Bug 1374348 - explicit required permissions for the GCE provider user
Summary: explicit required permissions for the GCE provider user
Keywords:
Status: CLOSED WONTFIX
Alias: None
Product: Red Hat CloudForms Management Engine
Classification: Red Hat
Component: Documentation
Version: 5.6.0
Hardware: x86_64
OS: Linux
medium
medium
Target Milestone: GA
: 5.7.0
Assignee: Red Hat CloudForms Documentation
QA Contact: Red Hat CloudForms Documentation
URL:
Whiteboard: doc
Depends On:
Blocks:
TreeView+ depends on / blocked
 
Reported: 2016-09-08 13:25 UTC by Colin Arnott
Modified: 2018-05-30 23:45 UTC (History)
10 users (show)

Fixed In Version:
Doc Type: If docs needed, set a value
Doc Text:
Clone Of:
Environment:
Last Closed: 2018-04-04 04:41:18 UTC
Category: ---
Cloudforms Team: Unknown
Target Upstream Version:


Attachments (Terms of Use)

Description Colin Arnott 2016-09-08 13:25:23 UTC
Document URL: 
https://access.redhat.com/documentation/en/red-hat-cloudforms/4.1/managing-providers/#adding_amazon_ec2_providers

Section Number and Name: 
3.4.1.8 Adding Google Compute Engine Providers: service account

Describe the issue: 
The GCE provider currently requires the Service Account JSON key, my security standards prevent me from giving cart blanch access to my GCE environment. Can you please enumerate the permissions required by CFME so that I can use least privilege when creating the CFME user for my GCE environment.

Suggestions for improvement: 
Add a section indicating required permissions for the GCE provider.

Additional information:

Comment 10 Andrew Dahms 2017-03-06 05:06:59 UTC
Moving to 'NEW' while assigned to the default assignee.

Comment 11 Andrew Dahms 2018-04-04 04:41:18 UTC
Thank you for raising this bug.

After further discussion with the program team, we have been given the advice not to document specific permissions for service accounts at this time based on the following article -

http://cloudformsblog.redhat.com/2017/08/16/security-management-operations/

As such, I will be closing this bug for now, but we can re-investigate this request again in the future if required.

Comment 12 Andrew Dahms 2018-05-30 23:45:13 UTC
Cancelling old needinfo request.


Note You need to log in before you can comment on or make changes to this bug.