Limited Permissions Service Account
Nobody has claimed this yet.
Assessment
- Difficulty
- 1/5
- Estimated time
- 1-3 hours
- Newbie friendliness
- 74/100
- Issue type
- Documentation
- Clarity
- Mostly clear
- Activity status
- Quiet
- Tech stack
- google-cloud
- Domain
- documentation
Research direction
Start in the README and review the linked Google Workspace service-account documentation and selective-access references. Explain how to create a custom admin role with only user API and directory API read access, assign it to the service account, and clarify that domain-wide delegation and impersonation are not required. Done means the README points to the relevant setup guidance and describes the limited-permission configuration.
Written by the indexing model from the issue text.
Description
Is your feature request related to a problem? Please describe.
A clear and concise description of what the problem is. Ex. I'm always frustrated when [...]
Describe the solution you'd like
Drawing on @bburky 's feedback to the above PR.
Because the Google docs aren't too clear on this, it's probably worth adding a note to the README to point specifically to the "Assign a role to a service account" docs section and explain how to set up the service account:
https://developers.google.com/workspace/guides/create-credentials#assign_a_role_to_a_service_accountI would suggest to create a custom admin role limited to only user API read and directory API read. Grant the admin role to the service account with "Assign a role to a service account". The service account's maximum permissions are those of the Admin role (the service account will not be restricted to specific OAuth roles like with domain-wide delegation).
The "Optional: Set up domain-wide delegation for a service account" steps can be skipped entirely. This method does not use domain-wide delegation at all or impersonation.
Additionally refer to:
- Dominant language
- Go
- Stars
- 666
- Forks
- 213
- Avg merge
- 2d 1h
- Merged PRs (30d)
- 3
Contributor guide
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
More from awslabs/ssosync
-
Support
Difficulty 2/5 1-3 hours Newbie friendliness 68/100
-
Support
Difficulty 3/5 1-2 days Newbie friendliness 48/100
-
Support
Difficulty 2/5 1-3 hours Newbie friendliness 55/100
-
Q2 — Will ssosync take ownership of an existing AWS group if the name matches, or always create new? OpenSupport
Difficulty 4/5 3-5 days Newbie friendliness 35/100
-
Support
Difficulty 4/5 3-5 days Newbie friendliness 35/100
Similar issues
-
Difficulty 1/5 Under an hour Newbie friendliness 84/100
-
enhancement needs triage
Difficulty 2/5 1-3 hours Newbie friendliness 68/100
-
kind/cleanup
Difficulty 2/5 1-3 hours Newbie friendliness 88/100
kubernetes-sigs/kueue#15947 ·
-
Difficulty 2/5 1-3 hours Newbie friendliness 78/100
sympozium-ai/sympozium#627 ·
-
Difficulty 2/5 1-3 hours Newbie friendliness 86/100