Skip to content

ci: Initial Terraform configurations (Work in Progress) #8436

New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Closed
wants to merge 111 commits into from
Closed
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
111 commits
Select commit Hold shift + click to select a range
1d3f47c
ci: Initial Terraform configurations (Work in Progress)
burkedavison Sep 21, 2022
fb6b240
ci: Add Terraform scripts and configurations for java-accessapproval,…
burkedavison Sep 21, 2022
fe40718
fix: Remove hardcoded project prefix, and replace with environment va…
burkedavison Sep 21, 2022
65ff848
fix: Ensure 'set-quota-project' is set to the created GCP project. De…
burkedavison Sep 21, 2022
6f89ea6
fix: Workaround set-quota-project not working when previous quota pro…
burkedavison Sep 22, 2022
dad488e
chore: Add 'auto_create_subnetworks' to container network configuration.
burkedavison Sep 22, 2022
3959735
fix: Add predestroy stage. Remove container network from tfstate to a…
burkedavison Sep 22, 2022
3fbf756
chore: Refactor script to split project and module provisioning. Supp…
burkedavison Sep 22, 2022
061b666
chore: Add java-compute terraform config
burkedavison Sep 22, 2022
9eaac54
chore: Add java-containeranalysis terraform config
burkedavison Sep 22, 2022
1ddad88
chore: Add java-datacatalog terraform config
burkedavison Sep 22, 2022
638566e
chore: Add java-datalabeling terraform config
burkedavison Sep 22, 2022
45dfae5
chore: Add java-errorreporting terraform config
burkedavison Sep 22, 2022
1aee4e1
chore: Add java-game-servers terraform config
burkedavison Sep 22, 2022
57a1ef3
chore: Add java-iot terraform config
burkedavison Sep 22, 2022
52b4884
chore: Add java-kms terraform config
burkedavison Sep 22, 2022
fdf8198
chore: Add java-monitoring terraform config
burkedavison Sep 22, 2022
4c93bcb
chore: Add java-resourcemanager terraform config
burkedavison Sep 22, 2022
d8d5727
chore: Add java-secretmanager terraform config
burkedavison Sep 22, 2022
cbe9b98
chore: Add java-speech terraform config
burkedavison Sep 22, 2022
cf3c219
chore: Add java-trace terraform config
burkedavison Sep 22, 2022
f7543ae
chore: Add java-translate terraform config
burkedavison Sep 22, 2022
d5b11ca
chore: Add java-video-intelligence terraform config
burkedavison Sep 22, 2022
57aebd8
chore: Add java-vision terraform config
burkedavison Sep 22, 2022
5e8a943
chore: Refactor solution to use single generated Terraform root modul…
burkedavison Sep 26, 2022
3a817cf
chore: Add java-asset
burkedavison Sep 26, 2022
85d4ace
chore: Add java-iam-admin
burkedavison Sep 26, 2022
e13a6e9
chore: Add java-notebooks
burkedavison Sep 26, 2022
72a0d60
chore: Add java-texttospeech
burkedavison Sep 26, 2022
8594ff7
chore: Add java-dataproc
burkedavison Sep 26, 2022
51f1fd8
chore: Add java-tasks
burkedavison Sep 26, 2022
8f27d2a
fix: Remove unintentional .kokoro/build.sh modification.
burkedavison Sep 26, 2022
7efd5d4
fix: Ensure compute API is enabled prior to requesting compute defaul…
burkedavison Sep 27, 2022
cacbcec
chore: Create and Impersonate a Service Account on the Terraform-crea…
burkedavison Sep 27, 2022
13c2f1b
chore: Add java-dns terraform configuration
burkedavison Sep 27, 2022
329748c
chore: Add java-dialogflow and java-dialogflow-cx terraform configura…
burkedavison Sep 27, 2022
c75f5c8
fix: Ensure environment variables are correctly added when performing…
burkedavison Sep 28, 2022
