Skip to content

Start using dedicated Google Service Account for every staging registry. #9486

@upodroid

Description

@upodroid

For all projects using us-central1-docker.pkg/k8s-staging-images/* staging registries listed here, you'll need to start using user-supplied service account that is dedicated to your GitHub repository.

Docs: https://docs.cloud.google.com/build/docs/securing-builds/configure-user-specified-service-accounts

in cloudbuild.yaml, you'll need to add this line:

serviceAccount: projects/k8s-staging-images/serviceAccounts/[REGISTRY_NAME]-sa@k8s-staging-images.iam.gserviceaccount.com

/priority important-soon

Metadata

Metadata

Assignees

No one assigned

    Labels

    priority/important-soonMust be staffed and worked on either currently, or very soon, ideally in time for the next release.

    Type

    No type
    No fields configured for issues without a type.

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions