Allow Cloud Armor

Org Admin Duration: 2 min | Persona: Org Admin

In this section, you will grant the appropriate IAM role for the Tenant project’s service account. This will allow later this service account to provision Cloud Armor.

Initialize variables:

WORK_DIR=~/
source ${WORK_DIR}acm-workshop-variables.sh

Define role

Define the compute.securityAdmin role with an IAMPolicyMember for the Tenant project’s service account:

cat <<EOF > ${WORK_DIR}$HOST_PROJECT_DIR_NAME/projects/$TENANT_PROJECT_ID/security-admin.yaml
apiVersion: iam.cnrm.cloud.google.com/v1beta1
kind: IAMPolicyMember
metadata:
  name: security-admin-${TENANT_PROJECT_ID}
  namespace: config-control
  annotations:
    config.kubernetes.io/depends-on: iam.cnrm.cloud.google.com/namespaces/config-control/IAMServiceAccount/${TENANT_PROJECT_ID},resourcemanager.cnrm.cloud.google.com/namespaces/config-control/Project/${TENANT_PROJECT_ID}
spec:
  memberFrom:
    serviceAccountRef:
      name: ${TENANT_PROJECT_ID}
  role: roles/compute.securityAdmin
  resourceRef:
    kind: Project
    external: projects/${TENANT_PROJECT_ID}
EOF

Deploy Kubernetes manifests

cd ${WORK_DIR}$HOST_PROJECT_DIR_NAME/
git add . && git commit -m "Allow Cloud Armor for Tenant project" && git push origin main

Check deployments

graph TD; IAMServiceAccount-->Project IAMPartialPolicy-->IAMServiceAccount ConfigConnectorContext-->IAMServiceAccount IAMPolicyMember-->IAMServiceAccount IAMPolicyMember-->Project IAMPolicyMember-->IAMServiceAccount IAMPolicyMember-->Project IAMPolicyMember-->IAMServiceAccount IAMPolicyMember-->Project IAMPolicyMember-->IAMServiceAccount IAMPolicyMember-->Project IAMPolicyMember-->IAMServiceAccount IAMPolicyMember-->Project Service-->Project IAMPolicyMember-->IAMServiceAccount IAMPolicyMember-->Project Service-->Project Service-->Project IAMPolicyMember-->IAMServiceAccount IAMPolicyMember-->Project Service-->Project Service-->Project Service-->Project Service-->Project IAMPolicyMember-->IAMServiceAccount IAMPolicyMember-->Project

List the Kubernetes resources managed by Config Sync in Config Controller for the Host project configs repository:

gcloud alpha anthos config sync repo describe \
    --project $HOST_PROJECT_ID \
    --managed-resources all \
    --sync-name root-sync \
    --sync-namespace config-management-system

Wait and re-run this command above until you see "status": "SYNCED" for this RootSync. All the managed_resources listed should have STATUS: Current as well.

List the GitHub runs for the Host project configs repository:

cd ${WORK_DIR}$HOST_PROJECT_DIR_NAME && gh run list

List the Google Cloud resources created:

gcloud projects get-iam-policy $TENANT_PROJECT_ID \
    --filter="bindings.members:${TENANT_PROJECT_SA_EMAIL}" \
    --flatten="bindings[].members" \
    --format="table(bindings.role)" \
    | grep securityAdmin

Wait and re-run this command above until you see the resources created.