GCP Service Account Impersonation in Terraform Simplifying Access Control

แชร์
ฝัง
  • เผยแพร่เมื่อ 14 ต.ค. 2024

ความคิดเห็น • 6

  • @leandrojpg
    @leandrojpg 5 หลายเดือนก่อน +1

    Congratulations for sharing, this helps a lot, hundreds of materials explain in key terms what is very insecure.
    One question, don't you need to log in with gcloud before running terraform?
    Just setting the service account will Terraform take care of this under the hood?

    • @thecloudbaba8668
      @thecloudbaba8668  5 หลายเดือนก่อน

      Yes, absolutely. Cloud auth login is needed before you run terraform..

    • @leandrojpg
      @leandrojpg 5 หลายเดือนก่อน

      But understand what it looks like in automation in a real environment, why did you do this on your machine. But it's not ideal, right? what is the solution?

    • @thecloudbaba8668
      @thecloudbaba8668  5 หลายเดือนก่อน

      It’s an ideal approach. When you run gclouud auth login, you get authenticated using password and MFA. This approach is secure from the key-based approach. Hope it make sense

    • @leandrojpg
      @leandrojpg 5 หลายเดือนก่อน

      @@thecloudbaba8668 So this is good for you to run on your machine, right? because in an automation to use terraform this wouldn't be the best method, would it?

    • @thecloudbaba8668
      @thecloudbaba8668  5 หลายเดือนก่อน +1

      That is the best method.. always use impersonation service account which is keyless based authentication and authorization