Skip to content

Commit c5926a7

Browse files
authored
Adding missing permissions to workload scanning to make it work with GCR images (#28)
1 parent a575ed2 commit c5926a7

File tree

1 file changed

+3
-0
lines changed

1 file changed

+3
-0
lines changed

modules/services/workload-scan/controller.tf

Lines changed: 3 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -15,6 +15,9 @@ resource "google_project_iam_custom_role" "controller" {
1515
"artifactregistry.repositories.list",
1616
"artifactregistry.dockerimages.get",
1717
"artifactregistry.dockerimages.list",
18+
"storage.objects.get",
19+
"storage.buckets.list",
20+
"storage.objects.list",
1821

1922
# workload identity federation
2023
"iam.serviceAccounts.getAccessToken",

0 commit comments

Comments
 (0)