I'm looking to onboard a new developer to my GCP project, assigning responsibilities such as deploying cloud functions and potentially granting access to others. However, after providing them with admin setIAMPolicy permissions, I observed that they can edit my role as the owner, which is undesirable.
Are there specific permission settings or role configurations that allow for necessary access while preventing the user from altering roles with Owner and Editor privileges? I'm seeking advice and best practices to strike a balance in access control. Any guidance on achieving this would be highly appreciated. Thank you!
If you want to let them freedom to grant permission (on service account for instance) they have also freedom to grant themselves the role they want!
The problem is not easy to solve. Up to now, I saw 2 solutions:
Nothing magic, Prevent the role assignation (proactive) or auto remove the overpower roles after grant (reactive).
I implemented both, and the reactive is the easiest and fastest one to use. But you have to accept a few second delay between grant and removal of roles.