GoogleCloudPlatform / pbmm-on-gcp-onboarding

GCP Canadian Public Sector Landing Zone overlay on top of the TEF via CFT modules - a secure cloud foundation
https://cloud.google.com/architecture/security-foundations
Apache License 2.0
45 stars 56 forks source link

Terraform-Deployer-Service-Account-Least-privileges-Permissions #324

Closed stanimprover closed 1 year ago

stanimprover commented 1 year ago

As part of reducing the permissions of the Terraform deployer service account used to bootstrap a landing zone in Google Cloud Platform (GCP). The terraform deployer service account which had over 25 roles attached to it. Organizational viewer and Logs Configuration Writer have been removed because they have overlapping roles in Organization Role Administrator and Logging Admin respectively.

main-23 Screenshot 2023-09-29 at 7 32 20 AM
google-cla[bot] commented 1 year ago

Thanks for your pull request! It looks like this may be your first contribution to a Google open source project. Before we can look at your pull request, you'll need to sign a Contributor License Agreement (CLA).

View this failed invocation of the CLA check for more information.

For the most up to date status, view the checks section at the bottom of the pull request.