Re-verify automatic import of default org policies
ludoo opened this issue · 3 comments
ludoo commented
I still had this issue today with a brand-new org:
- storage.uniformBucketLevelAccess
- iam.allowedPolicyMemberDomains
- iam.disableServiceAccountKeyUpload
- iam.disableServiceAccountKeyCreation
- iam.automaticIamGrantsForDefaultServiceAccounts
Did I do something wrong?
Originally posted by @lyricnz in #2056 (comment)
juliocc commented
All these are contained in the set of org policies we're importing:
cloud-foundation-fabric/fast/stages/0-bootstrap/organization.tf
Lines 102 to 120 in 0420dec
ludoo commented
We should make sure our imports still work...
lyricnz commented
Problem appears to be PEBKAC - but to be fair, there's no mention of "Secure by Default Org Policy" during the google screens during creation of an Organization (that I could see). It appears it's now enforced+default by Google since May 3, 2024.
vs
https://cloud.google.com/resource-manager/docs/secure-by-default-organizations