Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
6 changes: 3 additions & 3 deletions platform-cloud/docs/compute-envs/google-cloud-batch.md
Original file line number Diff line number Diff line change
Expand Up @@ -2,7 +2,7 @@
title: "Google Cloud Batch"
description: "Instructions to set up Google Cloud Batch in Seqera Platform"
date created: "2023-04-21"
last updated: "2026-09-01"
last updated: "2026-09-16"
tags: [google, batch, gcp, compute environments]
---

Expand Down Expand Up @@ -65,8 +65,9 @@ By default, Google Cloud Batch uses the default Compute Engine service account t
- Logs Viewer (`roles/logging.logViewer`) on the project (to view and retrieve logs from Cloud Logging)
- Service Account User (`roles/iam.serviceAccountUser`)
- Secret Manager Secret Accessor (`roles/secretmanager.secretAccessor`) on the project (required if your pipelines use Seqera secrets; the head job and tasks read secrets from GCP Secret Manager)
- Storage Bucket Viewer (`roles/storage.bucketViewer`) on the project (required if you grant Storage access per bucket instead of project-wide Storage Admin, which already includes the `storage.buckets.list` permission)

If your Google Cloud project does not require access restrictions on any of its Cloud Storage buckets, you can grant project Storage Admin (`roles/storage.admin`) permissions to your service account to simplify setup. To grant access only to specific buckets, add the service account as a principal on each bucket individually. See [Cloud Storage bucket](#cloud-storage-bucket) below.
If your Google Cloud project does not require access restrictions on any of its Cloud Storage buckets, you can grant project Storage Admin (`roles/storage.admin`) permissions to your service account to simplify setup. To grant access only to specific buckets, add the service account as a principal on each bucket individually. See [Cloud Storage bucket](#cloud-storage-bucket) below. Seqera needs the `storage.buckets.list` permission at the project level to list buckets when you create a compute environment, to browse buckets in Data Explorer, and to [validate the credential](./preflight-checks). Bucket-level grants cannot confer `storage.buckets.list`.

#### User permissions

Expand All @@ -75,7 +76,6 @@ Ask your Google Cloud administrator to grant you the following IAM user permissi
- Batch Job Editor (`roles/batch.jobsEditor`) on the project
- Service Account User (`roles/iam.serviceAccountUser`) on the job's service account (default: Compute Engine service account)
- View Service Accounts (`roles/iam.serviceAccountViewer`) on the project
- `storage.buckets.list` on the project via a custom role, if you use per-bucket Storage grants instead of project-wide Storage Admin. Seqera requires this permission to validate credentials — without it, credential validation fails and the compute environment is marked invalid.
Comment thread
christopher-hakkaart marked this conversation as resolved.

#### Authentication methods

Expand Down
5 changes: 3 additions & 2 deletions platform-enterprise_docs/compute-envs/google-cloud-batch.md
Original file line number Diff line number Diff line change
Expand Up @@ -2,7 +2,7 @@
title: "Google Cloud Batch"
description: "Instructions to set up Google Cloud Batch in Seqera Platform"
date created: "2023-04-21"
last updated: "2026-09-01"
last updated: "2026-09-16"
tags: [google, batch, gcp, compute environments]
---

Expand Down Expand Up @@ -65,8 +65,9 @@ By default, Google Cloud Batch uses the default Compute Engine service account t
* Service Account User (`roles/iam.serviceAccountUser`)
* Service Usage Consumer (`roles/serviceusage.serviceUsageConsumer`)
* Secret Manager Secret Accessor (`roles/secretmanager.secretAccessor`) on the project (required if your pipelines use Seqera secrets; the head job and tasks read secrets from GCP Secret Manager)
* Storage Bucket Viewer (`roles/storage.bucketViewer`) on the project (required if you grant Storage access per bucket instead of project-wide Storage Admin, which already includes the `storage.buckets.list` permission)

If your Google Cloud project does not require access restrictions on any of its Cloud Storage buckets, you can grant project Storage Admin (`roles/storage.admin`) permissions to your service account to simplify setup. To grant access only to specific buckets, add the service account as a principal on each bucket individually. See [Cloud Storage bucket](#cloud-storage-bucket) below.
If your Google Cloud project does not require access restrictions on any of its Cloud Storage buckets, you can grant project Storage Admin (`roles/storage.admin`) permissions to your service account to simplify setup. To grant access only to specific buckets, add the service account as a principal on each bucket individually. See [Cloud Storage bucket](#cloud-storage-bucket) below. Seqera needs the `storage.buckets.list` permission at the project level to list buckets when you create a compute environment, to browse buckets in Data Explorer, and to [validate the credential](./preflight-checks). Bucket-level grants cannot confer `storage.buckets.list`.

#### User permissions

Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -2,7 +2,7 @@
title: "Google Cloud Batch"
description: "Instructions to set up Google Cloud Batch in Seqera Platform"
date created: "2023-04-21"
last updated: "2026-09-01"
last updated: "2026-09-16"
tags: [google, batch, gcp, compute environments]
---

Expand Down Expand Up @@ -64,8 +64,9 @@ By default, Google Cloud Batch uses the default Compute Engine service account t
* Logs Writer (`roles/logging.logWriter`) on the project (to let jobs generate logs in Cloud Logging)
* Service Account User (`roles/iam.serviceAccountUser`)
* Service Usage Consumer (`roles/serviceusage.serviceUsageConsumer`)
* Storage Bucket Viewer (`roles/storage.bucketViewer`) on the project (required if you grant Storage access per bucket instead of project-wide Storage Admin, which already includes the `storage.buckets.list` permission)

If your Google Cloud project does not require access restrictions on any of its Cloud Storage buckets, you can grant project Storage Admin (`roles/storage.admin`) permissions to your service account to simplify setup. To grant access only to specific buckets, add the service account as a principal on each bucket individually. See [Cloud Storage bucket](#cloud-storage-bucket) below.
If your Google Cloud project does not require access restrictions on any of its Cloud Storage buckets, you can grant project Storage Admin (`roles/storage.admin`) permissions to your service account to simplify setup. To grant access only to specific buckets, add the service account as a principal on each bucket individually. See [Cloud Storage bucket](#cloud-storage-bucket) below. Seqera needs the `storage.buckets.list` permission at the project level to list buckets when you create a compute environment, to browse buckets in Data Explorer, and to [validate the credential](./preflight-checks). Bucket-level grants cannot confer `storage.buckets.list`.

#### User permissions

Expand All @@ -74,7 +75,6 @@ Ask your Google Cloud administrator to grant you the following IAM user permissi
* Batch Job Editor (`roles/batch.jobsEditor`) on the project
* Service Account User (`roles/iam.serviceAccountUser`) on the job's service account (default: Compute Engine service account)
* View Service Accounts (`roles/iam.serviceAccountViewer`) on the project
* `storage.buckets.list` on the project via a custom role, if you use per-bucket Storage grants instead of project-wide Storage Admin. Seqera requires this permission to validate credentials — without it, credential validation fails and the compute environment is marked invalid.

#### Authentication methods

Expand Down