Skip to content

Instantly share code, notes, and snippets.

@janmasarik
Created August 19, 2020 12:14
Show Gist options
  • Star 0 You must be signed in to star a gist
  • Fork 0 You must be signed in to fork a gist
  • Save janmasarik/97da3fe11f53314aa292ed48bfe1a32b to your computer and use it in GitHub Desktop.
Save janmasarik/97da3fe11f53314aa292ed48bfe1a32b to your computer and use it in GitHub Desktop.
apiVersion: constraints.gatekeeper.sh/v1alpha1
kind: GCPIAMAllowedBindingsConstraintV3
metadata:
name: iam-restrict-editor-on-default-sa
annotations:
description: Default service accounts should not have editor privileges
spec:
severity: high
match:
target:
- "organizations/**"
parameters:
mode: denylist
role: roles/editor
members:
- serviceAccount:*-compute@developer.gserviceaccount.com
- serviceAccount:*@appspot.gserviceaccount.com
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment