# allow a cluster to write logs to its banner project(gcp_project_id) apiVersion: iam.cnrm.cloud.google.com/v1beta1 kind: IAMPolicyMember metadata: name: fluentbit-sa-k8s-logs-writer-banner spec: member: serviceAccount:o11y-${cluster_hash}@${gcp_project_id}.iam.gserviceaccount.com resourceRef: apiVersion: resourcemanager.cnrm.cloud.google.com/v1beta1 kind: Project external: projects/${gcp_project_id} role: roles/logging.logWriter