-
Notifications
You must be signed in to change notification settings - Fork 168
Open
Description
Currently, GCP PD CSI driver requires a Service Account that has the iam.serviceAccountUser role:
gcp-compute-persistent-disk-csi-driver/docs/kubernetes/user-guides/driver-install.md
Line 21 in eead51b
| roles/iam.serviceAccountUser |
However, that goes agains Google's Security Health Analytics recommendation:
Is it possible to remove this role from the driver's requirements? What would it take to do that?
I looked around this repository but couldn't find the reason this role is required, only this comment that references it: #134 (comment)
Metadata
Metadata
Assignees
Labels
No labels