| copyright |
|
||
|---|---|---|---|
| lastupdated | 2026-08-28 | ||
| keywords | satellite, hybrid, multicloud | ||
| subcollection | satellite |
{{site.data.keyword.attribute-definition-list}}
{: #iam-common}
Review commonly required permissions for creating and managing {{site.data.keyword.satelliteshort}} infrastructure in cloud providers. {: shortdesc}
{: #permissions-aws}
When you use an {{site.data.keyword.bplong}} template to create your {{site.data.keyword.satelliteshort}} location, you must be assigned a role that can create virtual instances and networks in AWS. For example, you can be assigned the AmazonEC2FullAccess built-in role{: external} in AWS. For more information about other built-in roles, see the AWS documentation{: external}.
{: #permissions-azure}
When you use an {{site.data.keyword.bplong}} template to create your {{site.data.keyword.satelliteshort}} location, you must be assigned a role that can create virtual instances and networks in Microsoft Azure. For example, you can be assigned the Contributor built-in role{: external} in Azure. For more information about other built-in roles, see the Azure documentation{: external}.
{: #permissions-gcp}
When you use an {{site.data.keyword.bplong}} template to create your {{site.data.keyword.satelliteshort}} location, you must be assigned a role that can create virtual instances and networks in Google Cloud Platform. For example, you can be assigned the Cloud Build Editor{: external} role in a specific project in GCP IAM. For more information about role permissions in GCP, see the GCP documentation{: external}.
{: #permissions-vmware}
Assign the Administrator role for VMware vSphere vCenter servers when using a {{site.data.keyword.bplong}} template. See the VMware documentation{: external}. {: shortdesc}