Skip to content

Commit 4799b36

Browse files
Merge pull request #935 from flavianmissi/CCO-248
IR-408: request individual permissions for gcs
2 parents 06dfe47 + df639f9 commit 4799b36

File tree

1 file changed

+11
-3
lines changed

1 file changed

+11
-3
lines changed

manifests/01-registry-credentials-request-gcs.yaml

Lines changed: 11 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -17,9 +17,17 @@ spec:
1717
providerSpec:
1818
apiVersion: cloudcredential.openshift.io/v1
1919
kind: GCPProviderSpec
20-
predefinedRoles:
21-
- roles/storage.admin
22-
- roles/resourcemanager.tagUser
20+
permissions:
21+
- storage.buckets.create
22+
- storage.buckets.delete
23+
- storage.buckets.get
24+
- storage.buckets.list
25+
- storage.buckets.createTagBinding
26+
- storage.buckets.listEffectiveTags
27+
- storage.objects.create
28+
- storage.objects.delete
29+
- storage.objects.get
30+
- storage.objects.list
2331
skipServiceCheck: true
2432
serviceAccountNames:
2533
- cluster-image-registry-operator

0 commit comments

Comments
 (0)