Skip to content

Avoid project level IAM for specific roles#204

Merged
jku merged 3 commits intosigstore:mainfrom
jku:avoid-project-level-iam-for-specific-roles
Apr 29, 2026
Merged

Avoid project level IAM for specific roles#204
jku merged 3 commits intosigstore:mainfrom
jku:avoid-project-level-iam-for-specific-roles

Conversation

@jku
Copy link
Copy Markdown
Member

@jku jku commented Apr 29, 2026

"google_project_iam_member" is not a good way to grant sensitive roles. Use more specific methods.

jku added 3 commits April 28, 2026 19:56
In the case of KMS we want to hand permissions per keyring.

Signed-off-by: Jussi Kukkonen <[email protected]>
Fulcio SA should only have access to the specific CA pool

Signed-off-by: Jussi Kukkonen <[email protected]>
tiles_tlog workload_iam_member should only have access to specific secrets

Signed-off-by: Jussi Kukkonen <[email protected]>
@jku jku requested a review from a team as a code owner April 29, 2026 11:26
@jku jku merged commit c3a6970 into sigstore:main Apr 29, 2026
5 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants