Google Storage - Bucket Permissions

Status
Not open for further replies.

wys

Platinum Partner
Basic Certified
Joined
Jan 5, 2015
Messages
18
Reaction score
0
With 3CX v16u5 we are looking to move all our backups to a Google Storage.

We have created Service Accounts and Buckets for all of our clients with 3CX v16u5, Google Storage connection to the bucket works fine when the service account is set with the Role Storage Admin, however when I remove the Storage Admin role at the top level and just apply Storage Admin for the specific user at the bucket level 3CX won't connect to the bucket.

Has anyone else had this issue, or is there a better way to set this up but keep segregation between backup folders.
 
Hi wys

Have you tried creating separate projects per customer or were you storing all the backups in the same project?
 
Hi wys

Have you tried creating separate projects per customer or were you storing all the backups in the same project?

Hi JohnS_3CX,

Thanks for the reply.

I have a single project with a bucket and service account for each client.

As mentioned in my original post i'd like to only have a service account access one bucket, to prevent 3CX instances being able to access all bucket resources.

It my understanding, if you remove the storage admin role from the service account which stops inheritance to all buckets, you should be able to just give the service account Storage Admin on a specific bucket, but this wouldn't work and 3CX wouldn't connect.

Thanks in advance
 
3CX will really rely on what Google will allow it to do. Changing the role structure in a way that breaks the chain of permission will probably cause the Google API to give us a negative response when we try to access the the bucket resource.

We defined the requirements here: https://www.3cx.com/docs/google-cloud-storage/
 
Status
Not open for further replies.

Latest Posts

Forum statistics

Threads
111,948
Messages
589,880
Members
164,841
Latest member
erre