Allow Cloud Armor
Duration: 2 min | Persona: Org Admin
In this section, you will grant the appropriate IAM role for the Tenant project’s service account. This will allow later this service account to provision Cloud Armor.
Initialize variables:
WORK_DIR=~/
source ${WORK_DIR}acm-workshop-variables.shDefine role
Define the compute.securityAdmin role with an IAMPolicyMember for the Tenant project’s service account:
cat <<EOF > ${WORK_DIR}$HOST_PROJECT_DIR_NAME/projects/$TENANT_PROJECT_ID/security-admin.yaml
apiVersion: iam.cnrm.cloud.google.com/v1beta1
kind: IAMPolicyMember
metadata:
name: security-admin-${TENANT_PROJECT_ID}
namespace: config-control
annotations:
config.kubernetes.io/depends-on: iam.cnrm.cloud.google.com/namespaces/config-control/IAMServiceAccount/${TENANT_PROJECT_ID},resourcemanager.cnrm.cloud.google.com/namespaces/config-control/Project/${TENANT_PROJECT_ID}
spec:
memberFrom:
serviceAccountRef:
name: ${TENANT_PROJECT_ID}
role: roles/compute.securityAdmin
resourceRef:
kind: Project
external: projects/${TENANT_PROJECT_ID}
EOFDeploy Kubernetes manifests
cd ${WORK_DIR}$HOST_PROJECT_DIR_NAME/
git add . && git commit -m "Allow Cloud Armor for Tenant project" && git push origin mainCheck deployments
graph TD; IAMPolicyMember-.->Project
List the Kubernetes resources managed by Config Sync in Config Controller for the Host project configs repository:
Run this command and click on this link:
echo -e "https://console.cloud.google.com/kubernetes/config_management/packages?project=${HOST_PROJECT_ID}"Wait until you see the Sync status column as Synced and the Reconcile status column as Current.
Run this command:
gcloud alpha anthos config sync repo describe \
--project $HOST_PROJECT_ID \
--managed-resources all \
--sync-name root-sync \
--sync-namespace config-management-systemWait and re-run this command above until you see "status": "SYNCED". All the managed_resources listed should have STATUS: Current too.
List the GitHub runs for the Host project configs repository:
cd ${WORK_DIR}$HOST_PROJECT_DIR_NAME && gh run listList the Google Cloud resources created:
gcloud projects get-iam-policy $TENANT_PROJECT_ID \
--filter="bindings.members:${TENANT_PROJECT_SA_EMAIL}" \
--flatten="bindings[].members" \
--format="table(bindings.role)" \
| grep securityAdminWait and re-run this command above until you see the resources created.