Skip to content

[DOC] - Document minimal GCP IAM permissions required for deploying and destroying Nebari #583

@marcelovilla

Description

@marcelovilla

Preliminary Checks

Summary

Currently, our docs suggest to use a service account with four predefined roles attached. However, these are very broad permissions and they're far from ideal from a security and principle-of-least-privilege standpoint.

We should define and document custom GCP IAM roles with just enough permissions to deploy and destroy Nebari. This will help users follow best practices and safely integrate Nebari into more restrictive cloud environments.

Metadata

Metadata

Assignees

Type

No type

Projects

Status

Todo 📬

Status

TODO 📬

Relationships

None yet

Development

No branches or pull requests

Issue actions