Policy: GCP > Project > Organization Policy > Disable service account key creation
Manage the GCP Organization Policy "Disable service account key creation" for the project.
This boolean constraint disables the creation of service account external keys where this constraint is set to True.
By default, service account external keys can be created by users based on their Cloud IAM roles and permissions.
Resource Types
This policy targets the following resource types:
Primary Policy
This policy is used with the following primary policy:
Controls
- GCP > Project > Organization Policy > Disable service account key creation
- GCP > Project > Organization Policy
Policy Specification
Schema Type |
|
---|---|
Default |
|
Valid Values [YAML] |
|
Examples [YAML] |
|
Category
In Your Workspace
Developers
- tmod:@turbot/turbot#/control/categories/policy
- tmod:@turbot/gcp-orgpolicy#/policy/types/iamDisableServiceAccountKeyCreation
- turbot graphql policy-type --id "tmod:@turbot/gcp-orgpolicy#/policy/types/iamDisableServiceAccountKeyCreation"
- turbot graphql policy-settings --filter "policyTypeId:tmod:@turbot/gcp-orgpolicy#/policy/types/iamDisableServiceAccountKeyCreation"
Get Policy TypeGet Policy Settings
Category URI
Policy Type URI
GraphQL
CLI