GoogleCloudPlatform / GoogleCloudPlatform/pubsec-declarative-toolkit
Implement Authoritative IAM Permissions (MVP)
Open
enhancement
security-controls
- Dominant language
- Shell
- Stars
- 36
- Forks
- 26
- PR merge metrics
- No merged PRs in 30d
Description
As a security admin,
I want config controller to have an authoritative list of IAM permissions for each level of the GCP organization (org, folders and projects),
so that any additional permissions granted through other means would be automatically reverted by the configuration drift protection.
**Refinement Notes:**
Clarifying Discussion: making use of **IAMPolicy** as much as possible for all the different level of that landing zone
**In Scope:**
- will address/fix bug [#3626]
- MVP
**Out of Scope:**
- nothing noted
Contributor guide
Assessment
This issue has not been assessed yet.