3 ms·
Just temporary add the user to yet another group with the needed permissions. Or use the IAM conditional policy. Or impersonate a service-account (which is more
by negus 3y ago
Just temporary add the user to yet another group with the needed permissions. Or use the IAM conditional policy.
Or impersonate a service-account (which is more or less the same as asuming AWS role)
GCP's lack of "AWS role" concept is great and straigtforward.
As well as its lack of both identity-bound policies and resource-bound policies at the same time.
- kasey_junk 3y agoYou can’t impersonate a service account with the console. The rest of those are either manual or too broad.