Skip to content

Commit 121d53f

Browse files
committed
Removes org browser role, adds compute viewe role
1 parent 807e7db commit 121d53f

File tree

1 file changed

+2
-8
lines changed
  • 4-appfactory/modules/app-group-baseline

1 file changed

+2
-8
lines changed

4-appfactory/modules/app-group-baseline/main.tf

+2-8
Original file line numberDiff line numberDiff line change
@@ -27,7 +27,8 @@ locals {
2727
"roles/storage.admin", "roles/iam.serviceAccountAdmin",
2828
"roles/artifactregistry.admin", "roles/clouddeploy.admin",
2929
"roles/cloudbuild.builds.editor", "roles/resourcemanager.projectIamAdmin",
30-
"roles/iam.serviceAccountUser", "roles/source.admin", "roles/cloudbuild.connectionAdmin"
30+
"roles/iam.serviceAccountUser", "roles/source.admin", "roles/cloudbuild.connectionAdmin",
31+
"roles/compute.viewer"
3132
]
3233
} },
3334
{
@@ -253,13 +254,6 @@ resource "google_service_account_iam_member" "account_access" {
253254
member = "serviceAccount:${reverse(split("/", module.tf_cloudbuild_workspace.cloudbuild_sa))[0]}"
254255
}
255256

256-
resource "google_organization_iam_member" "builder_organization_browser" {
257-
for_each = toset(local.org_ids)
258-
member = "serviceAccount:${reverse(split("/", module.tf_cloudbuild_workspace.cloudbuild_sa))[0]}"
259-
org_id = each.value
260-
role = "roles/browser"
261-
}
262-
263257
// Create infra project
264258
module "app_infra_project" {
265259
source = "terraform-google-modules/project-factory/google"

0 commit comments

Comments
 (0)