-
Notifications
You must be signed in to change notification settings - Fork 1.9k
OSDOCS#17996: reduce scope of mapi controller perms for gcp RNs #105690
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
base: enterprise-4.21
Are you sure you want to change the base?
OSDOCS#17996: reduce scope of mapi controller perms for gcp RNs #105690
Conversation
|
🤖 Thu Jan 29 16:35:32 - Prow CI generated the docs preview: |
|
@jeana-redhat: all tests passed! Full PR test history. Your PR dashboard. DetailsInstructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the kubernetes-sigs/prow repository. I understand the commands that are listed here. |
skopacz1
left a comment
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
One comment otherwise LGTM
| + | ||
| When you install a {gcp-first} and configure it to use {gcp-short} Workload Identity, you can now restrict the {gcp-short} `iam.serviceAccounts.actAs` permission that the Cloud Credential Operator utility grants the Machine API controller service account at the project level to only the compute nodes service account. | ||
| + | ||
| For more information, see xref:../installing/installing_gcp/installing-gcp-customizations.adoc#restricting-sa-impersonation-compute-sa-gcp_installing-gcp-customizations[Restricting service account impersonation to the compute nodes service account]. |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
I'll leave it to you to verify that this xref works once the main PR merges
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Roger, thanks!
Version(s):
4.21
Issue:
OSDOCS-17996
Link to docs preview:
Restricting service account impersonation to the compute nodes service account
QE review:
Additional information:
Rel notes to accompany #105412