To use this cloudbuild.yaml
the following pre-reqs need to be met:
- Create a invoker service account (e.g.
service-invoker@my-project.iam.gserviceaccount.com
) - Grant the
Cloud Run Invoker
/Cloud Function Invoker
role / permissions to invoker service account - Grant
roles/iam.serviceAccountOpenIdTokenCreator
to the Cloud Build service account for the invoker service account - Enable the
iamcredentials.googleapis.com
API