I'm a beginner so I don't want to make any elementary security mistakes.
In the setup tasks - I need to create an osLogin permission, which means my service account for terraform needs elevated permissions, is there a better way of managing this? Could I perhaps configure that account with `gcloud` and then do the rest with terraform? Is that more secure?
Additionally, I want to pull code from github to non-bastion instances. Is there a good way to get a ssh key onto each box, securely and automatically, to allow github access? Consider that I might want to spin up a new disk and instance for dev at any time.