3 ms·
I think the real learning here is not to colocate different things in a single GCP project. AFAIK projects don't cost anything so why not create one per service
by exitheone 5y ago
I think the real learning here is not to colocate different things in a single GCP project. AFAIK projects don't cost anything so why not create one per service?
- asah 5y agoThe way you're wording this suggests that this was a sensible design prior to this vulnerability, but in fact all sorts of tools, config, etc work within a project but not across projects, including IAM. Yes obviously anything can be duplicated but it's a big pain. Probably easier to create separate subnets for VMs that don't trust each other ?
- briffle 5y agoIAM works across projects easily. The "Organization" concept it Google Cloud is used to collect projects, and manage permissions of groups (or subfolders) of projects very easily.
- rantwasp 5y agothe real learning for me is to not use gcp. sounds harsh, but you don’t get second chances when it comes to trust in this context.