Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[IaC] Remove developer access for terraform planner service account #10075

Open
1 task
Tracked by #10076
KacperMalachowski opened this issue Mar 8, 2024 · 0 comments
Open
1 task
Tracked by #10076

Comments

@KacperMalachowski
Copy link
Contributor

KacperMalachowski commented Mar 8, 2024

Description:

As part of #8594 we have to set roles/container.developer to prevent from creating custom role. With end of using Prow the GKE clusters will be removed as well, please ensure to remove that role as well as it grants too much permissions for planner service account.

Acceptance Criteria

  • Terraform Planner has not write access to resources except state bucket

Important information:

Blocked by Prow usage.

@KacperMalachowski KacperMalachowski changed the title [IAC] Remove developer access for terraform planner service account [IaC] Remove developer access for terraform planner service account Mar 8, 2024
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

1 participant