Repository navigation
docs(cli): add legacy Compute Admin migration checklist to GCP setup - #2137
Conversation
Older configure-gcp wizards granted roles/compute.admin and rerunning the current wizard preserves that binding. Document the operator checklist for the inventory-and-remediation part of #2123: inventory broad grants with owner authorization, establish the narrow roles, validate them live without purchasing, and revoke only after explicit approval.
|
No actionable comments were generated in the recent review. 🎉 ℹ️ Recent review info⚙️ Run configuration
📒 Files selected for processing (1)
Included review availability: This review used your included allowance. 0 included reviews remain after this review. Your included PR review attempts over the past 7 days set your current allowance at 1 review per hour. 📝 WalkthroughWalkthroughThe GCP setup guide replaces a brief recommendation with a checklist for reviewing legacy Compute Admin grants. It documents inventory, narrow-role validation, approved binding removal, access checks, and rollback steps. ChangesLegacy GCP grant migration
Priority: ⬆️ High Estimated code review effort: 2 (Simple) | ~10 minutes Change: Other · Severity of issue fixed: High Merge Risk: ⚪ Minimal · up to No actionable merge-blocking risk remains in the reviewed documentation change. 🚥 Pre-merge checks | ✅ 5✅ Passed checks (5 passed)
✨ Finishing Touches🧪 Generate unit tests (beta)
Comment |
|
@coderabbitai review |
|
Address independent review on #2137: cover inherited folder/org bindings with get-ancestors-iam-policy, note that test-iam-permissions silently omits missing permissions, restore the operator identity before the revocation step, flag the --condition failure mode on conditional bindings, and cover installs whose local key file was already removed.
|
Independent review pass 1 found one actionable (project-only policy would miss inherited folder/org grants) plus two nitpicks and two notes; all five addressed in 82cdc92: added get-ancestors-iam-policy for inherited bindings, test-iam-permissions omission caveat, operator identity restore before the revocation step, IAM condition heads-up, and key-file-path guidance. Re-review in flight. @coderabbitai review |
|
|
@coderabbitai full review |
|
|
@coderabbitai full review |
|
|
Codex takeover audit: head remains 82cdc92; CI re-fetched green and merge state CLEAN. Recovered Kimi wire history confirms both independent review passes used kimi-code/k3, not the exact claude-opus-5-5 required by CLAUDE.md. Direct invocation of the pinned reviewer failed: Not logged in; Please run /login. Merge is held for exact-model review at this SHA and recording its verdict here. The owner CodeRabbit quota waiver does not waive that reviewer gate. No merge, IAM mutation, purchase, or new CR trigger performed. Existing live inventory remains tracked in #2123 pending project-owner authorization. |
Use ancestor policy field paths and the supported IAM permissions API. Inspect replacement bindings before approved removal, then verify access after broad grants stop masking missing narrow permissions. Refs #2123
|
@coderabbitai full review |
|
|
Owner override applied. Independent Codex review clean at exact head 38124c7. Four migration defects fixed and review refinements closed. Fresh build, Markdown lint, diff check, and all applicable commit hooks passed. Offline regression fixture demonstrates old ancestor query misses inherited grant and corrected query retains scope/member/condition. Documented REST curl request executed against local HTTP fixture with exact method/path/headers/body. Evidence is offline/local; live IAM propagation and deployed analysis remain uncovered and tracked in #2123 pending owner authorization. No cloud mutation or purchase. CI watchers armed for both current-head workflows; CR full review requested with one watcher. |
Adds the legacy Compute Admin migration checklist tracked in #2123. Existing wizard installations retain broad grants until their owner reviews and authorizes removal.
The checklist inventories direct and inherited policies with resource and condition attribution, inspects exact narrow role grants, removes only individually approved bindings at the owning resource, and tests effective permissions after broad access stops masking missing replacements. The supported Resource Manager permissions API replaces an invalid gcloud command. Credential recovery, conditional grants and operator rollback require explicit authorization.
Verification at
38124c788dc4b84689d05a2ad05dc86f1a071be3:Evidence is offline fixtures and local HTTP integration. No live IAM propagation or deployed read-only workflow verified, no cloud mutation or purchase performed. Live installation inventory and remediation remain tracked by #2123 pending project-owner authorization. This PR does not close that issue.
Refs #2123