Skip to content

Conversation

@jeana-redhat
Copy link
Contributor

@jeana-redhat jeana-redhat commented Jan 29, 2026

Version(s):
4.21

Issue:
OSDOCS-17996

Link to docs preview:
Restricting service account impersonation to the compute nodes service account

QE review:

  • QE has approved this change.

Additional information:
Rel notes to accompany #105412

@jeana-redhat jeana-redhat added this to the Planned for 4.21 GA milestone Jan 29, 2026
@jeana-redhat jeana-redhat added do-not-merge DEPRECATED. Indicates that a PR should not merge. Label can only be manually applied/removed. merge-review-needed Signifies that the merge review team needs to review this PR branch/enterprise-4.21 labels Jan 29, 2026
@openshift-ci openshift-ci bot added the size/XS Denotes a PR that changes 0-9 lines, ignoring generated files. label Jan 29, 2026
@skopacz1 skopacz1 added the merge-review-in-progress Signifies that the merge review team is reviewing this PR label Jan 29, 2026
@ocpdocs-previewbot
Copy link

🤖 Thu Jan 29 16:35:32 - Prow CI generated the docs preview:

https://105690--ocpdocs-pr.netlify.app/openshift-enterprise/latest/release_notes/ocp-4-21-release-notes.html

@openshift-ci
Copy link

openshift-ci bot commented Jan 29, 2026

@jeana-redhat: all tests passed!

Full PR test history. Your PR dashboard.

Details

Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the kubernetes-sigs/prow repository. I understand the commands that are listed here.

Copy link
Contributor

@skopacz1 skopacz1 left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

One comment otherwise LGTM

+
When you install a {gcp-first} and configure it to use {gcp-short} Workload Identity, you can now restrict the {gcp-short} `iam.serviceAccounts.actAs` permission that the Cloud Credential Operator utility grants the Machine API controller service account at the project level to only the compute nodes service account.
+
For more information, see xref:../installing/installing_gcp/installing-gcp-customizations.adoc#restricting-sa-impersonation-compute-sa-gcp_installing-gcp-customizations[Restricting service account impersonation to the compute nodes service account].
Copy link
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I'll leave it to you to verify that this xref works once the main PR merges

Copy link
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Roger, thanks!

@skopacz1 skopacz1 added ok-to-merge and removed merge-review-in-progress Signifies that the merge review team is reviewing this PR merge-review-needed Signifies that the merge review team needs to review this PR labels Jan 29, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

branch/enterprise-4.21 do-not-merge DEPRECATED. Indicates that a PR should not merge. Label can only be manually applied/removed. ok-to-merge size/XS Denotes a PR that changes 0-9 lines, ignoring generated files.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants