-
Notifications
You must be signed in to change notification settings - Fork 1.8k
OSDOCS-16429 Reducing GCP permissions #100149
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Conversation
|
🤖 Fri Oct 17 15:05:31 - Prow CI generated the docs preview: |
2bc9dcf to
bbb3b20
Compare
bbb3b20 to
3caf3f6
Compare
| * `iam.serviceAccountKeys.get` | ||
| * `iam.serviceAccountKeys.list` | ||
| * `iam.serviceAccounts.actAs` | ||
| ** This permission can be limited to act as the control plane and compute service accounts. Alternatively, you may grant the service account that the installation program creates the `iam.serviceAccountUser` role on the control plane and compute service accounts. |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
I guess "you may grant the service account that the installation program creates" should be "you may grant the service account that the installation program uses", is it?
3caf3f6 to
693bcb6
Compare
| ==== | ||
| If you do not supply a service account for control plane nodes in the `install-config.yaml` file, please grant the below permissions to the service account in the host project. If you do not supply a service account for compute nodes in the `install-config.yaml` file, please grant the below permissions to the service account in the host project for cluster destruction. | ||
| If you do not supply a service account for control plane nodes in the `install-config.yaml` file, please grant the below permissions to the service account in the host project. If you do not supply a service account for compute nodes in the `install-config.yaml` file, please grant the below permissions to the service account in the host project for cluster destruction. If you do supply service accounts for control plane and compute nodes, you do not need to grant the below permissions. |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Can I ask you to fix this one? Per ISG: Do not use to indicate a relative location in a document, as in “the information below”
| If you do not supply a service account for control plane nodes in the `install-config.yaml` file, please grant the below permissions to the service account in the host project. If you do not supply a service account for compute nodes in the `install-config.yaml` file, please grant the below permissions to the service account in the host project for cluster destruction. If you do supply service accounts for control plane and compute nodes, you do not need to grant the below permissions. | |
| If you do not supply a service account for control plane nodes in the `install-config.yaml` file, please grant the following permissions to the service account in the host project. If you do not supply a service account for compute nodes in the `install-config.yaml` file, please grant the following permissions to the service account in the host project for cluster destruction. If you do supply service accounts for control plane and compute nodes, you do not need to grant the following permissions. |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Updated, thanks
693bcb6 to
b7455e9
Compare
|
@bscott-rh: all tests passed! Full PR test history. Your PR dashboard. Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the kubernetes-sigs/prow repository. I understand the commands that are listed here. |
|
/cherrypick enterprise-4.20 |
|
@bscott-rh: new pull request created: #100761 In response to this:
Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the kubernetes-sigs/prow repository. |
Version(s):
4.20
Issue:
https://issues.redhat.com/browse/OSDOCS-16429
Link to docs preview:
https://100149--ocpdocs-pr.netlify.app/openshift-enterprise/latest/installing/installing_gcp/installing-gcp-account.html#minimum-required-permissions-ipi-gcp_installing-gcp-account
QE review: