Update docs about role automatically granted to dataform SA

This commit is contained in:
Wiktor Niesiobędzki 2024-03-02 13:24:51 +00:00 committed by Wiktor Niesiobędzki
parent 4aa08f63d3
commit ef19524b0b
2 changed files with 14 additions and 13 deletions

View File

@ -213,19 +213,20 @@ module "project" {
This table lists all affected services and roles that you need to grant to service identities This table lists all affected services and roles that you need to grant to service identities
| service | service identity | role | | service | service identity | role |
|---|---|---| |------------------------------------|----------------------|----------------------------------------|
| apigee.googleapis.com | apigee | roles/apigee.serviceAgent | | apigee.googleapis.com | apigee | roles/apigee.serviceAgent |
| artifactregistry.googleapis.com | artifactregistry | roles/artifactregistry.serviceAgent | | artifactregistry.googleapis.com | artifactregistry | roles/artifactregistry.serviceAgent |
| cloudasset.googleapis.com | cloudasset | roles/cloudasset.serviceAgent | | cloudasset.googleapis.com | cloudasset | roles/cloudasset.serviceAgent |
| cloudbuild.googleapis.com | cloudbuild | roles/cloudbuild.builds.builder | | cloudbuild.googleapis.com | cloudbuild | roles/cloudbuild.builds.builder |
| dataplex.googleapis.com | dataplex | roles/dataplex.serviceAgent | | dataform.googleapis.com | dataform | roles/dataform.serviceAgent |
| dlp.googleapis.com | dlp | roles/dlp.serviceAgent | | dataplex.googleapis.com | dataplex | roles/dataplex.serviceAgent |
| gkehub.googleapis.com | fleet | roles/gkehub.serviceAgent | | dlp.googleapis.com | dlp | roles/dlp.serviceAgent |
| meshconfig.googleapis.com | servicemesh | roles/anthosservicemesh.serviceAgent | | gkehub.googleapis.com | fleet | roles/gkehub.serviceAgent |
| meshconfig.googleapis.com | servicemesh | roles/anthosservicemesh.serviceAgent |
| multiclusteringress.googleapis.com | multicluster-ingress | roles/multiclusteringress.serviceAgent | | multiclusteringress.googleapis.com | multicluster-ingress | roles/multiclusteringress.serviceAgent |
| pubsub.googleapis.com | pubsub | roles/pubsub.serviceAgent | | pubsub.googleapis.com | pubsub | roles/pubsub.serviceAgent |
| sqladmin.googleapis.com | sqladmin | roles/cloudsql.serviceAgent | | sqladmin.googleapis.com | sqladmin | roles/cloudsql.serviceAgent |
## Shared VPC ## Shared VPC

View File

@ -146,7 +146,7 @@
service_agent: "service-%s@dataflow-service-producer-prod.iam.gserviceaccount.com" service_agent: "service-%s@dataflow-service-producer-prod.iam.gserviceaccount.com"
- name: "dataform" - name: "dataform"
service_agent: "service-%s@gcp-sa-dataform.iam.gserviceaccount.com" service_agent: "service-%s@gcp-sa-dataform.iam.gserviceaccount.com"
jit: true jit: true # roles/dataform.serviceAgent
- name: "datafusion" - name: "datafusion"
service_agent: "service-%s@gcp-sa-datafusion.iam.gserviceaccount.com" service_agent: "service-%s@gcp-sa-datafusion.iam.gserviceaccount.com"
- name: "datalabeling" - name: "datalabeling"