service account 만들어서 role 적절히 추가하고 있는데
내가 필요한건 compute.networks.create 라 치면
Roles 들어가서 이 permission 갖고 있는 role이 뭐가 있나 보고 "적당히" 골라서 service account에 추가 하고 있음
근데 이렇게 하는게 맞음?; 나는 딱 compute.networks.create 이 권한만 필요한데 안쓰는 퍼미션을 수십개나 더 추가하는식이네
차라리 service account 마다 custom role 만드는게 맞나?
뭐가 best practice임?
이 댓글은 게시물 작성자가 삭제하였습니다.
https://cloud.google.com/blog/products/identity-security/dont-get-pwned-practicing-the-principle-of-least-privilege