41f1325
fix: Fail fast if terraform apply fails.
burkedavison Sep 28, 2022
8cecc8d
chore: Rework module output and env.sh design to eliminate need for f…
burkedavison Sep 28, 2022
ecfdd45
chore: Add java-notification support
burkedavison Sep 28, 2022
327c613
fix: Ensure environment variables are set with script if not already …
burkedavison Sep 28, 2022
977ce54
fix: Add time delay to allow role/permissions to apply to service acc…
burkedavison Sep 28, 2022
6c25de7
fix: Relocate invocation of generated-env.sh to ensure consistent app…
burkedavison Sep 28, 2022
3d4cc93
chore: Support 'y' argument to destroy.sh to destroy the project non-…
burkedavison Sep 28, 2022
5b71c3f
fix: Destroy modules before project to ensure clean starting point fo…
burkedavison Sep 28, 2022
36f146d
chore: Add test-individually.sh, which iterates through each terrafor…
burkedavison Sep 28, 2022
1f86837
fix: Apply predestroy.sh to <root>/.terraform state.
burkedavison Sep 28, 2022
cd1b082
chore: Add java-scheduler, although not yet reliable.
burkedavison Sep 29, 2022
03ef514
chore: Add java-oslogin. Not currently working.
burkedavison Sep 29, 2022
9ae6b1a
fix: Rework of Terraform logic to use single root module. Project and…
burkedavison Sep 30, 2022
74a6728
fix: cleanup
burkedavison Sep 30, 2022
040d9a3
fix: Ensure cloudresourcemanager.googleapis.com is enabled prior to s…
burkedavison Oct 3, 2022
be9b07c
Merge branch 'main' into terraform
burkedavison Oct 3, 2022
a50e5fd
fix: Workaround for 'Resource Exhausted' error given first time runni…
burkedavison Oct 3, 2022
01b0570
fix: Re-enable job and topic deletions during Scheduler IT clean up.
burkedavison Oct 3, 2022
5e05e29
fix: Re-enable application-default login and add delay after enabling…
burkedavison Oct 3, 2022
8d3ded0
fix: Apply retry to v1beta1 Scheduler IT
burkedavison Oct 3, 2022
42e677d
fix: Sleep immediately after gcloud project creation to allow default…
burkedavison Oct 3, 2022
30da4a1
fix: Add 10s delay after creating service account and before assignin…
burkedavison Oct 3, 2022
6a8b09a
fix: Replace compound assertion statement with fine-grain assertions …
burkedavison Oct 3, 2022
2529c10
Merge remote-tracking branch 'origin/terraform' into terraform
burkedavison Oct 3, 2022
7ee1e2a
fix: Add delay to allow service account permissions to settle.
burkedavison Oct 3, 2022
70ce173
chore: Handle generated-outputs.template.tf same as generated-main+va…
burkedavison Oct 3, 2022
e1f2f03
fix: Assign gcloud_account local variable before using it. Comment im…
burkedavison Oct 3, 2022
eb9a2f1
fix: Synchronize environment using common script when entering indivi…
burkedavison Oct 3, 2022
68e6e14
fix: Fail ITHeadersTest if server does not respond to request, rather…
burkedavison Oct 3, 2022
854dac7
fix: Sleep syntax, and no longer sync environment before apply.sh
burkedavison Oct 3, 2022
c800cdc
fix: DRY and remove unnecessary resources from template.
burkedavison Oct 3, 2022
5c204bd
Revert "fix: Fail ITHeadersTest if server does not respond to request…
burkedavison Oct 4, 2022
82de4ef
chore: Explicit error when headers is null.
burkedavison Oct 4, 2022
3b8c01b
chore: Make API enabling and disabling behaviors variables, following…
burkedavison Oct 4, 2022
ff29a16
fix: Increase retries and retry delay in Scheduler IT to ensure enoug…
burkedavison Oct 4, 2022
7eb3309
fix: Add region to submodule input object. Fix typo.
burkedavison Oct 4, 2022
