Skip to content

[AN-181] Give default compute SA the secretAccessor role #377

New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Merged
merged 1 commit into from
Nov 22, 2024

Conversation

lucymcnatt
Copy link
Contributor

@lucymcnatt lucymcnatt commented Nov 7, 2024

@lucymcnatt lucymcnatt requested a review from a team as a code owner November 7, 2024 14:08
@lucymcnatt lucymcnatt requested review from davidangb and marctalbott and removed request for a team November 7, 2024 14:08
Copy link

sonarqubecloud bot commented Nov 7, 2024

Copy link
Collaborator

@davidangb davidangb left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

+1 for code syntax.

I assume you've run this through appsec and everyone agrees this is a Good Idea?

@lucymcnatt
Copy link
Contributor Author

I assume you've run this through appsec and everyone agrees this is a Good Idea?

We've submitted a 1-pager about these changes and gotten preliminary approval, but will hold off on merging until there's a final decision
https://broadinstitute.slack.com/archives/CADU7L0SZ/p1730223296197239

Copy link
Member

@marctalbott marctalbott left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This will only give the SA the secretAccessor role in new Google projects that RBS creates. To make sure all new workspaces get this change, you'll need to set up new project pools

EDIT: Other than that this looks good!

@lucymcnatt
Copy link
Contributor Author

After discussing with the team, we've decided to go ahead and merge this without creating new project pool;

  • this change will be propagated to prod with some other Batch changes next week
  • this role is only necessary for accessing private dockerhub images with the new batch backend so not something we need urgently in the lower environments.

@lucymcnatt lucymcnatt enabled auto-merge (squash) November 22, 2024 15:29
@lucymcnatt lucymcnatt merged commit 6031dcb into master Nov 22, 2024
5 checks passed
@lucymcnatt lucymcnatt deleted the AN-181-batch-permissions branch November 22, 2024 15:30
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

4 participants