DEV Community

Discussion on: Securing access to Google Service Accounts from Gitlab CI

Collapse
 
chabane profile image
Chabane R.

Hi Tim!

Thanks for your contribution!

The credentials will live as long as the gitlab runner job is up so just after the completion of the stage.

For a Kubernetes cluster shared between different teams or departments, I would recommend using Kubernetes RBAC or Kubernetes Agents (Premium tiers). It could help to respect least privilege principles.