From 8df02071de360de7c91d8ac43d14df6beec2b564 Mon Sep 17 00:00:00 2001 From: Aaron Crickenberger Date: Fri, 6 Aug 2021 11:11:40 -0700 Subject: [PATCH] infra/gcp/main: _actually_ use roles/container.admin --- infra/gcp/ensure-main-project.sh | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/infra/gcp/ensure-main-project.sh b/infra/gcp/ensure-main-project.sh index e771c4ded5d..6a01c9ae023 100755 --- a/infra/gcp/ensure-main-project.sh +++ b/infra/gcp/ensure-main-project.sh @@ -214,7 +214,7 @@ function empower_cluster_admins_and_users() { prow_deployer_acct="prow-deployer@k8s-infra-prow-build-trusted.iam.gserviceaccount.com" # TODO(spiffxp): use container.deployer once we figure out why it isn't getting RBAC privileges old_prow_deployer_role=$(custom_org_role_name "container.deployer") - prow_deployer_role=$(custom_org_role_name "container.deployer") + prow_deployer_role="roles/container.admin" color 6 "Empowering ${prow_deployer_acct} to deploy to clusters in project: ${project}" ensure_removed_project_role_binding "${project}" "serviceAccount:${prow_deployer_acct}" "${old_prow_deployer_role}" ensure_project_role_binding "${project}" "serviceAccount:${prow_deployer_acct}" "${prow_deployer_role}"