On GCP document:
Users granted the Service Account User role on a service account can use it to indirectly access all the resources to which the service account has access. For example, if a service account has been granted the Compute Admin role (roles/compute.admin), a user that has been granted the Service Account Users role (roles/iam.serviceAccountUser) on that service account can act as the service account to start a Compute Engine instance. In this flow, the user impersonates the service account to perform any tasks using its granted roles and permissions.
So I would like to try this feature:
- Create a project
- Add
testuser@example.comto the project and grant Viewer role. - Open a new browser and login into GCP console with
testuser, and confirmed that the user can only view instances and cannot create instance. - Add a service account:
sa-name@project-id.iam.gserviceaccount.com, and grantCompute Adminrole, so this service account can create instance. - Grant
testuser@example.comwithservice account userrole to this service account.
So per above GCP document, I expect testuser@example.com can create instance, but the Create instance button remains disabled.
Then I grant testuser@example.com with service account user role in project level, still the Create instance button remains disabled.
So what is wrong?
Am I understanding wrong? grant
testuser@example.comwithservice account userrole does not give testuser the ability to create instance?Am I doing something wrong?
How can I create instance by
service account user?