Permissions¶
runway keeps three identities separate:
| Identity | What it does | Minimum roles |
|---|---|---|
| Deployer (you / CI) | runs runway; uploads sources, submits builds, creates/updates the service, reads logs |
roles/run.developer (+ run.services.setIamPolicy, e.g. roles/run.admin, to switch public access), roles/cloudbuild.builds.editor, roles/logging.viewer, roles/storage.objectUser on the bucket, roles/artifactregistry.reader on the repository, roles/iam.serviceAccountUser on the runtime and build service accounts |
| Build service account | runs Cloud Build: reads the archive, pushes the image, writes build logs | roles/storage.objectViewer on the bucket, roles/artifactregistry.writer on the repository, roles/logging.logWriter on the project |
| Runtime service account | identity of the running container | roles/secretmanager.secretAccessor on each referenced secret, plus whatever the app needs |
The Cloud Run service agent pulls images from Artifact Registry in the same
project automatically; for a repository in another project grant
service-<PROJECT_NUMBER>@serverless-robot-prod.iam.gserviceaccount.com
roles/artifactregistry.reader there.
Optional, for a complete runway doctor report: roles/browser (project),
roles/serviceusage.serviceUsageViewer and roles/secretmanager.viewer.
Extra deployer permissions for the optional features:
| Feature | Deployer needs |
|---|---|
identity.create |
roles/iam.serviceAccountAdmin on the service account's project (and roles/iam.serviceAccountUser on the account once created; grant it at project level or re-run after granting) |
identity.roles on a project |
roles/resourcemanager.projectIamAdmin on that project |
identity.roles on a bucket |
roles/storage.admin on that bucket (storage.buckets.setIamPolicy) |
identity.roles on a dataset |
roles/bigquery.dataOwner on that dataset |
identity.roles on a secret |
roles/secretmanager.admin on that secret |
tags |
roles/resourcemanager.tagUser on the tag value, roles/resourcemanager.tagViewer, and run.services.createTagBinding (roles/run.admin) |
provider.tags |
roles/resourcemanager.tagUser on the tag value and on the project (resourcemanager.projects.createTagBinding) |
iap |
roles/iap.admin, roles/run.admin (invoker binding for the IAP agent), roles/serviceusage.serviceUsageConsumer (creates the IAP service agent) |
volumes |
nothing extra; the runtime service account needs access to the bucket (grant it with identity.roles) |
| impersonation | the caller needs roles/iam.serviceAccountTokenCreator on the impersonated account (and on each delegate); iamcredentials.googleapis.com must be enabled. The impersonated account then needs the deployer roles in this table |
undeploy |
run.services.delete (roles/run.developer); to remove the runtime identity also roles/iam.serviceAccountAdmin and the setIamPolicy permissions used to grant its roles; --delete-images needs roles/artifactregistry.repoAdmin |
enable_apis |
roles/serviceusage.serviceUsageAdmin on the deployment project |
buckets |
roles/storage.admin on the project (storage.buckets.create, update, setIamPolicy) |
create_build_resources |
roles/artifactregistry.admin (repository + its IAM), roles/storage.admin, roles/iam.serviceAccountAdmin, roles/resourcemanager.projectIamAdmin (log writer grant) |