How do I give a role to secret in GCP?

Viewed 126

I am trying to access a secret stored in secret manager, following this. It says:

 Accessing a secret version requires the Secret Manager Secret Accessor role 
(roles/secretmanager.secretAccessor) on the secret, project, folder, or organization.
 IAM roles can't be granted on a secret version.

So, how do I apply the Secret Manager Secret Accessor role to the secret?

3 Answers

The quote refers to granting the user who wants to access the secret, the role of secretmanager.secretAccessor.

To grant a role:

  1. In the Google Cloud console, go to the IAM page.
  2. Select a project, folder, or organization.
  3. Select a principal to grant a role to:

To grant a role to a principal who already has other roles on the resource, find the row containing the principal's email address, click edit Edit principal in that row, and click add Add another role.

To grant a role to a Google-managed service account, select the Include Google-provided role grants checkbox to see its email address.

Note: You cannot edit inherited roles when managing access to a resource. To edit inherited roles, go to the resource where the role was granted. To grant a role to a principal who does not already have other roles on the resource, click person_add Add, then enter the principal's email address.

  1. Select a role to grant from the drop-down list. For best security practices, choose a role that includes only the permissions that your principal needs.
  2. Optional: Add a condition to the role.
  3. Click Save. The principal is granted the role on the resource.

In this page, you will find more information about Manage access to projects, folders, and organizations

You might want to add a role to a Service Account and not for the secret object

The relevant operation of accessing a secret will be done by a Entity(User or Service Account) with permissions granted by the relevant role

You can add the relevant role to the relevant service account with one line as following:

gcloud projects add-iam-policy-binding  <YOUR_PROJECT_ID> --member='serviceAccount:99999999@cloudbuild.gserviceaccount.com' --role='roles/secretmanager.secretAccessor'

It is good practice to grant the role for the user or service account at the most restrictive level, which in this case should be the secret itself. This can be done as follows:

gcloud secrets add-iam-policy-binding my_secret --member='serviceAccount:my_service_account@my_project.iam.gserviceaccount.com' --project=my_project --role='roles/secretmanager.secretAccessor'
Related