cloud-foundation-fabric
cloud-foundation-fabric copied to clipboard
Possibly over-privileged service account in scheduled-asset-inventory-export-bq
On line 39 of the scheduled-asset-inventory-export-bq/main.tf the robot service account is granted projectIamAdmin.
"roles/resourcemanager.projectIamAdmin" = ["serviceAccount:${module.project.service_accounts.robots.cloudasset}"]
Granting project-wide admin is generally discouraged. Is such a high privilege really needed?
@lcaggio can you take a look? if that's really needed, we might want to limit it via delegated role grants.
@lcaggio can you tal?
@lcaggio can you check this, or should we close it?