Agent Engine: remove unnecesary permission after bug fix (#3926)

This commit is contained in:
Luca Prete
2026-05-04 09:05:48 +02:00
committed by GitHub
parent b4ade637fd
commit 4cf46f2dd9
12 changed files with 23 additions and 80 deletions

View File

@@ -24,9 +24,7 @@ variable "service_account_config" {
name = optional(string) name = optional(string)
roles = optional(list(string), [ roles = optional(list(string), [
"roles/aiplatform.user", "roles/aiplatform.user",
"roles/storage.objectViewer", "roles/storage.objectViewer"
# TODO: remove when b/441480710 is solved
"roles/viewer"
]) ])
}) })
nullable = false nullable = false

View File

@@ -23,11 +23,6 @@ values:
member: serviceAccount:my-agent@project-id.iam.gserviceaccount.com member: serviceAccount:my-agent@project-id.iam.gserviceaccount.com
project: project-id project: project-id
role: roles/storage.objectViewer role: roles/storage.objectViewer
module.agent_engine.google_project_iam_member.default["roles/viewer"]:
condition: []
member: serviceAccount:my-agent@project-id.iam.gserviceaccount.com
project: project-id
role: roles/viewer
module.agent_engine.google_service_account.service_account[0]: module.agent_engine.google_service_account.service_account[0]:
account_id: my-agent account_id: my-agent
create_ignore_already_exists: null create_ignore_already_exists: null
@@ -73,11 +68,11 @@ values:
triggers: null triggers: null
counts: counts:
google_project_iam_member: 3 google_project_iam_member: 2
google_service_account: 1 google_service_account: 1
google_vertex_ai_reasoning_engine: 1 google_vertex_ai_reasoning_engine: 1
modules: 1 modules: 1
resources: 6 resources: 5
time_sleep: 1 time_sleep: 1
outputs: {} outputs: {}

View File

@@ -23,11 +23,6 @@ values:
member: serviceAccount:my-agent@project-id.iam.gserviceaccount.com member: serviceAccount:my-agent@project-id.iam.gserviceaccount.com
project: project-id project: project-id
role: roles/storage.objectViewer role: roles/storage.objectViewer
module.agent_engine.google_project_iam_member.default["roles/viewer"]:
condition: []
member: serviceAccount:my-agent@project-id.iam.gserviceaccount.com
project: project-id
role: roles/viewer
module.agent_engine.google_service_account.service_account[0]: module.agent_engine.google_service_account.service_account[0]:
account_id: my-agent account_id: my-agent
create_ignore_already_exists: null create_ignore_already_exists: null
@@ -153,13 +148,13 @@ values:
triggers: null triggers: null
counts: counts:
google_project_iam_member: 3 google_project_iam_member: 2
google_service_account: 1 google_service_account: 1
google_storage_bucket: 1 google_storage_bucket: 1
google_storage_bucket_object: 3 google_storage_bucket_object: 3
google_vertex_ai_reasoning_engine: 1 google_vertex_ai_reasoning_engine: 1
modules: 1 modules: 1
resources: 10 resources: 9
time_sleep: 1 time_sleep: 1
outputs: {} outputs: {}

View File

@@ -23,11 +23,6 @@ values:
member: serviceAccount:my-agent@project-id.iam.gserviceaccount.com member: serviceAccount:my-agent@project-id.iam.gserviceaccount.com
project: project-id project: project-id
role: roles/storage.objectViewer role: roles/storage.objectViewer
module.agent_engine.google_project_iam_member.default["roles/viewer"]:
condition: []
member: serviceAccount:my-agent@project-id.iam.gserviceaccount.com
project: project-id
role: roles/viewer
module.agent_engine.google_service_account.service_account[0]: module.agent_engine.google_service_account.service_account[0]:
account_id: my-agent account_id: my-agent
create_ignore_already_exists: null create_ignore_already_exists: null
@@ -73,11 +68,11 @@ values:
triggers: null triggers: null
counts: counts:
google_project_iam_member: 3 google_project_iam_member: 2
google_service_account: 1 google_service_account: 1
google_vertex_ai_reasoning_engine: 1 google_vertex_ai_reasoning_engine: 1
modules: 1 modules: 1
resources: 6 resources: 5
time_sleep: 1 time_sleep: 1
outputs: {} outputs: {}

