Skip to content

Commit 27caf9e

Browse files
authored
Merge pull request #41 from gitpod-io/nan/agent-storage-iam-comment
docs: explain why agent_storage needs objectAdmin
2 parents 7024d33 + d64f32d commit 27caf9e

1 file changed

Lines changed: 2 additions & 0 deletions

File tree

iam.tf

Lines changed: 2 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -318,6 +318,8 @@ resource "google_storage_bucket_iam_member" "runner_runner_assets_access" {
318318
}
319319

320320
# GCS access for agent storage bucket (runner VMs)
321+
# objectAdmin is required because the runner deletes conversation, blob, and
322+
# result objects during agent execution cleanup (objectUser lacks delete).
321323
resource "google_storage_bucket_iam_member" "runner_agent_storage_access" {
322324
count = var.enable_agents ? 1 : 0
323325

0 commit comments

Comments
 (0)