Skip to content

Files

Latest commit

 

History

History
26 lines (16 loc) · 580 Bytes

google-iam-no-folder-level-service-account-impersonation.md

File metadata and controls

26 lines (16 loc) · 580 Bytes

Pattern: Use of folder-level service account access for Google IAM

Issue: -

Description

Users with service account access at folder level can impersonate any service account. Instead, they should be given access to particular service accounts as required.

Resolution: Provide access at the service-level instead of folder-level, if required.

Examples

Example of incorrect code:

Example of correct code:

resource "google_folder_iam_binding" "folder-123" {
	folder = "folder-123"
	role    = "roles/nothingInParticular"
}