dd7a68e
Merge branch 'main' into terraform
burkedavison Oct 4, 2022
acc1c28
fix: When running ITs with terraform, ignore os-login, recommender, a…
burkedavison Oct 4, 2022
77fec0e
chore: DRY friendly output module name, and module output value parsing.
burkedavison Oct 4, 2022
41bc320
fix: Randomize Dialogflow Agent name.
burkedavison Oct 4, 2022
8629ecd
fix: Randomize Container Network name.
burkedavison Oct 4, 2022
cacb6ed
fix: Attempt to refresh Terraform's state if no project ID is in its …
burkedavison Oct 4, 2022
69a760d
chore: Add java-recommender Terraform configuration, and adjust IT to…
burkedavison Oct 4, 2022
75c031d
chore: Improve ./.terraform/README.md
burkedavison Oct 4, 2022
92fa513
fix: Only invoke predestroy.sh for active modules.
burkedavison Oct 5, 2022
d6a936f
chore: Refactor all Terraform project setup steps into setup.sh
burkedavison Oct 5, 2022
fb6b69a
chore: Add java-talent Terraform configuration
burkedavison Oct 5, 2022
09cf5cb
chore: Simplify
burkedavison Oct 6, 2022
1a06ff9
fix: Consistent application of variable rename
burkedavison Oct 6, 2022
8611e97
fix: Wait 60s after service account creation to mitigate errors due t…
burkedavison Oct 6, 2022
3f18991
chore: Slightly lengthen initialization waiting time for service acco…
burkedavison Oct 6, 2022
b891f4d
fix: Additional delay and comment around scheduler retry.
burkedavison Oct 6, 2022
5778d9b
chore: Remove ./.terraform/README.md while offline review continues.
burkedavison Oct 6, 2022
8604095
Merge branch 'main' into terraform
burkedavison Oct 6, 2022
0c917af
fix: Don't prepend "serviceAccount:" when using member "allAuthentica…
burkedavison Oct 7, 2022
f479750
Merge branch 'main' into terraform
burkedavison Oct 7, 2022
f8277b8
chore: Change module delimiter from ':' to ',' for consistency with .…
burkedavison Oct 7, 2022
843c440
Merge branch 'main' into terraform
burkedavison Oct 7, 2022
0fef18c
chore: Split 'gcloud' steps from 'terraform' steps in preparation for…
burkedavison Oct 7, 2022
483dea6
fix: Return to previous working directory after plan.sh
burkedavison Oct 7, 2022
c5264f9
chore: Use set -eo pipefail rather than explicit "|| exit"
burkedavison Oct 10, 2022
42b099b
Merge branch 'main' into terraform
burkedavison Oct 11, 2022
70527ff
chore: Remove 'test-individually.sh'
burkedavison Oct 11, 2022
bc34548
fix: Ignore 'java-recommender' IT rather than modifying logic.
burkedavison Oct 11, 2022
56abe0c
Merge branch 'main' into terraform
burkedavison Oct 14, 2022
0db282c
chore: release main (#8610)
release-please[bot] Oct 14, 2022
6420712
build: have release-please tag releases (#8615)
chingor13 Oct 17, 2022
023793d
Merge branch 'main' into terraform
burkedavison Oct 17, 2022
ddae556
Merge branch 'main' into terraform
burkedavison Oct 19, 2022
3f9b482
fix: Revert ITHeadersTest changes to same as main
burkedavison Oct 19, 2022
5ac7c07
fix: Remove unused import
burkedavison Oct 19, 2022
a6dfc72
fix: Apply mvn com.coveo:fmt-maven-plugin:format
burkedavison Oct 19, 2022
09abe52
ci: Terraform now used in Kokoro integration tests
burkedavison Oct 24, 2022
23c4a91
ci: Temporarily disable Terraform in integration tests
burkedavison Oct 24, 2022
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
14 changes: 13 additions & 1 deletion .gitignore
Original file line number Diff line number Diff line change
Expand Up @@ -57,4 +57,16 @@ api_key
generation/new_client/workspace

# Monorepo repository generation
monorepo
monorepo

# Terraform
*.hcl
**/.terraform/.terraform/
**/.terraform/plugins/
**/.terraform/providers/
**/.terraform/plugin_path
*.lock.
*.tfstate
*.tfstate.backup
*.tfstate.*.backup
*.tfstate.lock.info
10 changes: 10 additions & 0 deletions .kokoro/build.sh
Original file line number Diff line number Diff line change
Expand Up @@ -47,6 +47,13 @@ case ${JOB_TYPE} in
IFS=,
echo "${modified_module_list[*]}"
)

# terraform -version
# source ./.terraform/helpers/init.sh "$module_list"
# source ./.terraform/helpers/plan.sh
# source ./.terraform/helpers/apply.sh
# source ./.terraform/helpers/populate-env.sh

install_modules
printf "Running Integration Tests for:\n%s\n" "${module_list}"
mvn -B ${INTEGRATION_TEST_ARGS} \
Expand All @@ -66,6 +73,9 @@ case ${JOB_TYPE} in
-T 1C \
verify
RETURN_CODE=$?

# source ./.terraform/helpers/destroy.sh

printf "Finished Integration Tests for:\n%s\n" "${module_list}"
else
echo "No Integration Tests to run"
Expand Down
7 changes: 7 additions & 0 deletions .terraform/.gitignore
Original file line number Diff line number Diff line change
@@ -0,0 +1,7 @@
generated.tfplan
generated.tfplan.json
generated.auto.tfvars
generated-env.sh
generated-main.tf
generated-outputs.tf
generated-variables.tf
31 changes: 31 additions & 0 deletions .terraform/cleanup.sh
Original file line number Diff line number Diff line change
@@ -0,0 +1,31 @@
#
# Copyright 2022 Google LLC
#
# Licensed under the Apache License, Version 2.0 (the "License");
# you may not use this file except in compliance with the License.
# You may obtain a copy of the License at
#
# https://www.apache.org/licenses/LICENSE-2.0
#
# Unless required by applicable law or agreed to in writing, software
# distributed under the License is distributed on an "AS IS" BASIS,
# WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
# See the License for the specific language governing permissions and
# limitations under the License.
#
set -eo pipefail

scriptDir="$(cd -P -- "$(dirname -- "${BASH_SOURCE[0]}")" && pwd -P)"
pushd "$scriptDir" >/dev/null

# Ensure GCP project environment variables are initialized.
if [[ $(terraform state list) == "" ]]; then
echo "Nothing to destroy."
exit
fi

source ./helpers/gcloud-sync-env.sh
source ./helpers/destroy.sh
source ./helpers/gcloud-delete-project.sh

popd >/dev/null
21 changes: 21 additions & 0 deletions .terraform/helpers/apply.sh
Original file line number Diff line number Diff line change
@@ -0,0 +1,21 @@
#
# Copyright 2022 Google LLC
#
# Licensed under the Apache License, Version 2.0 (the "License");
# you may not use this file except in compliance with the License.
# You may obtain a copy of the License at
#
# https://www.apache.org/licenses/LICENSE-2.0
#
# Unless required by applicable law or agreed to in writing, software
# distributed under the License is distributed on an "AS IS" BASIS,
# WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
# See the License for the specific language governing permissions and
# limitations under the License.
#
set -eo pipefail

helperDir="$(cd -P -- "$(dirname -- "${BASH_SOURCE[0]}")" && pwd -P)"
pushd "$helperDir/.." >/dev/null || exit
terraform apply "generated.tfplan" || exit
popd >/dev/null || exit
71 changes: 71 additions & 0 deletions .terraform/helpers/common.sh
Original file line number Diff line number Diff line change
@@ -0,0 +1,71 @@
#
# Copyright 2022 Google LLC
#
# Licensed under the Apache License, Version 2.0 (the "License");
# you may not use this file except in compliance with the License.
# You may obtain a copy of the License at
#
# https://www.apache.org/licenses/LICENSE-2.0
#
# Unless required by applicable law or agreed to in writing, software
# distributed under the License is distributed on an "AS IS" BASIS,
# WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
# See the License for the specific language governing permissions and
# limitations under the License.
#
set -eo pipefail

# Find all directories starting with 'java-', sort them, then join
# with ',' as the delimiter.
function listAllModules() {
# Ensure current directory is repo root.
helperDir="$(cd -P -- "$(dirname -- "${BASH_SOURCE[0]}")" && pwd -P)"
pushd "$helperDir/../.." >/dev/null

ls -1 -d java-* | sort | paste -s -d, -

popd >/dev/null
}

# Replaces '-' with '_' to get a Terraform output-friendly label
function getFriendlyOutputName() {
echo "$1" | tr '-' _
}

# Get the output object in JSON format for the given module.
function getOutput() {
friendlyName=$(getFriendlyOutputName "$1")
terraform output -json "$friendlyName"
}

# Parse stdin and get the value associated with the given key.
function parseJson() {
python3 -c "import sys, json; print(json.load(sys.stdin)['$1'])"
}

# Example use: getModuleOutput java-redis redis_network
function getModuleOutput() {
getOutput "$1" | parseJson "$2"
}

# @returns exit code 0 if list $1 contains entry $2.
function contains() {
echo "$1" | grep -w -q "$2"
}

# @returns a new-line delimited list of active terraform modules
function getActiveTerraformModules() {
terraform state list | awk -F'[/.]' '{print $2}' | uniq
}

function getTerraformServiceAccountName() {
echo "terraform-service-account"
}

function getTerraformServiceAccountEmail() {
if [ -z "${GOOGLE_CLOUD_PROJECT}" ]; then
echo "GOOGLE_CLOUD_PROJECT must be defined."
exit 1
fi
echo "$(getTerraformServiceAccountName)@$GOOGLE_CLOUD_PROJECT.iam.gserviceaccount.com"
}
39 changes: 39 additions & 0 deletions .terraform/helpers/destroy.sh
Original file line number Diff line number Diff line change
@@ -0,0 +1,39 @@
#
# Copyright 2022 Google LLC
#
# Licensed under the Apache License, Version 2.0 (the "License");
# you may not use this file except in compliance with the License.
# You may obtain a copy of the License at
#
# https://www.apache.org/licenses/LICENSE-2.0
#
# Unless required by applicable law or agreed to in writing, software
# distributed under the License is distributed on an "AS IS" BASIS,
# WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
# See the License for the specific language governing permissions and
# limitations under the License.
#
set -eo pipefail

helperDir="$(cd -P -- "$(dirname -- "${BASH_SOURCE[0]}")" && pwd -P)"
pushd "$helperDir/.." >/dev/null

# Execute 'predestroy.sh' scripts for any active modules
source ./helpers/common.sh
allModules=$(listAllModules)
activeModules=$(getActiveTerraformModules)
IFS=','
for module in $allModules; do
friendlyName=$(getFriendlyOutputName "$module")
if ! contains "$activeModules" "$friendlyName"; then
continue # Skip unless active.
fi

if [[ -f "../$module/.terraform/predestroy.sh" ]]; then
# shellcheck disable=SC1090
source "../$module/.terraform/predestroy.sh"
fi
done

terraform destroy -auto-approve
popd >/dev/null
65 changes: 65 additions & 0 deletions .terraform/helpers/gcloud-create-project.sh
Original file line number Diff line number Diff line change
@@ -0,0 +1,65 @@
#!/bin/bash
#
# Copyright 2022 Google LLC
#
# Licensed under the Apache License, Version 2.0 (the "License");
# you may not use this file except in compliance with the License.
# You may obtain a copy of the License at
#
# https://www.apache.org/licenses/LICENSE-2.0
#
# Unless required by applicable law or agreed to in writing, software
# distributed under the License is distributed on an "AS IS" BASIS,
# WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
# See the License for the specific language governing permissions and
# limitations under the License.
#
set -eo pipefail

if [ -n "${GOOGLE_CLOUD_PROJECT}" ]; then
echo "Using current GOOGLE_CLOUD_PROJECT: $GOOGLE_CLOUD_PROJECT"
return
fi

currentProject=$(gcloud config get project)
if [ -n "${currentProject}" ]; then
echo -n "Do you want to use the current gcloud project ($currentProject)? (Y|n): "
read -r shouldUseCurrent
if [[ "$shouldUseCurrent" != n* ]] && [[ "$shouldUseCurrent" != N* ]]; then
GOOGLE_CLOUD_PROJECT=$currentProject
export GOOGLE_CLOUD_PROJECT
return
fi
fi

echo -n "GOOGLE_CLOUD_PROJECT not set. Do you want to create a project? (Y|n): "
read -r shouldCreate
if [[ "$shouldCreate" == n* ]] || [[ "$shouldCreate" == N* ]]; then
echo "Project required. Exiting."
exit 1
fi

# Ensure required environment variables are set.
if [ -z "${GOOGLE_CLOUD_FOLDER_ID}" ]; then
echo -n "GOOGLE_CLOUD_FOLDER_ID not set. GCP Folder ID: "
read -r folder_id
export GOOGLE_CLOUD_FOLDER_ID="${folder_id}"
fi
if [ -z "${GOOGLE_CLOUD_BILLING_ACCOUNT}" ]; then
echo -n "GOOGLE_CLOUD_BILLING_ACCOUNT not set. GCP Billing Account ID: "
read -r billing_acct
export GOOGLE_CLOUD_BILLING_ACCOUNT="${billing_acct}"
fi
if [ -z "${GOOGLE_CLOUD_PROJECT_PREFIX}" ]; then
echo -n "GOOGLE_CLOUD_PROJECT_PREFIX not set. Prefix for New Project: "
read -r prefix
export GOOGLE_CLOUD_PROJECT_PREFIX="${prefix}"
fi

