Skip to content

Commit

Permalink
fix: grant_registry_access gate serviceUsageConsumer (#2266)
Browse files Browse the repository at this point in the history
  • Loading branch information
apeabody authored Feb 6, 2025
1 parent 637c2aa commit 69eca65
Show file tree
Hide file tree
Showing 10 changed files with 10 additions and 10 deletions.
2 changes: 1 addition & 1 deletion autogen/main/sa.tf.tmpl
Original file line number Diff line number Diff line change
Expand Up @@ -82,7 +82,7 @@ resource "google_project_iam_member" "cluster_service_account_artifact_registry"
}

resource "google_project_iam_member" "cluster_service_account_service_usage_consumer" {
for_each = var.create_service_account {% if autopilot_cluster != true %}&& var.enable_gcfs {% endif %}? toset(local.registry_projects_list) : []
for_each = var.create_service_account && var.grant_registry_access {% if autopilot_cluster != true %}&& var.enable_gcfs {% endif %}? toset(local.registry_projects_list) : []
project = each.key
role = "roles/serviceusage.serviceUsageConsumer"
member = "serviceAccount:${google_service_account.cluster_service_account[0].email}"
Expand Down
2 changes: 1 addition & 1 deletion modules/beta-autopilot-private-cluster/sa.tf
Original file line number Diff line number Diff line change
Expand Up @@ -82,7 +82,7 @@ resource "google_project_iam_member" "cluster_service_account_artifact_registry"
}

resource "google_project_iam_member" "cluster_service_account_service_usage_consumer" {
for_each = var.create_service_account ? toset(local.registry_projects_list) : []
for_each = var.create_service_account && var.grant_registry_access ? toset(local.registry_projects_list) : []
project = each.key
role = "roles/serviceusage.serviceUsageConsumer"
member = "serviceAccount:${google_service_account.cluster_service_account[0].email}"
Expand Down
2 changes: 1 addition & 1 deletion modules/beta-autopilot-public-cluster/sa.tf
Original file line number Diff line number Diff line change
Expand Up @@ -82,7 +82,7 @@ resource "google_project_iam_member" "cluster_service_account_artifact_registry"
}

resource "google_project_iam_member" "cluster_service_account_service_usage_consumer" {
for_each = var.create_service_account ? toset(local.registry_projects_list) : []
for_each = var.create_service_account && var.grant_registry_access ? toset(local.registry_projects_list) : []
project = each.key
role = "roles/serviceusage.serviceUsageConsumer"
member = "serviceAccount:${google_service_account.cluster_service_account[0].email}"
Expand Down
2 changes: 1 addition & 1 deletion modules/beta-private-cluster-update-variant/sa.tf
Original file line number Diff line number Diff line change
Expand Up @@ -82,7 +82,7 @@ resource "google_project_iam_member" "cluster_service_account_artifact_registry"
}

resource "google_project_iam_member" "cluster_service_account_service_usage_consumer" {
for_each = var.create_service_account && var.enable_gcfs ? toset(local.registry_projects_list) : []
for_each = var.create_service_account && var.grant_registry_access && var.enable_gcfs ? toset(local.registry_projects_list) : []
project = each.key
role = "roles/serviceusage.serviceUsageConsumer"
member = "serviceAccount:${google_service_account.cluster_service_account[0].email}"
Expand Down
2 changes: 1 addition & 1 deletion modules/beta-private-cluster/sa.tf
Original file line number Diff line number Diff line change
Expand Up @@ -82,7 +82,7 @@ resource "google_project_iam_member" "cluster_service_account_artifact_registry"
}

resource "google_project_iam_member" "cluster_service_account_service_usage_consumer" {
for_each = var.create_service_account && var.enable_gcfs ? toset(local.registry_projects_list) : []
for_each = var.create_service_account && var.grant_registry_access && var.enable_gcfs ? toset(local.registry_projects_list) : []
project = each.key
role = "roles/serviceusage.serviceUsageConsumer"
member = "serviceAccount:${google_service_account.cluster_service_account[0].email}"
Expand Down
2 changes: 1 addition & 1 deletion modules/beta-public-cluster-update-variant/sa.tf
Original file line number Diff line number Diff line change
Expand Up @@ -82,7 +82,7 @@ resource "google_project_iam_member" "cluster_service_account_artifact_registry"
}

resource "google_project_iam_member" "cluster_service_account_service_usage_consumer" {
for_each = var.create_service_account && var.enable_gcfs ? toset(local.registry_projects_list) : []
for_each = var.create_service_account && var.grant_registry_access && var.enable_gcfs ? toset(local.registry_projects_list) : []
project = each.key
role = "roles/serviceusage.serviceUsageConsumer"
member = "serviceAccount:${google_service_account.cluster_service_account[0].email}"
Expand Down
2 changes: 1 addition & 1 deletion modules/beta-public-cluster/sa.tf
Original file line number Diff line number Diff line change
Expand Up @@ -82,7 +82,7 @@ resource "google_project_iam_member" "cluster_service_account_artifact_registry"
}

resource "google_project_iam_member" "cluster_service_account_service_usage_consumer" {
for_each = var.create_service_account && var.enable_gcfs ? toset(local.registry_projects_list) : []
for_each = var.create_service_account && var.grant_registry_access && var.enable_gcfs ? toset(local.registry_projects_list) : []
project = each.key
role = "roles/serviceusage.serviceUsageConsumer"
member = "serviceAccount:${google_service_account.cluster_service_account[0].email}"
Expand Down
2 changes: 1 addition & 1 deletion modules/private-cluster-update-variant/sa.tf
Original file line number Diff line number Diff line change
Expand Up @@ -82,7 +82,7 @@ resource "google_project_iam_member" "cluster_service_account_artifact_registry"
}

resource "google_project_iam_member" "cluster_service_account_service_usage_consumer" {
for_each = var.create_service_account && var.enable_gcfs ? toset(local.registry_projects_list) : []
for_each = var.create_service_account && var.grant_registry_access && var.enable_gcfs ? toset(local.registry_projects_list) : []
project = each.key
role = "roles/serviceusage.serviceUsageConsumer"
member = "serviceAccount:${google_service_account.cluster_service_account[0].email}"
Expand Down
2 changes: 1 addition & 1 deletion modules/private-cluster/sa.tf
Original file line number Diff line number Diff line change
Expand Up @@ -82,7 +82,7 @@ resource "google_project_iam_member" "cluster_service_account_artifact_registry"
}

resource "google_project_iam_member" "cluster_service_account_service_usage_consumer" {
for_each = var.create_service_account && var.enable_gcfs ? toset(local.registry_projects_list) : []
for_each = var.create_service_account && var.grant_registry_access && var.enable_gcfs ? toset(local.registry_projects_list) : []
project = each.key
role = "roles/serviceusage.serviceUsageConsumer"
member = "serviceAccount:${google_service_account.cluster_service_account[0].email}"
Expand Down
2 changes: 1 addition & 1 deletion sa.tf
Original file line number Diff line number Diff line change
Expand Up @@ -82,7 +82,7 @@ resource "google_project_iam_member" "cluster_service_account_artifact_registry"
}

resource "google_project_iam_member" "cluster_service_account_service_usage_consumer" {
for_each = var.create_service_account && var.enable_gcfs ? toset(local.registry_projects_list) : []
for_each = var.create_service_account && var.grant_registry_access && var.enable_gcfs ? toset(local.registry_projects_list) : []
project = each.key
role = "roles/serviceusage.serviceUsageConsumer"
member = "serviceAccount:${google_service_account.cluster_service_account[0].email}"
Expand Down

0 comments on commit 69eca65

Please sign in to comment.