为第三方配置Firebase Hosting部署权限的IAM角色咨询
Great question—this is a super common scenario when you need to grant deployment access without letting third parties mess with other parts of your Firebase/GCP project. Here are the targeted roles you should use instead of the overly broad Project Editor:
1. Firebase Hosting Admin (roles/firebase.hostingAdmin)
This is the most straightforward role for full control over Firebase Hosting, and it’s isolated exclusively to Hosting resources. With this role, the third party can:
- Deploy static assets to your Hosting sites via CLI or the Firebase Console
- Configure Hosting settings like rewrite rules, custom domains, SSL certificates, and redirects
- Roll back deployments and manage Hosting versions
Crucially, they won’t have permissions to enable other Firebase products (like Firestore, Cloud Functions, or Authentication) or modify non-Hosting project resources—so you don’t have to worry about unexpected costs from enabled services.
2. Firebase Hosting Deployer (roles/firebase.hostingDeployer)
If you want even tighter control (e.g., you don’t want the third party modifying Hosting configuration like custom domains), use this more granular role. It only allows:
- Deploying static assets to existing Hosting sites
- Viewing Hosting deployment history and versions
They won’t be able to change any core Hosting settings or access other project resources. This is perfect if you just need someone to push code updates without altering your Hosting setup.
Why Avoid Project Editor?
You’re right to steer clear of Project Editor—this role grants full read/write access to all resources in your GCP/Firebase project. A third party with this role could enable paid services, modify database rules, delete resources, or make other costly changes outside of Hosting.
Quick Setup Steps
- Go to the GCP Console’s IAM page for your project
- Click "Add" to add a new member (enter the third party’s email or service account)
- In the "Role" dropdown, search for either
Firebase Hosting AdminorFirebase Hosting Deployerand select it - Save the changes—they’ll now have exactly the permissions needed for Hosting deployments
内容的提问来源于stack exchange,提问作者Chris

