is there a way to have Google Cloud IAM Service account restricted to only one zone in Coud DNS? I want to use this for automatic ACME DNS-01 certificate issuing, but I do not want to add full control of all domains/zones. I tried to set Condition to Service account, but it did not work - zone names are probably not resources?
Docs says that lowest resource is Project, so only possibility to have acme challenge secured is to have separate Project with own service account for that domain? https://cloud.google.com/dns/docs/access-control