apache / apache/beam

[Playground] Use impersonate_service_account in Terraform

Open
#21,371 0 comments 0 reactions 0 assignees View on GitHub
beam-playground improvement P2
Dominant language
Java
Stars
8.7k
Forks
4.7k
Avg merge
1d 20h
Merged PRs (30d)
196

Description

For security purposes, we need to avoid service account keys in terraform. So that we need to use impersonate_service_account in terraform providers.

Imported from Jira [BEAM-13971](https://issues.apache.org/jira/browse/BEAM-13971). Original Jira may contain additional context.
Reported by: IKozyrev.

Contributor guide

Open the contributing guide

Research direction

Inspect the Playground Terraform configuration and provider definitions to find where service account keys are referenced. Read the original Jira issue for additional context, then determine the required impersonate_service_account setup and verify that the Terraform configuration no longer depends on service account keys.

Written by the indexing model from the issue text.

Assessment

Tech stack
terraform
Domain
cloud, infrastructure, security
Issue type
Refactor
Difficulty
4/5
Estimated time
3-5 days
Activity status
Stale
Clarity
Mostly clear
Newbie friendliness
35/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.