View File

@@ -23,11 +23,6 @@ values:
member: serviceAccount:my-agent@project-id.iam.gserviceaccount.com member: serviceAccount:my-agent@project-id.iam.gserviceaccount.com
project: project-id project: project-id
role: roles/storage.objectViewer role: roles/storage.objectViewer
module.agent_engine.google_project_iam_member.default["roles/viewer"]:
condition: []
member: serviceAccount:my-agent@project-id.iam.gserviceaccount.com
project: project-id
role: roles/viewer
module.agent_engine.google_service_account.service_account[0]: module.agent_engine.google_service_account.service_account[0]:
account_id: my-agent account_id: my-agent
create_ignore_already_exists: null create_ignore_already_exists: null
@@ -81,11 +76,11 @@ values:
triggers: null triggers: null
counts: counts:
google_project_iam_member: 3 google_project_iam_member: 2
google_service_account: 1 google_service_account: 1
google_vertex_ai_reasoning_engine: 1 google_vertex_ai_reasoning_engine: 1
modules: 1 modules: 1
resources: 6 resources: 5
time_sleep: 1 time_sleep: 1
outputs: {} outputs: {}

View File

@@ -23,11 +23,6 @@ values:
member: serviceAccount:my-agent@project-id.iam.gserviceaccount.com member: serviceAccount:my-agent@project-id.iam.gserviceaccount.com
project: project-id project: project-id
role: roles/storage.objectViewer role: roles/storage.objectViewer
module.agent_engine.google_project_iam_member.default["roles/viewer"]:
condition: []
member: serviceAccount:my-agent@project-id.iam.gserviceaccount.com
project: project-id
role: roles/viewer
module.agent_engine.google_service_account.service_account[0]: module.agent_engine.google_service_account.service_account[0]:
account_id: my-agent account_id: my-agent
create_ignore_already_exists: null create_ignore_already_exists: null
@@ -74,11 +69,11 @@ values:
triggers: null triggers: null
counts: counts:
google_project_iam_member: 3 google_project_iam_member: 2
google_service_account: 1 google_service_account: 1
google_vertex_ai_reasoning_engine: 1 google_vertex_ai_reasoning_engine: 1
modules: 1 modules: 1
resources: 6 resources: 5
time_sleep: 1 time_sleep: 1
outputs: {} outputs: {}

View File

@@ -23,11 +23,6 @@ values:
member: serviceAccount:my-agent@project-id.iam.gserviceaccount.com member: serviceAccount:my-agent@project-id.iam.gserviceaccount.com
project: project-id project: project-id
role: roles/storage.objectViewer role: roles/storage.objectViewer
module.agent_engine.google_project_iam_member.default["roles/viewer"]:
condition: []
member: serviceAccount:my-agent@project-id.iam.gserviceaccount.com
project: project-id
role: roles/viewer
module.agent_engine.google_service_account.service_account[0]: module.agent_engine.google_service_account.service_account[0]:
account_id: my-agent account_id: my-agent
create_ignore_already_exists: null create_ignore_already_exists: null
@@ -153,13 +148,13 @@ values:
triggers: null triggers: null
counts: counts:
google_project_iam_member: 3 google_project_iam_member: 2
google_service_account: 1 google_service_account: 1
google_storage_bucket: 1 google_storage_bucket: 1
google_storage_bucket_object: 3 google_storage_bucket_object: 3
google_vertex_ai_reasoning_engine: 1 google_vertex_ai_reasoning_engine: 1
modules: 1 modules: 1
resources: 10 resources: 9
time_sleep: 1 time_sleep: 1
outputs: {} outputs: {}

View File

@@ -23,11 +23,6 @@ values:
member: serviceAccount:my-agent@project-id.iam.gserviceaccount.com member: serviceAccount:my-agent@project-id.iam.gserviceaccount.com
project: project-id project: project-id
role: roles/storage.objectViewer role: roles/storage.objectViewer
module.agent_engine.google_project_iam_member.default["roles/viewer"]:
condition: []
member: serviceAccount:my-agent@project-id.iam.gserviceaccount.com
project: project-id
role: roles/viewer
module.agent_engine.google_service_account.service_account[0]: module.agent_engine.google_service_account.service_account[0]:
account_id: my-agent account_id: my-agent
create_ignore_already_exists: null create_ignore_already_exists: null
@@ -72,11 +67,11 @@ values:
triggers: null triggers: null
counts: counts:
google_project_iam_member: 3 google_project_iam_member: 2
google_service_account: 1 google_service_account: 1
google_vertex_ai_reasoning_engine: 1 google_vertex_ai_reasoning_engine: 1
modules: 1 modules: 1
resources: 6 resources: 5
time_sleep: 1 time_sleep: 1
outputs: {} outputs: {}

