Skip to content

Conversation

@bscott-rh
Copy link
Contributor

@bscott-rh bscott-rh commented Nov 14, 2025

@bscott-rh bscott-rh added this to the Continuous Release milestone Nov 14, 2025
@openshift-ci openshift-ci bot added the size/M Denotes a PR that changes 30-99 lines, ignoring generated files. label Nov 14, 2025
@ocpdocs-previewbot
Copy link

ocpdocs-previewbot commented Nov 14, 2025

@openshift-ci
Copy link

openshift-ci bot commented Nov 25, 2025

@bscott-rh: all tests passed!

Full PR test history. Your PR dashboard.

Details

Instructions for interacting with me using PR comments are available here. If you have questions or suggestions related to my behavior, please file an issue against the kubernetes-sigs/prow repository. I understand the commands that are listed here.

roles:
- <role_name>
resources:
- projects/902460926346

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

@lnguyen1401 Would you please confirm if the project number "902460926346" is correct, and corresponds to the project "rhcos-cloud"? I'm asking because I got below instead, thanks in advance!

$ gcloud projects describe rhcos-cloud
createTime: '2019-07-19T17:39:10.423Z'
labels:
  cost-center: '706'
  cost_category: dev
  service-owner: amccrae
  service-phase: dev
lifecycleState: ACTIVE
name: RHCOS cloud
parent:
  id: '710785325000'
  type: folder
projectId: rhcos-cloud
projectNumber: '7991419043'
$ 

where:
+
<role_name>:: Specifies the IAM role that you created for the installation program.
<service_account>:: Specifies the name of the installation program service account. No newline at end of file

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

@lnguyen1401 Do you know which role or permissions are required?

@bscott-rh Per Google doc, "egressFrom.identityType" should be ANY_IDENTITY, ANY_USER_ACCOUNT, or ANY_SERVICE_ACCOUNT instead. And "egressFrom.identities" can be used to list the service accounts and etc.

allowedValues:
- projects/rhcos-cloud
----
. Modify the `iam.allowedPolicyMemberDomains` constraint to allow the service account that the installation program uses to authenticate with {gcp-short} and create storage.

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

@lnguyen1401 @bscott-rh How about showing a sample constraint for such modification?

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I wonder if "iam.managed.allowedPolicyMembers" is a better choice. WDYT?

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

branch/enterprise-4.19 branch/enterprise-4.20 branch/enterprise-4.21 size/M Denotes a PR that changes 30-99 lines, ignoring generated files.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants