serviceagents container projects 123456789012 serviceproducer aiplatform googleapis com principal serviceaccount service 123456789012 gcp sa aiplatform iam gserviceaccount com role roles aiplatform serviceagent state active container projects 123456789012 serviceproducer aiplatform googleapis com principal serviceaccount service 123456789012 gcp ri aiplatform iam gserviceaccount com state active container projects 123456789012 serviceproducer aiplatform googleapis com principal serviceaccount service 123456789012 gcp sa vertex vtc iam gserviceaccount com role roles aiplatform trainingclusterserviceagent state active grant roles to service agents after google cloud creates the necessary service agents for your projects folders and organizations you use the service agents email addresses to grant them roles if you asked google cloud to create service agents you must grant those service agents the roles that they are typically granted automatically if you don t some services might not function properly this is because service agents that are created at a user s request aren t automatically granted roles console use the list of roles and service agents that you created in trigger service agent creation to identify which service agents need to be granted roles for each service agent that needs a role do the following in the google cloud console go to the iam page go to iam select a project folder or organization that you created the service agent for click person_add grant access then enter the service agent s email address click select a role then search for a role to grant based on the following the role name the google cloud product that you want to grant access to the permission that you want to give the job function to perform to follow the principle of least privilege choose a role that includes only the permissions that your principal needs click save the service agent is granted the role on the resource gcloud use the list of roles and service agents that you created in trigger service agent creation to identify which service agents need to be granted roles for each service agent that needs a role use the add iam policy binding command to grant the role to the service agent note to grant roles to multiple service agents at a time use the read modify write pattern instead of the add iam policy binding command before using any of the command data below make the following replacements resource_type the resource type that you want to manage access to use projects resource manager folders or organizations resource_id your google cloud project folder or organization id project ids are alphanumeric like my project folder and organization ids are numeric like 123456789012 principal the email address of the service agent that you want to grant access to prefaced by serviceaccount for example serviceaccount service 0123456789012 gcp sa aiplatform cc iam gserviceaccount com role_name the name of the role that you want to grant to the service agent execute the following command linux macos or cloud shell gcloud resource_type add iam policy binding resource_id member principal role role_name condition condition windows powershell gcloud resource_type add iam policy binding resource_id member principal role role_name condition condition windows cmd exe gcloud resource_type add iam policy binding ...
|