-
Hi, Stage 2 wants to use prefix-prod-resman-pf-0@prefix-prod-iac-core-0.iam.gserviceaccount.com as the impersonation account which has the Project Creator Role under the Teams hierarchy. But the Sandbox folder doesn't have this service account listed. It has prexix-dev-resman-sbox-0@prefix-prod-iac-core-0.iam.gserviceaccount.com attached with the Project Creator role and not prefix-prod-resman-pf-0@ so we get a 403 error. This must have to do with the automated providers files created and used on the 2-PF stage as opposed to the 9-sandbox-providers.tf file created in earlier stages. |
Beta Was this translation helpful? Give feedback.
Replies: 1 comment 1 reply
-
Good point on the prefix, we should |
Beta Was this translation helpful? Give feedback.
Reading the rest of your reply, sorry hectic day :) You have two choices:
context/project-factory
tag to the Sandbox foldermain.tf
We will make all this a lot easier once the resman changes we have in the pipeline go in. Thanks for reminding us that we need to provide more explicit choices, and document this stuff better. :)