Summary
gcpStepCreateServiceAccount builds the expected service-account email up front and returns it on every branch, including Skip and unknown input, so the wizard continues with an identity it never created or verified. Step 4 then prints a grant for that principal and Step 5 tries to mint a key for it, and the failure surfaces several steps later as an opaque IAM error. The sibling gcpStepCreateKey returns an empty string on skip so the caller can ask for an existing credentials file.
Location
cmd/configure_gcp.go:678 at 3c0f8ac
Failure scenario
An operator answers s at Step 3 because they already use a differently named service account. The wizard reports "grants roles/compute.admin to [email protected]" for a principal that does not exist, then fails at key creation with an IAM error that does not mention the skipped step.
Evidence
saName := "cudly-service-account"
saEmail := fmt.Sprintf("%s@%s.iam.gserviceaccount.com", saName, projectID)
...
case "s", "skip":
fmt.Println("Skipping Create Service Account")
default:
fmt.Printf("Unknown option, skipping\n")
}
return saEmail, nil
Suggested fix
Return an empty string on skip and prompt for the existing service-account email, the way gcpStepCreateKey already returns "" on skip so the caller asks for an existing credentials file.
Found by the 2026-09-02 codebase audit, finding A10-020, reported by one reviewer and independently confirmed by a second. Full report: docs/audits/codebase-audit-2026-09-02.md.
Summary
gcpStepCreateServiceAccount builds the expected service-account email up front and returns it on every branch, including Skip and unknown input, so the wizard continues with an identity it never created or verified. Step 4 then prints a grant for that principal and Step 5 tries to mint a key for it, and the failure surfaces several steps later as an opaque IAM error. The sibling gcpStepCreateKey returns an empty string on skip so the caller can ask for an existing credentials file.
Location
cmd/configure_gcp.go:678at 3c0f8acFailure scenario
An operator answers
sat Step 3 because they already use a differently named service account. The wizard reports "grants roles/compute.admin to [email protected]" for a principal that does not exist, then fails at key creation with an IAM error that does not mention the skipped step.Evidence
Suggested fix
Return an empty string on skip and prompt for the existing service-account email, the way gcpStepCreateKey already returns "" on skip so the caller asks for an existing credentials file.
Found by the 2026-09-02 codebase audit, finding
A10-020, reported by one reviewer and independently confirmed by a second. Full report:docs/audits/codebase-audit-2026-09-02.md.