Documentation missing for Google service account setup
- Dominant language
- Go
- Stars
- 666
- Forks
- 213
- Avg merge
- 1d 7h
- Merged PRs (30d)
- 4
Description
**Describe the bug**
In the README/Google section there is no detail of which role in GCP is required for the service account. The linked Google documentation (https://developers.google.com/workspace/guides/create-credentials#google-cloud-console) states 'optionally assign roles to your service account to grant access to your cloud resources'. Then there is a section on assigning a role to the service account for the Google Admin access.
For ssosync to work the service account will need some permissions to both Google Cloud & Google Workspace. The documentation should provide this information.
**To Reproduce**
Read the README & observe the lack of detail on which roles to assign.
**Expected behavior**
README provides full details of roles required for Google Cloud & Google Workspace access, or if not required this should be stated.
Examples of how to test that you have the correct access set up would also be useful. The likely audience here is AWS customers who may not be running any workloads in GCP so specific guidance on configuring appropriate access to sensitive APIs is important.
**Additional context**
Contributor guide
Research direction
Start with the README/Google section and review the linked Google Cloud credential guide. Determine and document the required Google Cloud and Google Workspace roles, including whether any are unnecessary, and add examples for verifying access to the required APIs. Done means the README gives complete setup guidance for service accounts.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- gcp, google-cloud
- Domain
- cloud, documentation
- Issue type
- Documentation
- Difficulty
- 4/5
- Estimated time
- 3-5 days
- Activity status
- Stale
- Clarity
- Mostly clear
- Newbie friendliness
- 38/100