cloud-foundation-fabric/fast/stages-multitenant/0-bootstrap-tenant/IAM.md

5.8 KiB

IAM bindings reference

Legend: + additive, conditional.

Organization [org_id #0]

members roles
tn0-admins
group
roles/orgpolicy.policyAdmin +
roles/resourcemanager.organizationViewer +
tn0-gke-dev-0
serviceAccount
roles/orgpolicy.policyAdmin +
tn0-gke-prod-0
serviceAccount
roles/orgpolicy.policyAdmin +
tn0-networking-0
serviceAccount
roles/orgpolicy.policyAdmin +
tn0-pf-dev-0
serviceAccount
roles/orgpolicy.policyAdmin +
tn0-pf-prod-0
serviceAccount
roles/orgpolicy.policyAdmin +
tn0-resman-0
serviceAccount
roles/orgpolicy.policyAdmin +
tn0-sandbox-0
serviceAccount
roles/orgpolicy.policyAdmin +
tn0-security-0
serviceAccount
roles/orgpolicy.policyAdmin +
tn0-teams-0
serviceAccount
roles/orgpolicy.policyAdmin +

Folder test tenant 0 [#1]

members roles
tn0-admins
group
roles/compute.xpnAdmin
roles/logging.admin
roles/owner
roles/resourcemanager.folderAdmin
roles/resourcemanager.projectCreator
tn0-networking-0
serviceAccount
roles/compute.xpnAdmin
tn0-resman-0
serviceAccount
roles/compute.xpnAdmin
roles/logging.admin
roles/owner
roles/resourcemanager.folderAdmin
roles/resourcemanager.projectCreator

Project prod-iac-core-0

members roles
tn0-bootstrap-1
serviceAccount
roles/logging.logWriter +

Project tn0-audit-logs-0

members roles
f260055713332-284719
serviceAccount
roles/logging.bucketWriter +
prod-resman-0
serviceAccount
roles/owner
tn0-resman-0
serviceAccount
roles/owner

Project tn0-iac-core-0

members roles
tn0-admins
group
roles/iam.serviceAccountTokenCreator
roles/iam.workloadIdentityPoolAdmin
SERVICE_IDENTITY_service-networking
serviceAccount
roles/servicenetworking.serviceAgent +
prod-resman-0
serviceAccount
roles/owner
tn0-resman-0
serviceAccount
roles/cloudbuild.builds.editor
roles/iam.serviceAccountAdmin
roles/iam.workloadIdentityPoolAdmin
roles/owner
roles/source.admin
roles/storage.admin