fix(gcp): restrict setup wizard compute permissions - #2122
Conversation
Replace the setup wizard's Compute Admin grant with Compute Viewer and an exact project custom role for compute.commitments.create. Preserve conditional access and fail rather than silently widening existing grants. Cover the real SDK policy requests and wizard failure exits with local HTTP fixtures. Existing broad grants require separate operator review.
|
Navigate logical layers of code changes, visualize relationships, and explore their blast radius. No actionable comments were generated in the recent review. 🎉 ℹ️ Recent review info⚙️ Run configurationConfiguration used: Repository: LeanerCloud/cloud-commitments-cli/.coderabbit.yaml Review profile: CHILL Plan: Essentials Run ID: 📒 Files selected for processing (4)
Included review availability: This review used your included allowance. 0 included reviews remain after this review. Your included PR review attempts over the past 7 days set your current allowance at 1 review per hour. 📝 WalkthroughWalkthroughGCP setup replaces the project-level ChangesGCP IAM setup
Priority: ⬆️ High Estimated code review effort: 3 (Moderate) | ~25 minutes Change: Bug fix · Severity of issue fixed: High Sequence Diagram(s)sequenceDiagram
actor Operator
participant ConfigureGCP as gcpStepGrantRole
participant PurchaserRole as ensureGCPPurchaserRole
participant IAM as Google Cloud IAM API
Operator->>ConfigureGCP: Select Run
ConfigureGCP->>PurchaserRole: Validate or create project role
PurchaserRole->>IAM: Get cudlyCommitmentPurchaser
alt Role lookup returns 404
PurchaserRole->>IAM: Create role with compute.commitments.create
end
PurchaserRole-->>ConfigureGCP: Return validated role
ConfigureGCP->>IAM: Read and update compute.viewer policy binding
ConfigureGCP->>IAM: Read and update purchaser role policy binding
Merge Risk: ⚪ Minimal · up to The narrowed permissions are ready to merge after normal checks. Provisioning failures stop before key creation, and rerunning setup repairs partial grants. 🚥 Pre-merge checks | ✅ 4 | ❌ 1❌ Failed checks (1 warning)
✅ Passed checks (4 passed)
Full details: Docstring CoverageExplanation Docstring coverage is 63.64% which is insufficient. The required threshold is 80.00%. Docstring coverage is scoped to functions touched by this diff. Analyzed 11 functions across 3 files. (1 skipped: 1 unsupported.)
✨ Finishing Touches 💡 1📝 Generate docstrings 💡
🧪 Generate unit tests (beta)
Comment |
configure-gcpcurrently grants full Compute Admin access before minting a service-account key. Replace that grant with Compute Viewer and a project custom role containing onlycompute.commitments.create.The wizard validates existing custom roles before binding them and refuses to widen conditional-only membership. It preserves existing grants, including broad grants from older installations, which need separate operator review. Setup documentation distinguishes operator permissions from runtime permissions and notes separate Recommender access requirements.
Validation uses the real wizard coordinator and Google SDK against local HTTP fixtures. The regression fails on the original Compute Admin policy request. Cases cover custom-role reuse and rejection, preserved conditional and broad grants, create conflicts, and partial policy-write failure before key minting. No live IAM mutation or purchase was performed; fixture evidence does not establish live Google IAM propagation.
Verified commit:
1272e721b8d5185634840c9aa9fc7698dd7cb124.Closes #1946
Summary by CodeRabbit