New Google GCP Org Policy will impact GAM service account creation
- Dominant language
- Python
- Stars
- 4.3k
- Forks
- 537
- Avg merge
- 2h 34m
- Merged PRs (30d)
- 9
Description
Google Cloud has added [new default organization policies](https://cloud.google.com/blog/products/identity-security/introducing-stronger-default-org-policies-for-our-customers) for new Workspace/GCP domains that will break GAM service account key configuration. @taers232c fyi. We'll need to 1) encourage more admins to [run GAM on GCE securely](https://github.com/GAM-team/GAM/wiki/Running-GAM-on-Google-Compute-Engine-%28GCE%29-Securely) 2) if that's not possible, disable these restrictions at the GAM project level. We may be able to [do that programatically on the GAM project](https://cloud.google.com/resource-manager/docs/reference/orgpolicy/rest/v2/projects.policies/patch) during project create/update but we should notify the admin that they are reducing their own security posture by doing so.
Contributor guide
No contributing guide indexed for this repository
Assessment
This issue has not been assessed yet.