View File

@@ -23,11 +23,6 @@ values:
member: serviceAccount:my-agent@project-id.iam.gserviceaccount.com member: serviceAccount:my-agent@project-id.iam.gserviceaccount.com
project: project-id project: project-id
role: roles/storage.objectViewer role: roles/storage.objectViewer
module.agent_engine.google_project_iam_member.default["roles/viewer"]:
condition: []
member: serviceAccount:my-agent@project-id.iam.gserviceaccount.com
project: project-id
role: roles/viewer
module.agent_engine.google_service_account.service_account[0]: module.agent_engine.google_service_account.service_account[0]:
account_id: my-agent account_id: my-agent
create_ignore_already_exists: null create_ignore_already_exists: null
@@ -96,12 +91,12 @@ values:
triggers: null triggers: null
counts: counts:
google_project_iam_member: 3 google_project_iam_member: 2
google_service_account: 1 google_service_account: 1
google_storage_bucket: 1 google_storage_bucket: 1
google_vertex_ai_reasoning_engine: 1 google_vertex_ai_reasoning_engine: 1
modules: 1 modules: 1
resources: 7 resources: 6
time_sleep: 1 time_sleep: 1
outputs: {} outputs: {}

View File

@@ -23,11 +23,6 @@ values:
member: serviceAccount:my-agent@project-id.iam.gserviceaccount.com member: serviceAccount:my-agent@project-id.iam.gserviceaccount.com
project: project-id project: project-id
role: roles/storage.objectViewer role: roles/storage.objectViewer
module.agent_engine.google_project_iam_member.default["roles/viewer"]:
condition: []
member: serviceAccount:my-agent@project-id.iam.gserviceaccount.com
project: project-id
role: roles/viewer
module.agent_engine.google_service_account.service_account[0]: module.agent_engine.google_service_account.service_account[0]:
account_id: my-agent account_id: my-agent
create_ignore_already_exists: null create_ignore_already_exists: null
@@ -80,11 +75,11 @@ values:
triggers: null triggers: null
counts: counts:
google_project_iam_member: 3 google_project_iam_member: 2
google_service_account: 1 google_service_account: 1
google_vertex_ai_reasoning_engine: 1 google_vertex_ai_reasoning_engine: 1
modules: 1 modules: 1
resources: 6 resources: 5
time_sleep: 1 time_sleep: 1
outputs: {} outputs: {}

View File

@@ -23,11 +23,6 @@ values:
member: serviceAccount:my-agent@project-id.iam.gserviceaccount.com member: serviceAccount:my-agent@project-id.iam.gserviceaccount.com
project: project-id project: project-id
role: roles/storage.objectViewer role: roles/storage.objectViewer
module.agent_engine.google_project_iam_member.default["roles/viewer"]:
condition: []
member: serviceAccount:my-agent@project-id.iam.gserviceaccount.com
project: project-id
role: roles/viewer
module.agent_engine.google_service_account.service_account[0]: module.agent_engine.google_service_account.service_account[0]:
account_id: my-agent account_id: my-agent
create_ignore_already_exists: null create_ignore_already_exists: null
@@ -72,11 +67,11 @@ values:
triggers: null triggers: null
counts: counts:
google_project_iam_member: 3 google_project_iam_member: 2
google_service_account: 1 google_service_account: 1
google_vertex_ai_reasoning_engine: 1 google_vertex_ai_reasoning_engine: 1
modules: 1 modules: 1
resources: 6 resources: 5
time_sleep: 1 time_sleep: 1
outputs: {} outputs: {}

View File

@@ -23,11 +23,6 @@ values:
member: serviceAccount:my-agent@project-id.iam.gserviceaccount.com member: serviceAccount:my-agent@project-id.iam.gserviceaccount.com
project: project-id project: project-id
role: roles/storage.objectViewer role: roles/storage.objectViewer
module.agent_engine.google_project_iam_member.default["roles/viewer"]:
condition: []
member: serviceAccount:my-agent@project-id.iam.gserviceaccount.com
project: project-id
role: roles/viewer
module.agent_engine.google_service_account.service_account[0]: module.agent_engine.google_service_account.service_account[0]:
account_id: my-agent account_id: my-agent
create_ignore_already_exists: null create_ignore_already_exists: null
@@ -72,11 +67,11 @@ values:
triggers: null triggers: null
counts: counts:
google_project_iam_member: 3 google_project_iam_member: 2
google_service_account: 1 google_service_account: 1
google_vertex_ai_reasoning_engine: 1 google_vertex_ai_reasoning_engine: 1
modules: 1 modules: 1
resources: 6 resources: 5
time_sleep: 1 time_sleep: 1
outputs: {} outputs: {}