-
Notifications
You must be signed in to change notification settings - Fork 1.9k
OSDOCS-17793#Reducing permissions for GCP #104792
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
base: main
Are you sure you want to change the base?
Conversation
752b42f to
33640ac
Compare
33640ac to
858ca50
Compare
|
Install change LGTM. Thanks for handling this Lisa 🙇 |
| CMD="gcloud iam service-accounts add-iam-policy-binding \"${MASTER_NODE_SA}\" --project=\"${GOOGLE_PROJECT_ID}\" --member=\"serviceAccount:${SERVICE_ACCOUNT_EMAIL}\" --role=\"${SA_USER_ROLE}\" --condition=None" | ||
| run_command "${CMD}" | ||
| CMD="gcloud iam service-accounts add-iam-policy-binding \"${WORKER_NODE_SA}\" --project=\"${GOOGLE_PROJECT_ID}\" --member=\"serviceAccount:${SERVICE_ACCOUNT_EMAIL}\" --role=\"${SA_USER_ROLE}\" --condition=None" | ||
| run_command "${CMD}" |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
We did not introduce run_command func in this doc, can we use it directly?
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
I do not know. I got infor for this procedure from this script provided by @bscott-rh.
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
In turn, I found this script via @dobsonj 's comment on the storage epic: https://issues.redhat.com/browse/STOR-2531
858ca50 to
91a4bb6
Compare
|
@lpettyjo: all tests passed! Full PR test history. Your PR dashboard. DetailsInstructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the kubernetes-sigs/prow repository. I understand the commands that are listed here. |
Version(s): 4.21+
Issue: https://issues.redhat.com/browse/OSDOCS-17793
Link to docs preview:
Storage content: https://104792--ocpdocs-pr.netlify.app/openshift-enterprise/latest/storage/container_storage_interface/persistent-storage-csi-gcp-pd.html#persistent-storage-csi-gcp-pd-reduce-permissions_persistent-storage-csi-gcp-pd
Link from Install: https://104792--ocpdocs-pr.netlify.app/openshift-enterprise/latest/installing/installing_gcp/installing-gcp-account.html#installation-gcp-service-account_installing-gcp-account
QE review:
Additional information:
PTAL: @dobsonj @chao007 @gcharot @bscott-rh