[Playground] Use impersonate_service_account in Terraform
Open
beam-playground
improvement
P2
- Dominant language
- Java
- Stars
- 8.7k
- Forks
- 4.7k
- Avg merge
- 1d 20h
- Merged PRs (30d)
- 196
Description
For security purposes, we need to avoid service account keys in terraform. So that we need to use impersonate_service_account in terraform providers.
Imported from Jira [BEAM-13971](https://issues.apache.org/jira/browse/BEAM-13971). Original Jira may contain additional context.
Reported by: IKozyrev.
Contributor guide
Research direction
Inspect the Playground Terraform configuration and provider definitions to find where service account keys are referenced. Read the original Jira issue for additional context, then determine the required impersonate_service_account setup and verify that the Terraform configuration no longer depends on service account keys.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- terraform
- Domain
- cloud, infrastructure, security
- Issue type
- Refactor
- Difficulty
- 4/5
- Estimated time
- 3-5 days
- Activity status
- Stale
- Clarity
- Mostly clear
- Newbie friendliness
- 35/100