-
Story
-
Resolution: Done
-
Critical
-
None
-
None
-
None
-
False
-
None
-
False
-
-
Having the `iam.serviceAccounts.actAs` permission is a requirement right now for the Installer and the required scope is at the GCP Project level.
There is an escalation from a OSD customer flagging that this requirement is a security risk and is going against Google Cloud's security best practicies.
We need to spike how we could remove or limit that requirement to be complaint with Google Cloud's security best practices and unblock this customer for adopting OSD
- is incorporated by
-
CORS-3445 Support for pre-creation of Service Accounts used in GCP deployments
- Closed
-
OCPSTRAT-1294 Pre-creation Service Accounts used in GCP deployments
- Closed
- is related to
-
CCO-524 Removing or limiting the iam.serviceAccounts.actAs requirement on GCP
- Closed