Skip to content

Commit

Permalink
Merge pull request #1966 from ameukam/empower-ii-group-auditlogs
Browse files Browse the repository at this point in the history
Read access to read access k8s-artifacts-gcslogs
  • Loading branch information
k8s-ci-robot authored May 4, 2021
2 parents 8539853 + 56c5025 commit 163acfd
Showing 1 changed file with 6 additions and 0 deletions.
6 changes: 6 additions & 0 deletions infra/gcp/ensure-prod-storage.sh
Original file line number Diff line number Diff line change
Expand Up @@ -359,6 +359,12 @@ color 6 "Handling special cases"
$(svc_acct_email "${GCR_BACKUP_TEST_PRODBAK_PROJECT}" "${PROMOTER_SVCACCT}")
done

# Special case: empower k8s-infra-gcs-access-logs@kubernetes.io to read k8s-artifacts-gcslogs
# k8s-artifacts-gcslogs receive and store Cloud Audit logs for k8s-artificats-prod.
ensure_gcs_role_binding "gs://k8s-artifacts-gcslogs" \
"group:k8s-infra-gcs-access-logs@kubernetes.io" \
"objectViewer"

color 6 "Ensuring prod promoter vuln scanning svcacct exists"
ensure_service_account \
"${PROD_PROJECT}" \
Expand Down

0 comments on commit 163acfd

Please sign in to comment.