GoogleCloudPlatform / GoogleCloudPlatform/pubsec-declarative-toolkit

Implement Authoritative IAM Permissions (MVP)

Open
#312 1 comment 0 reactions 1 assignee Claimed by @ovidiuasiminei-ssc View on GitHub
enhancement security-controls
Dominant language
Shell
Stars
36
Forks
26
PR merge metrics
No merged PRs in 30d

Description

As a security admin,

I want config controller to have an authoritative list of IAM permissions for each level of the GCP organization (org, folders and projects),

so that any additional permissions granted through other means would be automatically reverted by the configuration drift protection.

**Refinement Notes:**

Clarifying Discussion: making use of **IAMPolicy** as much as possible for all the different level of that landing zone

**In Scope:**

- will address/fix bug [#3626]
- MVP

**Out of Scope:**

- nothing noted

Contributor guide

Open the contributing guide

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.