vmware-archive / terraforming-gcp

use terraform, deploy yourself a pcf
Apache License 2.0
71 stars 87 forks source link

update iam roles to align with pks documents service account roles #126

Closed oahcran closed 5 years ago

oahcran commented 5 years ago

issue #115

Follow the following two documentations for required roles mapping:

Ops Manager Service Account

ROLE
roles/compute.instanceAdmin.v1
roles/compute.networkAdmin
roles/compute.storageAdmin
roles/iam.serviceAccountTokenCreator
roles/iam.serviceAccountUser
roles/storage.admin

Master Node Service Account

ROLE
roles/compute.instanceAdmin.v1
roles/compute.networkAdmin
roles/compute.securityAdmin
roles/compute.storageAdmin
roles/compute.viewer
roles/iam.serviceAccountUser

Worker Node Service Account

ROLE
roles/compute.viewer