Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[GCP] Use storage.admin permission for automatically created skypilot-v1 service account #2947

Merged
merged 3 commits into from
Jan 14, 2024

Conversation

Michaelvll
Copy link
Collaborator

This is to make sure the service account skypilot-v1 automatically created by skypilot can access the user's bucket, to make it more convenient for the users.

Tested (run the relevant ones):

  • Code formatting: bash format.sh
  • Any manual or new tests for this PR (please specify below)
  • All smoke tests: pytest tests/test_smoke.py
  • Relevant individual smoke tests: pytest tests/test_smoke.py::test_fill_in_the_name
  • Backward compatibility tests: bash tests/backward_comaptibility_tests.sh

Copy link
Collaborator

@concretevitamin concretevitamin left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM

@@ -26,7 +26,7 @@
# NOTE: `serviceAccountUser` allows the head node to create workers with
# a serviceAccount. `roleViewer` allows the head node to run bootstrap_gcp.
DEFAULT_SERVICE_ACCOUNT_ROLES = [
'roles/storage.objectAdmin',
'roles/storage.admin',
Copy link
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

The old sky/skylet/providers/gcp/config.py has this too, should it be changed (or should that dir be removed)?

Copy link
Collaborator Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

The dir should be removed now. Also, the AWS node provider should be removed as well #2792. We will handle that in another PR.

@Michaelvll Michaelvll merged commit 3596677 into master Jan 14, 2024
19 checks passed
@Michaelvll Michaelvll deleted the gcp-storage-permission branch January 14, 2024 17:48
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

None yet

2 participants