Restore Permissions
To allow Veeam Backup for GCP to perform restore operations, the service account associated with the GCP project that will be used to manage the restored VM instances must have the following permissions:
cloudkms.cryptoKeys.getIamPolicy cloudkms.cryptoKeys.list cloudkms.cryptoKeys.setIamPolicy cloudkms.keyRings.list compute.addresses.list compute.addresses.use compute.addresses.useInternal compute.disks.create compute.disks.delete compute.disks.get compute.disks.list compute.disks.setLabels compute.disks.use compute.disks.useReadOnly compute.firewalls.list compute.globalOperations.get compute.globalOperations.list compute.instances.create compute.instances.delete compute.instances.get compute.instances.list compute.instances.setDeletionProtection compute.instances.setLabels compute.instances.setMachineResources compute.instances.setMetadata compute.instances.setMinCpuPlatform compute.instances.setScheduling compute.instances.setServiceAccount compute.instances.setTags compute.instances.start compute.instances.stop compute.instances.updateDisplayDevice compute.instances.updateNetworkInterface compute.machineTypes.list compute.networks.list compute.projects.get compute.regionOperations.get compute.regions.get compute.regions.list compute.routes.list compute.snapshots.create compute.snapshots.delete compute.snapshots.get compute.snapshots.getIamPolicy compute.snapshots.list compute.snapshots.setLabels compute.snapshots.useReadOnly compute.subnetworks.list compute.subnetworks.use compute.subnetworks.useExternalIp compute.zoneOperations.get compute.zones.get compute.zones.list iam.serviceAccounts.actAs iam.serviceAccounts.list resourcemanager.projects.get serviceusage.services.list |
Important |
The ability to rename VM instances is currently in pre-GA state. For more information, see Google Cloud documentation.
To learn how to provide access to Shared VPC networks, see Google Cloud documentation. |