Create a Secure Agent role and service account to grant the agent permissions to create and manage an
advanced cluster
on Google Cloud. You can include the master node and worker node permissions in the Secure Agent role, or you can create separate roles and service accounts for the cluster nodes.
Create the following roles and Google service accounts:
Secure Agent role and service account
Optionally, a master node role and service account
Optionally, a worker node role and service account
A Google Cloud service account is always linked to a Google Cloud project. Make sure that you use only one set of credentials for both the source and target when you run an