The following are the commands used to assign roles to the service account using the GCP command-line tool.

Commands for Service Engine Project

$ gcloud projects add-iam-policy-binding se-project --member serviceAccount:[email protected] --role projects/se-project/roles/avi.se
Updated IAM policy for project [se-project].
bindings:
- members:
  - serviceAccount:[email protected]
  role: projects/se-project/roles/avi.se
etag: B*******2=
version: 1

Commands for Network Project

$ gcloud projects add-iam-policy-binding network-project --member serviceAccount:[email protected] --role projects/network-project/roles/avi.network
Updated IAM policy for project [network-project].
bindings:
- members:
  - serviceAccount:[email protected]
  role: projects/network-project/roles/avi.network
etag: B*********Q=
version: 1

Commands for Storage Project

$ gcloud projects add-iam-policy-binding storage-project --member serviceAccount:[email protected] --role projects/storage-project/roles/avi.storage
Updated IAM policy for project [storage-project].
bindings:
- members:
  - serviceAccount:[email protected]
  role: projects/storage-project/roles/avi.storage
etag: B**********=
version: 1