From d3ef2ef11f439fab902913e3792545b828132fc6 Mon Sep 17 00:00:00 2001 From: Marios Andreopoulos Date: Wed, 2 Dec 2015 19:47:25 +0000 Subject: [PATCH] fix: do not set scopes account to service account used for instance creation --- cloud/google/gce.py | 7 ++----- 1 file changed, 2 insertions(+), 5 deletions(-) diff --git a/cloud/google/gce.py b/cloud/google/gce.py index fcaa3b85023..23ed01f7841 100644 --- a/cloud/google/gce.py +++ b/cloud/google/gce.py @@ -64,7 +64,7 @@ options: default: null choices: [ "bigquery", "cloud-platform", "compute-ro", "compute-rw", - "computeaccounts-ro", "computeaccounts-rw", "datastore", "logging-write", + "useraccounts-ro", "useraccounts-rw", "datastore", "logging-write", "monitoring", "sql", "sql-admin", "storage-full", "storage-ro", "storage-rw", "taskqueue", "userinfo-email" ] @@ -351,10 +351,7 @@ def create_instances(module, gce, instance_names): bad_perms.append(perm) if len(bad_perms) > 0: module.fail_json(msg='bad permissions: %s' % str(bad_perms)) - if service_account_email: - ex_sa_perms.append({'email': service_account_email}) - else: - ex_sa_perms.append({'email': "default"}) + ex_sa_perms.append({'email': "default"}) ex_sa_perms[0]['scopes'] = service_account_permissions # These variables all have default values but check just in case