cloud-foundation-fabric/fast/stages/1-resman/IAM.md

12 KiB

IAM bindings reference

Legend: + additive, conditional.

Organization [org_id #0]

members roles
dev-resman-dp-0
serviceAccount
roles/orgpolicy.policyAdmin +
roles/billing.user +
dev-resman-gke-0
serviceAccount
roles/billing.user +
dev-resman-pf-0
serviceAccount
roles/orgpolicy.policyAdmin +
roles/billing.costsManager +
roles/billing.user +
prod-resman-dp-0
serviceAccount
roles/orgpolicy.policyAdmin +
roles/billing.user +
prod-resman-gke-0
serviceAccount
roles/billing.user +
prod-resman-net-0
serviceAccount
roles/billing.user +
roles/compute.orgFirewallPolicyAdmin +
roles/compute.xpnAdmin +
prod-resman-pf-0
serviceAccount
roles/orgpolicy.policyAdmin +
roles/billing.costsManager +
roles/billing.user +
prod-resman-sec-0
serviceAccount
roles/accesscontextmanager.policyAdmin +
roles/billing.user +

Folder development [#0]

members roles
dev-resman-dp-0
serviceAccount
organizations/[org_id #0]/roles/serviceProjectNetworkAdmin
roles/logging.admin
roles/owner
roles/resourcemanager.folderAdmin
roles/resourcemanager.projectCreator

Folder development [#1]

members roles
dev-resman-gke-0
serviceAccount
roles/compute.xpnAdmin
roles/logging.admin
roles/owner
roles/resourcemanager.folderAdmin
roles/resourcemanager.projectCreator

Folder development [#2]

members roles
dev-resman-dp-0
serviceAccount
organizations/[org_id #0]/roles/serviceProjectNetworkAdmin
dev-resman-gke-0
serviceAccount
organizations/[org_id #0]/roles/serviceProjectNetworkAdmin
dev-resman-pf-0
serviceAccount
organizations/[org_id #0]/roles/serviceProjectNetworkAdmin

Folder development [#3]

members roles
dev-resman-pf-0
serviceAccount
organizations/[org_id #0]/roles/serviceProjectNetworkAdmin
roles/logging.admin
roles/owner
roles/resourcemanager.folderAdmin
roles/resourcemanager.projectCreator

Folder networking

members roles
gcp-network-admins
group
roles/editor
prod-resman-net-0
serviceAccount
roles/compute.xpnAdmin
roles/logging.admin
roles/owner
roles/resourcemanager.folderAdmin
roles/resourcemanager.projectCreator

Folder production [#0]

members roles
prod-resman-dp-0
serviceAccount
organizations/[org_id #0]/roles/serviceProjectNetworkAdmin
roles/logging.admin
roles/owner
roles/resourcemanager.folderAdmin
roles/resourcemanager.projectCreator

Folder production [#1]

members roles
prod-resman-gke-0
serviceAccount
roles/compute.xpnAdmin
roles/logging.admin
roles/owner
roles/resourcemanager.folderAdmin
roles/resourcemanager.projectCreator

Folder production [#2]

members roles
prod-resman-dp-0
serviceAccount
organizations/[org_id #0]/roles/serviceProjectNetworkAdmin
prod-resman-gke-0
serviceAccount
organizations/[org_id #0]/roles/serviceProjectNetworkAdmin
prod-resman-pf-0
serviceAccount
organizations/[org_id #0]/roles/serviceProjectNetworkAdmin

Folder production [#3]

members roles
prod-resman-pf-0
serviceAccount
organizations/[org_id #0]/roles/serviceProjectNetworkAdmin
roles/logging.admin
roles/owner
roles/resourcemanager.folderAdmin
roles/resourcemanager.projectCreator

Folder sandbox

members roles
dev-resman-sbox-0
serviceAccount
roles/logging.admin
roles/owner
roles/resourcemanager.folderAdmin
roles/resourcemanager.projectCreator

Folder security

members roles
gcp-security-admins
group
roles/viewer
prod-resman-sec-0
serviceAccount
roles/logging.admin
roles/owner
roles/resourcemanager.folderAdmin
roles/resourcemanager.projectCreator

Folder teams

members roles
prod-resman-teams-0
serviceAccount
roles/compute.xpnAdmin
roles/logging.admin
roles/owner
roles/resourcemanager.folderAdmin
roles/resourcemanager.projectCreator

Folder teams test

members roles
prod-teams-teams-test-0
serviceAccount
roles/compute.xpnAdmin
roles/logging.admin
roles/owner
roles/resourcemanager.folderAdmin
roles/resourcemanager.projectCreator

Project prod-iac-core-0

members roles
dev-pf-resman-pf-1
serviceAccount
roles/logging.logWriter +
dev-resman-dp-1
serviceAccount
roles/logging.logWriter +
dev-resman-gke-1
serviceAccount
roles/logging.logWriter +
prod-pf-resman-pf-1
serviceAccount
roles/logging.logWriter +
prod-resman-dp-1
serviceAccount
roles/logging.logWriter +
prod-resman-gke-1
serviceAccount
roles/logging.logWriter +
prod-resman-net-1
serviceAccount
roles/logging.logWriter +
prod-resman-sec-1
serviceAccount
roles/logging.logWriter +