GAM-team / GAM

command line management for Google Workspace
https://github.com/GAM-team/GAM/wiki
Apache License 2.0
3.54k stars 473 forks source link

New Google GCP Org Policy will impact GAM service account creation #1679

Open jay0lee opened 8 months ago

jay0lee commented 8 months ago

Google Cloud has added new default organization policies for new Workspace/GCP domains that will break GAM service account key configuration. @taers232c fyi. We'll need to 1) encourage more admins to run GAM on GCE securely 2) if that's not possible, disable these restrictions at the GAM project level. We may be able to do that programatically on the GAM project during project create/update but we should notify the admin that they are reducing their own security posture by doing so.

xmen2005 commented 7 months ago

Impractical the GCE securely not free