roles/browser
: Allows browsing resources.roles/compute.admin
: Grants administrative access to Compute Engine resources.roles/iam.serviceAccountAdmin
: Provides permissions to manage service accounts.roles/iam.serviceAccountUser
: Allows the use of service accounts.roles/serviceusage.serviceUsageConsumer
: Permits the consumption of service usage data.roles/storage.admin
: Offers administrative control over storage resources.roles/iam.serviceAccountTokenCreator
: allows creation of token for authroles/iam.securityAdmin
: If undesirable, you can initially include it to create necessary service accounts and then replace it with roles/iam.roleViewer
.roles/tpu.admin
: Grants access to TPUs.nextai-role
.--clone-disk-from
, you need to have the following permissions for the role as well:nextai-role
in the “Assign roles” section. Click Savenextai-role
(or the name you set) created in the last section and click on DONE. You can also Medium Permissions roles as described in the previous sections.