I am trying to push a Docker image to Google Artifact Registry (GAR) while impersonating a Service Account ($SERV_ACCT_EMAIL):
denied: Permission "artifactregistry.repositories.downloadArtifacts" denied on resource "projects/$GCP_PROJECT_ID/locations/us-west1/repositories/$GAR_REPOSITORY" (or it may not exist)
$SERV_ACCT_EMAIL has Artifact Registry Writer (roles/artifactregistry.writer) and Artifact Registry Reader (roles/artifactregistry.reader) roles; the latter of which has the permission artifactregistry.repositories.downloadArtifacts. Thus, if the resource is granted access to $SERV_ACCT_EMAIL, I believe I will indeed be able to push those artifacts.
How do I push to GAR while impersonating $SERV_ACCT_EMAIL?