Skip to content

fix(cli): skipping GCP service-account creation still returns a fabricated account email #2007

Description

@cristim

Summary

gcpStepCreateServiceAccount builds the expected service-account email up front and returns it on every branch, including Skip and unknown input, so the wizard continues with an identity it never created or verified. Step 4 then prints a grant for that principal and Step 5 tries to mint a key for it, and the failure surfaces several steps later as an opaque IAM error. The sibling gcpStepCreateKey returns an empty string on skip so the caller can ask for an existing credentials file.

Location

cmd/configure_gcp.go:678 at 3c0f8ac

Failure scenario

An operator answers s at Step 3 because they already use a differently named service account. The wizard reports "grants roles/compute.admin to [email protected]" for a principal that does not exist, then fails at key creation with an IAM error that does not mention the skipped step.

Evidence

	saName := "cudly-service-account"
	saEmail := fmt.Sprintf("%s@%s.iam.gserviceaccount.com", saName, projectID)
	...
	case "s", "skip":
		fmt.Println("Skipping Create Service Account")
	default:
		fmt.Printf("Unknown option, skipping\n")
	}
	return saEmail, nil

Suggested fix

Return an empty string on skip and prompt for the existing service-account email, the way gcpStepCreateKey already returns "" on skip so the caller asks for an existing credentials file.


Found by the 2026-09-02 codebase audit, finding A10-020, reported by one reviewer and independently confirmed by a second. Full report: docs/audits/codebase-audit-2026-09-02.md.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions