Hello

Thanks for your question. It means that the user who run the AppScript must be able to impersonate the service account i.e. to generate a token on behalf the service account.

To achieve that, you need a specific permission on the service account (because the service account is also a resource and you can bind IAM policies on it).

Therefore, you must grant the role service account token creator on the service account or higher in the hierarchy (project, folder or organization)

Sign up to discover human stories that deepen your understanding of the world.

Free

Distraction-free reading. No ads.

Organize your knowledge with lists and highlights.

Tell your story. Find your audience.

Membership

Read member-only stories

Support writers you read most

Earn money for your writing

Listen to audio narrations

Read offline with the Medium app

guillaume blaquiere
guillaume blaquiere

Written by guillaume blaquiere

GDE cloud platform, Group Data Architect @Carrefour, speaker, writer and polyglot developer, Google Cloud platform 3x certified, serverless addict and Go fan.

No responses yet

Write a response