You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Description
At present we have two service accounts representing oci-image-builder ado pipeline. One is defined in sap-kyma-prow project and second one is in kyma-project project. The oci-image-builder must use one and only one identity in our Google Cloud projects.
Reason
Two identities for the same workload may cause inappropriate permissions. It's easy to overlook second identity and do not adjust the permissions on both identities.
Having more than one identity makes oci-image-builder infrastructure more complex and error prone.
AC
oci-image-builder uses only one identity defined in sap-kyma-prow project.
The text was updated successfully, but these errors were encountered:
Description
At present we have two service accounts representing oci-image-builder ado pipeline. One is defined in sap-kyma-prow project and second one is in kyma-project project. The oci-image-builder must use one and only one identity in our Google Cloud projects.
Reason
Two identities for the same workload may cause inappropriate permissions. It's easy to overlook second identity and do not adjust the permissions on both identities.
Having more than one identity makes oci-image-builder infrastructure more complex and error prone.
AC
The text was updated successfully, but these errors were encountered: