GCP Managed Service Account is not created (for Cloud Asset API)

Viewed 1920

I have enabled the API Cloud Asset API (cloudasset.googleapis.com), but It didn't create the GCP managed service account service-{projectNumber}@gcp-sa-cloudasset.iam.gserviceaccount.com. I have read it at multiple place that GCP is suppose to create that account.

I have tried to enable/disable the API multiple times but still no luck.

If anyone knows the workaround, Please let me know :-)

3 Answers

The documentation should be updated, but the service account is not created when you activate the API, but when you run an export. So if you run an export of the assets, the service account will appear.

If, for a reason, you can't run an export (e.g. when you want to create an asset feed to monitor for changes), you can run the following command:

gcloud beta services identity create --service=cloudasset.googleapis.com --project=PROJECT_ID

In Terraform, I created a null_resource that does the trick.

It exists! But it has no permission. Simply go to IAM page, click on +ADD. Fill the email with the Cloud Asset service account email: service-{projectNumber}@gcp-sa-cloudasset.iam.gserviceaccount.com. And add it, at least the role Cloud Asset Service Agent. Save.

Having a similar problem, I could see the service account in the form of service-{projectNumber}@gcp-sa-cloudasset.iam.gserviceaccount.com was indeed created, but I could not assign a role to it, as I got this confusing (wrong) error you got (mail addresses and domains must be associated with an active Google Account, G Suite account, or Cloud Identity account.).

I discovered there is a new policy in town that prohibits the use of cross-project service account permissions: https://cloud.google.com/resource-manager/docs/organization-policy/restricting-service-accounts#disable_cross_project_service_accounts.

gcloud beta resource-manager org-policies disable-enforce iam.disableCrossProjectServiceAccountUsage --organization <org_id> should solve it.

Related