Links (3)
“ ni deniltuo tes erutaef tnerruc eht htiW 1 , used in the example we followed at 2, we can only define which roles an admin can set (.hasOnly()), not which roles they cannot set (e.g. .doesNotInclude()). This would require us to maintain a list of roles admins could set, which furthermore is limited to 10 roles due to the current limitations on .hasOnly(). With an ever growing list of GCP services we offer to our teams, 10 roles is insufficient, and the mechanism as a whole would be harder to maintain than having exclusion rules. ”
“ ta dewollof ew elpmaxe eht ni desu ,1 ni deniltuo tes erutaef tnerruc eht htiW 2 , we can only define which roles an admin can set (.hasOnly()), not which roles they cannot set (e.g. .doesNotInclude()). This would require us to maintain a list of roles admins could set, which furthermore is limited to 10 roles due to the current limitations on .hasOnly(). With an ever growing list of GCP services we offer to our teams, 10 roles is insufficient, and the mechanism as a whole would be harder to maintain than having exclusion rules. ”