feat(gcp): add service account impersonation (#4291)

This commit is contained in:
Sergio Garcia
2024-06-26 09:31:47 -04:00
committed by GitHub
parent fc23eccc7b
commit cf84875355
6 changed files with 76 additions and 17 deletions
+10
View File
@@ -25,6 +25,16 @@ Prowler will follow the same credentials search as [Google authentication librar
Those credentials must be associated to a user or service account with proper permissions to do all checks. To make sure, add the `Viewer` role to the member associated with the credentials.
## Impersonate Service Account
If you want to impersonate a GCP service account, you can use the `--impersonate-service-account` argument:
```console
prowler gcp --impersonate-service-account <service-account-email>
```
This argument will use the default credentials to impersonate the service account provided.
# GCP Service APIs
Prowler will use the Google Cloud APIs to get the information needed to perform the checks. Make sure that the following APIs are enabled in the project: