File tree 10 files changed +10
-10
lines changed
beta-autopilot-private-cluster
beta-autopilot-public-cluster
beta-private-cluster-update-variant
beta-public-cluster-update-variant
private-cluster-update-variant
10 files changed +10
-10
lines changed Original file line number Diff line number Diff line change @@ -82,7 +82,7 @@ resource "google_project_iam_member" "cluster_service_account_artifact_registry"
82
82
}
83
83
84
84
resource "google_project_iam_member" "cluster_service_account_service_usage_consumer" {
85
- for_each = var.create_service_account {% if autopilot_cluster != true %}&& var.enable_gcfs {% endif %}? toset(local.registry_projects_list) : []
85
+ for_each = var.create_service_account && var.grant_registry_access {% if autopilot_cluster != true %}&& var.enable_gcfs {% endif %}? toset(local.registry_projects_list) : []
86
86
project = each.key
87
87
role = "roles/serviceusage.serviceUsageConsumer"
88
88
member = "serviceAccount:${google_service_account.cluster_service_account[0].email}"
Original file line number Diff line number Diff line change @@ -82,7 +82,7 @@ resource "google_project_iam_member" "cluster_service_account_artifact_registry"
82
82
}
83
83
84
84
resource "google_project_iam_member" "cluster_service_account_service_usage_consumer" {
85
- for_each = var. create_service_account ? toset (local. registry_projects_list ) : []
85
+ for_each = var. create_service_account && var . grant_registry_access ? toset (local. registry_projects_list ) : []
86
86
project = each. key
87
87
role = " roles/serviceusage.serviceUsageConsumer"
88
88
member = " serviceAccount:${ google_service_account . cluster_service_account [0 ]. email } "
Original file line number Diff line number Diff line change @@ -82,7 +82,7 @@ resource "google_project_iam_member" "cluster_service_account_artifact_registry"
82
82
}
83
83
84
84
resource "google_project_iam_member" "cluster_service_account_service_usage_consumer" {
85
- for_each = var. create_service_account ? toset (local. registry_projects_list ) : []
85
+ for_each = var. create_service_account && var . grant_registry_access ? toset (local. registry_projects_list ) : []
86
86
project = each. key
87
87
role = " roles/serviceusage.serviceUsageConsumer"
88
88
member = " serviceAccount:${ google_service_account . cluster_service_account [0 ]. email } "
Original file line number Diff line number Diff line change @@ -82,7 +82,7 @@ resource "google_project_iam_member" "cluster_service_account_artifact_registry"
82
82
}
83
83
84
84
resource "google_project_iam_member" "cluster_service_account_service_usage_consumer" {
85
- for_each = var. create_service_account && var. enable_gcfs ? toset (local. registry_projects_list ) : []
85
+ for_each = var. create_service_account && var. grant_registry_access && var . enable_gcfs ? toset (local. registry_projects_list ) : []
86
86
project = each. key
87
87
role = " roles/serviceusage.serviceUsageConsumer"
88
88
member = " serviceAccount:${ google_service_account . cluster_service_account [0 ]. email } "
Original file line number Diff line number Diff line change @@ -82,7 +82,7 @@ resource "google_project_iam_member" "cluster_service_account_artifact_registry"
82
82
}
83
83
84
84
resource "google_project_iam_member" "cluster_service_account_service_usage_consumer" {
85
- for_each = var. create_service_account && var. enable_gcfs ? toset (local. registry_projects_list ) : []
85
+ for_each = var. create_service_account && var. grant_registry_access && var . enable_gcfs ? toset (local. registry_projects_list ) : []
86
86
project = each. key
87
87
role = " roles/serviceusage.serviceUsageConsumer"
88
88
member = " serviceAccount:${ google_service_account . cluster_service_account [0 ]. email } "
Original file line number Diff line number Diff line change @@ -82,7 +82,7 @@ resource "google_project_iam_member" "cluster_service_account_artifact_registry"
82
82
}
83
83
84
84
resource "google_project_iam_member" "cluster_service_account_service_usage_consumer" {
85
- for_each = var. create_service_account && var. enable_gcfs ? toset (local. registry_projects_list ) : []
85
+ for_each = var. create_service_account && var. grant_registry_access && var . enable_gcfs ? toset (local. registry_projects_list ) : []
86
86
project = each. key
87
87
role = " roles/serviceusage.serviceUsageConsumer"
88
88
member = " serviceAccount:${ google_service_account . cluster_service_account [0 ]. email } "
Original file line number Diff line number Diff line change @@ -82,7 +82,7 @@ resource "google_project_iam_member" "cluster_service_account_artifact_registry"
82
82
}
83
83
84
84
resource "google_project_iam_member" "cluster_service_account_service_usage_consumer" {
85
- for_each = var. create_service_account && var. enable_gcfs ? toset (local. registry_projects_list ) : []
85
+ for_each = var. create_service_account && var. grant_registry_access && var . enable_gcfs ? toset (local. registry_projects_list ) : []
86
86
project = each. key
87
87
role = " roles/serviceusage.serviceUsageConsumer"
88
88
member = " serviceAccount:${ google_service_account . cluster_service_account [0 ]. email } "
Original file line number Diff line number Diff line change @@ -82,7 +82,7 @@ resource "google_project_iam_member" "cluster_service_account_artifact_registry"
82
82
}
83
83
84
84
resource "google_project_iam_member" "cluster_service_account_service_usage_consumer" {
85
- for_each = var. create_service_account && var. enable_gcfs ? toset (local. registry_projects_list ) : []
85
+ for_each = var. create_service_account && var. grant_registry_access && var . enable_gcfs ? toset (local. registry_projects_list ) : []
86
86
project = each. key
87
87
role = " roles/serviceusage.serviceUsageConsumer"
88
88
member = " serviceAccount:${ google_service_account . cluster_service_account [0 ]. email } "
Original file line number Diff line number Diff line change @@ -82,7 +82,7 @@ resource "google_project_iam_member" "cluster_service_account_artifact_registry"
82
82
}
83
83
84
84
resource "google_project_iam_member" "cluster_service_account_service_usage_consumer" {
85
- for_each = var. create_service_account && var. enable_gcfs ? toset (local. registry_projects_list ) : []
85
+ for_each = var. create_service_account && var. grant_registry_access && var . enable_gcfs ? toset (local. registry_projects_list ) : []
86
86
project = each. key
87
87
role = " roles/serviceusage.serviceUsageConsumer"
88
88
member = " serviceAccount:${ google_service_account . cluster_service_account [0 ]. email } "
Original file line number Diff line number Diff line change @@ -82,7 +82,7 @@ resource "google_project_iam_member" "cluster_service_account_artifact_registry"
82
82
}
83
83
84
84
resource "google_project_iam_member" "cluster_service_account_service_usage_consumer" {
85
- for_each = var. create_service_account && var. enable_gcfs ? toset (local. registry_projects_list ) : []
85
+ for_each = var. create_service_account && var. grant_registry_access && var . enable_gcfs ? toset (local. registry_projects_list ) : []
86
86
project = each. key
87
87
role = " roles/serviceusage.serviceUsageConsumer"
88
88
member = " serviceAccount:${ google_service_account . cluster_service_account [0 ]. email } "
You can’t perform that action at this time.
0 commit comments