GAM-team / GAM-team/GAM

New Google GCP Org Policy will impact GAM service account creation

Open
#1,679 1 comment 0 reactions 1 assignee Claimed by @jay0lee View on GitHub
enhancement
Dominant language
Python
Stars
4.3k
Forks
537
Avg merge
2h 34m
Merged PRs (30d)
9

Description

Google Cloud has added [new default organization policies](https://cloud.google.com/blog/products/identity-security/introducing-stronger-default-org-policies-for-our-customers) for new Workspace/GCP domains that will break GAM service account key configuration. @taers232c fyi. We'll need to 1) encourage more admins to [run GAM on GCE securely](https://github.com/GAM-team/GAM/wiki/Running-GAM-on-Google-Compute-Engine-%28GCE%29-Securely) 2) if that's not possible, disable these restrictions at the GAM project level. We may be able to [do that programatically on the GAM project](https://cloud.google.com/resource-manager/docs/reference/orgpolicy/rest/v2/projects.policies/patch) during project create/update but we should notify the admin that they are reducing their own security posture by doing so.

Contributor guide

No contributing guide indexed for this repository

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.