Skip to content

Insufficient compute.networks.updatePeering rights for creating GKE Autopilot using FAST TF module running on Cloudbuild with FAST created SA #2113

Closed Answered by juliocc
fbadso asked this question in Q&A
Discussion options

You must be logged in to vote

Don't we have a chicken / egg problem when integrate the access right for the 1-resman created SA on a project / VPC resource that is managed further in stage 2-networking?

Yes and no. As you mention, resman doesn't create any projects/vpcs but you can still grant permissions on the folders. The easiest approach is to grant the teams service accounts serviceProjectNetworkAdmin on one of those folders (net/dev, net/prod, or the level one containing the other two)

Replies: 1 comment 3 replies

Comment options

You must be logged in to vote
3 replies
@fbadso
Comment options

@juliocc
Comment options

Answer selected by fbadso
@fbadso
Comment options

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Category
Q&A
Labels
None yet
2 participants