You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Please vote on this issue by adding a 👍 reaction to the original issue to help the community and maintainers prioritize this request
Please do not leave "+1" or "me too" comments, they generate extra noise for issue followers and do not help prioritize the request
If you are interested in working on this issue or have submitted a pull request, please leave a comment. If the issue is assigned to the "modular-magician" user, it is either in the process of being autogenerated, or is planned to be autogenerated soon. If the issue is assigned to a user, that user is claiming responsibility for the issue. If the issue is assigned to "hashibot", a community member has claimed the issue already.
Description
Reopening #6738 as an enhancement. Terraform doesn't set the X-Goog-User-Project header which allows User ADCs to work with Access Context Manager API. Current workaround is to use service account impersonation.
REDACTED@DESKTOP-7JUP8RO ~\..\..\terraform-google-forseti enable-firewall-logging ≣ ~15 -0 ! curl.exe -H "Authorization: Bearer $(gcloud auth application-default print-access-token)" "https://accesscontextmanager.googleapis.com/v1/accessPolicies?parent=organizations/684510004702"
C:\Program Files (x86)\Google\Cloud SDK\google-cloud-sdk\bin\..\lib\third_party\google\auth\_default.py:69: UserWarning: Your application has authenticated using end user credentials from Google Cloud SDK. We recommend that most server applications use service accounts instead. If your application continues to use end user credentials from Cloud SDK, you might receive a "quota exceeded" or "API not enabled" error. For more information about service accounts, see https://cloud.google.com/docs/authentication/
warnings.warn(_CLOUD_SDK_CREDENTIALS_WARNING)
{
"error": {
"code": 403,
"message": "Your application has authenticated using end user credentials from the Google Cloud SDK or Google Cloud Shell which are not supported by the accesscontextmanager.googleapis.com. We recommend configuring the billing/quota_project setting in gcloud or using a service account through the
auth/impersonate_service_account setting. For more information about service accounts and how to use them in your application, see https://cloud.google.com/docs/authentication/.",
"status": "PERMISSION_DENIED"
}
}
REDACTED@DESKTOP-7JUP8RO ~\..\..\terraform-google-forseti enable-firewall-logging ≣ ~1 -0 ! curl.exe -H "X-Goog-User-Project: REDACTED" -H "Authorization: Bearer $(gcloud auth application-default print-access-token)" "https://accesscontextmanager.googleapis.com/v1/accessPolicies?parent=organizations/684510004702"
C:\Program Files (x86)\Google\Cloud SDK\google-cloud-sdk\bin\..\lib\third_party\google\auth\_default.py:69: UserWarning: Your application has authenticated using end user credentials from Google Cloud SDK. We recommend that most server applications use service accounts instead. If your application continues to use end user credentials from Cloud SDK, you might receive a "quota exceeded" or "API not enabled" error. For more information about service accounts, see https://cloud.google.com/docs/authentication/
warnings.warn(_CLOUD_SDK_CREDENTIALS_WARNING)
{
"accessPolicies": [
{
"name": "accessPolicies/893819325231",
"parent": "organizations/684510004702",
"title": "RestrictAPIs",
"etag": "d1135c2e91171423"
}
]
}
New or Affected Resource(s)
google_access_context_manager_*
Potential Terraform Configuration
resource"google_access_context_manager_access_policy""base" {
parent=data.google_organization.org.nametitle="test"quota_project="foo"# or set at the provider
}
I'm going to lock this issue because it has been closed for 30 days ⏳. This helps our maintainers find and focus on the active issues.
If you feel this issue should be reopened, we encourage creating a new issue linking back to this one for added context. If you feel I made an error 🤖 🙉 , please reach out to my human friends 👉 [email protected]. Thanks!
ghost
locked and limited conversation to collaborators
Sep 26, 2020
Community Note
Description
Reopening #6738 as an enhancement. Terraform doesn't set the X-Goog-User-Project header which allows User ADCs to work with Access Context Manager API. Current workaround is to use service account impersonation.
New or Affected Resource(s)
Potential Terraform Configuration
References
The text was updated successfully, but these errors were encountered: