Closed simonkowallik closed 1 year ago
Hi, none of our templates configure a service account, they ask for an existing account. For templates that were using the serviceAccount parameter for service discovery, the parameter has been removed because those solutions no longer configure service discovery.
I was not referring to service account creation. Service accounts are relevant beyond service discovery. Firewall rules is one example. Version 3.0.1 silently removed the ability to assign a service account which existing customers previously relied on.
Seems like we have a fundamental misunderstanding of how serviceAccount is being used. I will run this by product management and update here with the internal issue number.
As a side note for the curious reader: When using the deployment manager without setting a service account, the resulting VM instance does not allow to add a service account through the cloud console. To add a service account to the VM instance after deployment use gcloud. example:
gcloud --project=$GCP_PROJECT compute instances set-service-account $VM_INSTANCE --service-account $SERVICE_ACCOUNT_EMAIL
Any updates on this? I noticed 3.20 standalone does not ask for service account in yaml nor does it configure the VM instance with a svc account. This now requires an additional step post deployment to add the svc account to the VM. This account is useful for things like service discovery.
I've created Jira ticket #1803 to get the serviceAccount parameter added back into standalone templates.
This also impairs standalone templates from accessing/creating a storage bucket with credentials.
Working with customer and having to shutdown, add service account, then start up BIG-IP again is disruptive to onboarding. Is there an ETA for service account to be added back to YAML and template code for automated service account binding?
Closing due to age. These legacy templates are now in maintenance mode and are being replaced by our next-generation templates available in the Cloud Templates 2.0 GitHub repo.
Do you already have an issue opened with F5 support?
No
Description
The option to configure a
serviceAccount
is missing in template version 3.0.1.Template
3.0.1 templates
Severity Level
For bugs, enter the bug severity level. Do not set any labels.
Severity: 4