What would you like to happen?
Goal: Grafana code has minimal permissions in apache-beam-testing it needs to surface Beam metrics, instead of operating under default compute engine service account.
My understanding of the process:
-
We create a new, least-privilege IAM service account in apache-beam-testing (e.g., grafana-sa), We grant this SA the necessary roles to fetch the metrics (e.g., roles/bigquery.dataViewer if needed).
-
We create a Kubernetes Service account (KSA). This is the identity Grafana Pod will eventually use.
-
We create an IAM binding that maps KSA to IAM SA
-
We configure the GKE cluster and its node pools to use Workload Identity
-
We configure the Grafana GKE deployment to use the KSA we created.
I never done this so my undestanding might have flaws. Docs:
https://docs.cloud.google.com/kubernetes-engine/docs/how-to/service-accounts#service-account-comparison
https://docs.cloud.google.com/kubernetes-engine/docs/concepts/workload-identity
Issue Priority
Priority: 2 (default / most feature requests should be filed as P2)
Issue Components
What would you like to happen?
Goal: Grafana code has minimal permissions in apache-beam-testing it needs to surface Beam metrics, instead of operating under default compute engine service account.
My understanding of the process:
We create a new, least-privilege IAM service account in apache-beam-testing (e.g., grafana-sa), We grant this SA the necessary roles to fetch the metrics (e.g., roles/bigquery.dataViewer if needed).
We create a Kubernetes Service account (KSA). This is the identity Grafana Pod will eventually use.
We create an IAM binding that maps KSA to IAM SA
We configure the GKE cluster and its node pools to use Workload Identity
We configure the Grafana GKE deployment to use the KSA we created.
I never done this so my undestanding might have flaws. Docs:
https://docs.cloud.google.com/kubernetes-engine/docs/how-to/service-accounts#service-account-comparison
https://docs.cloud.google.com/kubernetes-engine/docs/concepts/workload-identity
Issue Priority
Priority: 2 (default / most feature requests should be filed as P2)
Issue Components