Skip to content

Use user managed service account for GCP cloud build #2

@obriensystems

Description

@obriensystems

Make sure on older GCP orgs that the org policy is set

cloudbuild.disableCreateDefaultServiceAccount
https://console.cloud.google.com/iam-admin/orgpolicies/cloudbuild-disableCreateDefaultServiceAccount;fromListPage=true?project=ops-cicd-olx
and
cloudbuild.useBuildServiceAccount
https://console.cloud.google.com/iam-admin/orgpolicies/cloudbuild-useBuildServiceAccount;fromListPage=true?project=ops-cicd-olx

so we see

Your organization policy requires you to select a user-managed service account. For enhanced security, we recommend selecting a service account with only the necessary permissions for this build's execution.

https://cloud.google.com/build/docs/securing-builds/configure-user-specified-service-accounts?_gl=1*11kjg47*_ga*MTg0MDg1MTU4My4xNzQwMTYyMzYx*_ga_WH2QY8WWF5*czE3NjU5OTU1OTYkbzE5JGcxJHQxNzY1OTk5MjM0JGo2MCRsMCRoMA..

Image

Metadata

Metadata

Assignees

Labels

No labels
No labels

Type

No type

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions