Action Service Accounts Proof of Concept #2713
Draft
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
Ticket: https://broadworkbench.atlassian.net/browse/ID-433
I'm investigating/prototyping the feasibility of using Action Service Accounts instead of Pet Service Accounts for data access in Terra. This PR makes Rawls add the
read
,write
, andcompute
action service accounts to the appropriate GCP IAM Roles for workspaces on projects and buckets. The goal is to demonstrate data localization in a workspace without the use of Pet Service Account authorization.PR checklist
model/
, then you should publish a new officialrawls-model
and updaterawls-model
in Orchestration's dependencies.