Uploaded image for project: 'OpenShift Cloud Credential Operator'
  1. OpenShift Cloud Credential Operator
  2. CCO-524

Removing or limiting the iam.serviceAccounts.actAs requirement on GCP

XMLWordPrintable

    • False
    • None
    • False

      Having the `iam.serviceAccounts.actAs` permission is a requirement right now for the Installer and the required scope is at the GCP Project level.

      There is an escalation from a OSD customer flagging that this requirement is a security risk and is going against Google Cloud's security best practicies.

      We need to spike how we could remove or limit that requirement to be complaint with Google Cloud's security best practices and unblock this customer for adopting OSD

            jstuever@redhat.com Jeremiah Stuever
            jstuever@redhat.com Jeremiah Stuever
            Votes:
            0 Vote for this issue
            Watchers:
            4 Start watching this issue

              Created:
              Updated:
              Resolved: