Skip to content

Commit dda2fcf

Browse files
committed
Removes org browser role, adds compute viewe role
1 parent 807e7db commit dda2fcf

File tree

1 file changed

+2
-9
lines changed
  • 4-appfactory/modules/app-group-baseline

1 file changed

+2
-9
lines changed

4-appfactory/modules/app-group-baseline/main.tf

+2-9
Original file line numberDiff line numberDiff line change
@@ -27,7 +27,8 @@ locals {
2727
"roles/storage.admin", "roles/iam.serviceAccountAdmin",
2828
"roles/artifactregistry.admin", "roles/clouddeploy.admin",
2929
"roles/cloudbuild.builds.editor", "roles/resourcemanager.projectIamAdmin",
30-
"roles/iam.serviceAccountUser", "roles/source.admin", "roles/cloudbuild.connectionAdmin"
30+
"roles/iam.serviceAccountUser", "roles/source.admin", "roles/cloudbuild.connectionAdmin",
31+
"roles/compute.viewer"
3132
]
3233
} },
3334
{
@@ -38,7 +39,6 @@ locals {
3839
}
3940
)
4041

41-
org_ids = distinct([for env in var.envs : env.org_id])
4242
use_csr = var.cloudbuildv2_repository_config.repo_type == "CSR"
4343
service_repo_name = var.cloudbuildv2_repository_config.repositories[var.service_name].repository_name
4444
worker_pool_project = element(split("/", var.workerpool_id), index(split("/", var.workerpool_id), "projects") + 1, )
@@ -253,13 +253,6 @@ resource "google_service_account_iam_member" "account_access" {
253253
member = "serviceAccount:${reverse(split("/", module.tf_cloudbuild_workspace.cloudbuild_sa))[0]}"
254254
}
255255

256-
resource "google_organization_iam_member" "builder_organization_browser" {
257-
for_each = toset(local.org_ids)
258-
member = "serviceAccount:${reverse(split("/", module.tf_cloudbuild_workspace.cloudbuild_sa))[0]}"
259-
org_id = each.value
260-
role = "roles/browser"
261-
}
262-
263256
// Create infra project
264257
module "app_infra_project" {
265258
source = "terraform-google-modules/project-factory/google"

0 commit comments

Comments
 (0)