4 ms·
just a couple examples: the default service account is a project editor, which is insanely over-privileged, yet everything tries to use it, and all the demos.
by idunno246 8y ago
just a couple examples:
the default service account is a project editor, which is insanely over-privileged, yet everything tries to use it, and all the demos. Appengine only supports one service account for all apps, even if you have multiple apps, also Editor. similar things in gke.
Their pre-defined roles are a mess, and not consistent across services. Theres a role called 'dataflow admin' defined as the 'minimal permissions to run a job' which isn't what id call admin.
So if you try to use custom roles instead, cause the predefined roles are crazy, they will make breaking changes to permissions(literally did this last week with no notice).
Support access doesnt use IAM and only supports users, not groups, and no api - you have to go to a web form and add each user individually. good luck if you have more than a couple users, and have fun trying to keep that in sync.
The fact that its tied to gsuite is a problem as well, a gsuite admin is also a gcp admin, which is generally owned by different orgs(IT vs dev).
it seems like every month we have a new breaking change, or price change(maps is biting us constantly for some reason)
ultimately what it comes down to is weve been burned enough that we dont trust google
- danpalmer 8y agoThanks, lots of good details, this does make sense. We have hit a few of these. I hadn't even thought about the GSuite/GCP crossover – that's kind of good for us, but yeah in a larger company I guess they would be totally different orgs.