-
Notifications
You must be signed in to change notification settings - Fork 839
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Grant GCR write privileges to prow-build Service Account #1393
Conversation
Potential Fix for build failure of /assign @spiffxp |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
@ameukam -- An idea about special-casing this.
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
/hold
So thank you for submitting this, but I'm trying to figure out if this is really how we want to proceed vs. other alternatives
The k8s-infra-prow-build cluster runs untrusted jobs (PRs), and this would allow any of those to write to gcr.io/k8s-staging-ci-images.
At the same time, we have all these @kubernetes.io groups that try to restrict who can write to these repos. I'm not sure we want to completely bypass that security mechanism.
Looks like I reviewed a stale version of this PR. Two thoughts:
|
I'm fine with this in the interim. |
Grant prow-build Service Account privileges to write to GCR registries for the staging projects. Signed-off-by: Arnaud Meukam <ameukam@gmail.com>
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
/approve
/lgtm
/hold cancel
[APPROVALNOTIFIER] This PR is APPROVED This pull-request has been approved by: ameukam, spiffxp The full list of commands accepted by this bot can be found here. The pull request process is described here
Needs approval from an approver in each of these files:
Approvers can indicate their approval by writing |
For reasons I no longer have the visibility to troubleshoot, it appears as though service account membership in a group isn't being picked up. https://gsuiteupdates.googleblog.com/2020/08/service-accounts-in-google-groups-beta.html leads me to believe it should be, but our gsuite may not be in beta |
Grant prow-build Service Account privileges to write to GCR registries
for the staging projects.
Signed-off-by: Arnaud Meukam ameukam@gmail.com