@@ -46,6 +46,7 @@ metadata:
4646 cnrm.cloud.google.com/project-id: ${GKE_PROJECT_ID}
4747 cnrm.cloud.google.com/deletion-policy: "abandon"
4848 cnrm.cloud.google.com/disable-dependent-services: "false"
49+ resourcemanager.cnrm.cloud.google.com/namespaces/config-control/Project/${GKE_PROJECT_ID}
4950 name: artifactregistry.googleapis.com
5051 namespace: config-control
5152EOF
@@ -66,6 +67,7 @@ metadata:
6667 cnrm.cloud.google.com/project-id: ${GKE_PROJECT_ID}
6768 cnrm.cloud.google.com/deletion-policy: "abandon"
6869 cnrm.cloud.google.com/disable-dependent-services: "false"
70+ resourcemanager.cnrm.cloud.google.com/namespaces/config-control/Project/${GKE_PROJECT_ID}
6971 name: containeranalysis.googleapis.com
7072 namespace: config-control
7173EOF
@@ -77,6 +79,7 @@ metadata:
7779 cnrm.cloud.google.com/project-id: ${GKE_PROJECT_ID}
7880 cnrm.cloud.google.com/deletion-policy: "abandon"
7981 cnrm.cloud.google.com/disable-dependent-services: "false"
82+ resourcemanager.cnrm.cloud.google.com/namespaces/config-control/Project/${GKE_PROJECT_ID}
8083 name: containerscanning.googleapis.com
8184 namespace: config-control
8285EOF
@@ -93,6 +96,33 @@ git push origin main
9396
9497## Check deployments
9598
99+ {{< mermaid >}}
100+ graph TD;
101+ IAMServiceAccount-->Project
102+ IAMPartialPolicy-->IAMServiceAccount
103+ ConfigConnectorContext-->IAMServiceAccount
104+ IAMPolicyMember-->IAMServiceAccount
105+ IAMPolicyMember-->Project
106+ IAMPolicyMember-->IAMServiceAccount
107+ IAMPolicyMember-->Project
108+ IAMPolicyMember-->IAMServiceAccount
109+ IAMPolicyMember-->Project
110+ IAMPolicyMember-->IAMServiceAccount
111+ IAMPolicyMember-->Project
112+ IAMPolicyMember-->IAMServiceAccount
113+ IAMPolicyMember-->Project
114+ Service-->Project
115+ IAMPolicyMember-->IAMServiceAccount
116+ IAMPolicyMember-->Project
117+ Service-->Project
118+ Service-->Project
119+ IAMPolicyMember-->IAMServiceAccount
120+ IAMPolicyMember-->Project
121+ Service-->Project
122+ Service-->Project
123+ Service-->Project
124+ {{< /mermaid >}}
125+
96126List the GCP resources created:
97127``` Bash
98128gcloud projects get-iam-policy $GKE_PROJECT_ID \
0 commit comments