# Provision GCP Project
projectId="${GOOGLE_CLOUD_PROJECT_PREFIX}"-"$RANDOM"
gcloud projects create --folder="$GOOGLE_CLOUD_FOLDER_ID" "$projectId" || exit
gcloud config set project "$projectId"
gcloud services enable cloudresourcemanager.googleapis.com
gcloud beta billing projects link "$projectId" --billing-account="$GOOGLE_CLOUD_BILLING_ACCOUNT"
GOOGLE_CLOUD_PROJECT=$projectId
63 changes: 63 additions & 0 deletions .terraform/helpers/gcloud-create-service-account.sh
Original file line number Diff line number Diff line change
@@ -0,0 +1,63 @@
#
# Copyright 2022 Google LLC
#
# Licensed under the Apache License, Version 2.0 (the "License");
# you may not use this file except in compliance with the License.
# You may obtain a copy of the License at
#
# https://www.apache.org/licenses/LICENSE-2.0
#
# Unless required by applicable law or agreed to in writing, software
# distributed under the License is distributed on an "AS IS" BASIS,
# WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
# See the License for the specific language governing permissions and
# limitations under the License.
#
set -eo pipefail

# Use the project ID in gcloud set-quota-project. Clear the existing quota project directly from
# the configuration, and re-set.
gcloud config set project "$GOOGLE_CLOUD_PROJECT"
sed -i.bak '/quota_project_id/d' ~/.config/gcloud/application_default_credentials.json
gcloud auth application-default set-quota-project "$GOOGLE_CLOUD_PROJECT"

# Assign permission for current gcloud account to impersonate a service account.
gcloud_account=$(gcloud config get account)
gcloud projects add-iam-policy-binding "$GOOGLE_CLOUD_PROJECT" \
--member="user:$gcloud_account" \
--role="roles/iam.serviceAccountTokenCreator" >/dev/null

# Set up service account for impersonation
source ./helpers/common.sh
service_account_name=$(getTerraformServiceAccountName)
service_account_email=$(getTerraformServiceAccountEmail)
# If it doesn't already exist, create the service account.
gcloud iam service-accounts describe "$service_account_email" &>/dev/null
if [[ $? -ne 0 ]]; then
gcloud iam service-accounts create "$service_account_name"
createdServiceAccount=true
else
createdServiceAccount=false
fi

# Assign permissions to the service account.
gcloud projects add-iam-policy-binding "$GOOGLE_CLOUD_PROJECT" \
--member="serviceAccount:$service_account_email" \
--role="roles/owner" >/dev/null
gcloud projects add-iam-policy-binding "$GOOGLE_CLOUD_PROJECT" \
--member="serviceAccount:$service_account_email" \
--role="roles/resourcemanager.projectIamAdmin" >/dev/null

# See https://cloud.google.com/blog/topics/developers-practitioners/using-google-cloud-service-account-impersonation-your-terraform-code
export GOOGLE_IMPERSONATE_SERVICE_ACCOUNT=$service_account_email

if $createdServiceAccount; then
echo "Waiting 2m for service account permissions to take effect... [0s elapsed]"
sleep 30
echo "Waiting 2m for service account permissions to take effect... [30s elapsed]"
sleep 30
echo "Waiting 2m for service account permissions to take effect... [1m0s elapsed]"
sleep 30
echo "Waiting 2m for service account permissions to take effect... [1m30s elapsed]"
sleep 30
fi
35 changes: 35 additions & 0 deletions .terraform/helpers/gcloud-delete-project.sh
Original file line number Diff line number Diff line change
@@ -0,0 +1,35 @@
#
# Copyright 2022 Google LLC
#
# Licensed under the Apache License, Version 2.0 (the "License");
# you may not use this file except in compliance with the License.
# You may obtain a copy of the License at
#
# https://www.apache.org/licenses/LICENSE-2.0
#
# Unless required by applicable law or agreed to in writing, software
# distributed under the License is distributed on an "AS IS" BASIS,
# WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
# See the License for the specific language governing permissions and
# limitations under the License.
#
set -eo pipefail

if [ -n "${GOOGLE_CLOUD_PROJECT}" ]; then
helperDir="$(cd -P -- "$(dirname -- "${BASH_SOURCE[0]}")" && pwd -P)"
pushd "$helperDir/.." >/dev/null

# Always verify whether or not to destroy the project.
echo -n "Delete project ($GOOGLE_CLOUD_PROJECT)? (y/N): "
read -r shouldDestroy
if [[ "$shouldDestroy" == y* ]] || [[ "$shouldDestroy" == Y* ]]; then
# Do not use service account when attempting to delete the project
unset GOOGLE_IMPERSONATE_SERVICE_ACCOUNT
gcloud projects delete "$GOOGLE_CLOUD_PROJECT"
gcloud config unset project
unset GOOGLE_CLOUD_PROJECT
rm ./generated.auto.tfvars
fi

popd >/dev/null
fi
Loading