Skip to content

Commit 43df057

Browse files
authored
fix(cli): correct deploy roles (#3783)
1 parent 9c7cfad commit 43df057

3 files changed

Lines changed: 5 additions & 2 deletions

File tree

‎docs/tutorials/04-deploy.md‎

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -55,7 +55,7 @@ Both workflows sign in to Google Cloud with Workload Identity Federation. GitHub
5555
The command uses your Firebase CLI login. It needs the Owner role, or permission to create service accounts, workload identity pools and IAM bindings. It is safe to run again. It:
5656

5757
1. Enables the IAM, IAM Credentials, Security Token Service and Cloud Resource Manager APIs.
58-
1. Creates a `github-deploy` service account with the roles a deploy needs: `Firebase Hosting Admin`, `Firebase Rules Admin`, `Cloud Datastore Index Admin`, `Cloud Datastore Viewer` (the build reads your content), `Firebase Storage Viewer`, `Cloud Functions Admin`, `Cloud Scheduler Admin`, `Service Usage Consumer` and `Service Account User`. It can't write to Firestore or read Auth users and Storage files. Earlier versions granted `Firebase Admin`, `Cloud Run Admin`, `Artifact Registry Writer` and `Service Usage Admin`, and the command takes them away (verify with a deploy of every target).
58+
1. Creates a `github-deploy` service account with the roles a deploy needs: `Firebase Hosting Admin`, `Firebase Rules Admin`, `Cloud Datastore Index Admin`, `Cloud Datastore Viewer` (the build reads your content), `Firebase Storage Viewer`, `Storage Bucket Viewer`, `Cloud Functions Admin`, `Cloud Scheduler Admin`, `Service Usage Consumer` and `Service Account User`. It can't write to Firestore or read Auth users and Storage files. Earlier versions granted `Firebase Admin`, `Cloud Run Admin`, `Artifact Registry Writer` and `Service Usage Admin`, and the command takes them away (verify with a deploy of every target).
5959
1. Creates a `github` workload identity pool and provider that only accept tokens from your repository. It reads the repository from the `origin` remote. Pass `--repo owner/name` to choose another one.
6060
1. Sets the `WIF_PROVIDER` and `DEPLOY_SERVICE_ACCOUNT` repository variables with the [GitHub CLI](https://cli.github.com/). Without it, the command prints the values to add in the repository settings.
6161

‎packages/cli/src/commands/setup-github.test.ts‎

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -254,6 +254,7 @@ describe('setupGitHub', () => {
254254
'roles/datastore.indexAdmin',
255255
'roles/datastore.viewer',
256256
'roles/firebasestorage.viewer',
257+
'roles/storage.bucketViewer',
257258
'roles/cloudfunctions.admin',
258259
'roles/cloudscheduler.admin',
259260
'roles/serviceusage.serviceUsageConsumer',

‎packages/cli/src/commands/setup-github.ts‎

Lines changed: 3 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -31,8 +31,10 @@ export const DEPLOY_ROLES = [
3131
'roles/datastore.indexAdmin',
3232
// The build reads the site's content.
3333
'roles/datastore.viewer',
34-
// The Storage rules deploy looks up the default bucket.
34+
// The Storage rules deploy looks up the default bucket, which also checks storage.buckets.get and
35+
// list, despite its docs (firebase/firebase-tools#6593).
3536
'roles/firebasestorage.viewer',
37+
'roles/storage.bucketViewer',
3638
// Functions, with their Eventarc triggers and Cloud Run services.
3739
'roles/cloudfunctions.admin',
3840
// The job that runs scheduleNotifications.

0 commit comments

Comments
 (0)