-
Notifications
You must be signed in to change notification settings - Fork 21
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Verify required permission for Leo SA #806
Comments
This is not new -- I asked about this in November. Do we have an official answer? |
The ask here is what permissions the Leo SA needs in broad-dsde-prod, correct? I believe we need storage admin, because we create buckets in broad-dsde-prod. Other operations are all done in users' billing projects, so are probably not needed in broad-dsde-prod. We may be able to test this:
|
you probably also need SQLProxy rights (i think it's called SQLClient in
IAM).
|
Tested in dev: |
Also needs |
Bernick pinged the #dsp-infosec-champions room in slack asking that we look into the service specific Service Accounts to verify what permissions they actually need.
The text was updated successfully, but these errors were encountered: