Permissions Changelog

This section describes the latest changes in service account permissions required for Veeam Backup for Google Cloud to perform operations.

When you update Veeam Backup for Google Cloud version 4.0 to version 5.0, consider that additional permissions must be granted to the service accounts used to perform the following operations.

Repository Creation

storage.multipartUploads.create
storage.multipartUploads.abort

 

File-Level Restore to Original Location

pubsub.subscriptions.setIamPolicy

pubsub.subscriptions.getIamPolicy

pubsub.topics.setIamPolicy

pubsub.topics.getIamPolicy

storage.objects.create

storage.objects.delete

storage.objects.list

storage.objects.get

storage.objects.update

storage.buckets.create

Cloud Spanner Backup and Restore

compute.regions.list

compute.disks.list

compute.instances.get

compute.instances.list

compute.snapshots.get

compute.snapshots.list

compute.zones.get

compute.zones.list

compute.globalOperations.get

compute.zoneOperations.get

compute.regionOperations.get

resourcemanager.projects.get

compute.projects.get

compute.firewalls.list

compute.snapshots.getIamPolicy

compute.networks.list

compute.subnetworks.list

resourcemanager.projects.getIamPolicy

iam.serviceAccounts.actAs

compute.disks.create

compute.disks.createSnapshot

compute.disks.delete

compute.disks.setLabels

compute.instances.attachDisk

compute.instances.create

compute.instances.delete

compute.instances.detachDisk

compute.instances.setMetadata

compute.instances.setServiceAccount

compute.instances.setLabels

compute.instances.setTags

compute.routes.list

compute.regions.get

compute.snapshots.create

compute.snapshots.setLabels

compute.snapshots.setIamPolicy

compute.snapshots.delete

pubsub.subscriptions.consume

pubsub.subscriptions.create

pubsub.subscriptions.delete

pubsub.subscriptions.list

pubsub.subscriptions.get

logging.sinks.get

logging.sinks.delete

logging.sinks.list

pubsub.topics.attachSubscription

pubsub.topics.detachSubscription

pubsub.topics.create

pubsub.topics.delete

pubsub.topics.list

pubsub.topics.get

pubsub.topics.publish

compute.machineTypes.get

compute.machineTypes.list

compute.subnetworks.get

compute.subnetworks.use

compute.subnetworks.useExternalIp

compute.disks.use

serviceusage.services.list