Closed jku closed 9 months ago
google.api_core.exceptions.PermissionDenied: 403 Permission 'cloudkms.cryptoKeyVersions.useToSign' denied on resource 'projects/projectsigstore-staging/locations/global/keyRings/tuf-keyring/cryptoKeys/tuf-staging-key'
https://github.com/sigstore/root-signing-staging/actions/runs/7474882630/job/20341939571
projects/projectsigstore-staging/locations/global/keyRings/tuf-keyring/cryptoKeys/tuf-staging-key/cryptoKeyVersions/1
the service account should have roles/cloudkms.signer for the key or the keyring
roles/cloudkms.signer
Creating a dedicated service account with a signer permission granted to the SA for the keyring.
finally :pray: https://sigstore.github.io/root-signing-staging/timestamp.json
https://github.com/sigstore/root-signing-staging/actions/runs/7474882630/job/20341939571
projects/projectsigstore-staging/locations/global/keyRings/tuf-keyring/cryptoKeys/tuf-staging-key/cryptoKeyVersions/1