What scopes / roles are required for a service account to be able to submit container builder jobs?
问题 When creating a new service account to handle Container Builder jobs, the jobs fail with the following error despite the service account having Cloud Container Builder , Logs Viewer and Private Logs viewer : ERROR: (gcloud.container.builds.submit) HTTPError 403: <?xml version='1.0' encoding='UTF-8'?> <Error> <Code>AccessDenied</Code> <Message>Access denied.</Message> <Details>v2-container-builder@redacted.iam.gserviceaccount.com does not have storage.objects.get access to object redacted