[英](Terraform, GCP) Error 403: Permission iam.serviceAccounts.setIamPolicy is required to perform this operation on service account projects/myproject-17
On GCP , I'm trying to add "Service Account 2" as a member to "Service Account 1" with this Terraform code below:在GCP上,我正在尝试使用以下Terraform代码将“服务帐户 2”作为成员添加到“服务帐户 1” :
resource "google_service_account" "service_account_1" {
display_name = "Service Account 1"
account_id = "service-account-1"
}
resource "google_service_account" "service_account_2" {
display_name = "Service Account 2"
account_id = "service-account-2"
}
resource "google_service_account_iam_member" "service-account-iam_member" {
service_account_id = google_service_account.service_account_1.name
role = "roles/iam.serviceAccountUser"
member = "serviceAccount:${google_service_account.service_account_2.email}"
depends_on = [
google_service_account.service_account_1,
google_service_account.service_account_2
]
}
But I got this error below:但我在下面收到此错误:
Error applying IAM policy for service account 'projects/myproject-173831/serviceAccounts/service-account-1@myproject-173831.iam.gserviceaccount.com': Error setting IAM policy for service account 'projects/myproject-173831/serviceAccounts/service-account-1@myproject-173831.iam.gserviceaccount.com': googleapi: Error 403: Permission iam.serviceAccounts.setIamPolicy is required to perform this operation on service account projects/myproject-173831/serviceAccounts/service-account-1@myproject-173831.iam.gserviceaccount.com., forbidden
为服务帐户“projects/myproject-173831/serviceAccounts/service-account-1@myproject-173831.iam.gserviceaccount.com”应用 IAM 策略时出错:为服务帐户“projects/myproject-173831/serviceAccounts/service”设置 IAM 策略时出错-account-1@myproject-173831.iam.gserviceaccount.com':googleapi:错误 403:需要权限 iam.serviceAccounts.setIamPolicy 才能对服务帐户项目/myproject-173831/serviceAccounts/service-account-1@ 执行此操作myproject-173831.iam.gserviceaccount.com.,禁止
So now, I'm trying to add a role to solve this error above but there are too many roles to choose:所以现在,我正在尝试添加一个角色来解决上面的这个错误,但是有太多角色可供选择:
What role do I need to choose?我需要选择什么角色?
声明:本站的技术帖子网页,遵循CC BY-SA 4.0协议,如果您需要转载,请注明本站网址或者原文地址。任何问题请咨询:yoyou2525@163.com.