This module creates a per-project custom IAM role carrying the union of the
permissions of roles/monitoring.metricWriter, roles/cloudtrace.agent, and
roles/cloudprofiler.agent.
The service modules (regional-go-service, regional-service, cron,
regional-go-cron, and their wrappers) grant those three built-in roles to
each service's service account at the project level, costing three entries in
the project IAM policy per service. GCP caps an IAM policy at 1,500 member
entries, so projects with hundreds of services approach the limit quickly.
Creating this role once per project and passing it to the service modules via
observability_role collapses the three entries into one.
// Once per project, in a stack that applies before the services.
module "observability-role" {
source = "chainguard-dev/common/infra//modules/observability-role"
project_id = var.project_id
}
module "foo-service" {
source = "chainguard-dev/common/infra//modules/regional-go-service"
project_id = var.project_id
name = "foo"
// One project IAM policy entry instead of three.
observability_role = module.observability-role.id
...
}Services in stacks that cannot reference the module instance directly can
construct the id by convention: projects/${var.project_id}/roles/serviceObservability.
Note: the id output is deliberately assembled from configuration attributes
(project, role_id) rather than the resource's computed id, so that it is
known at plan time — the service modules use observability_role in count
expressions, which cannot depend on values only known after apply. Don't
"simplify" it to the computed attribute.
No requirements.
| Name | Version |
|---|---|
| n/a |
No modules.
| Name | Type |
|---|---|
| google_project_iam_custom_role.this | resource |
| Name | Description | Type | Default | Required |
|---|---|---|---|---|
| project_id | The project in which to create the custom role. | string |
n/a | yes |
| role_id | The role_id of the custom role. | string |
"serviceObservability" |
no |
| title | Human-readable title of the custom role. | string |
"Service Observability" |
no |
| Name | Description |
|---|---|
| id | Fully-qualified role id (projects/{project}/roles/{role_id}), for use as the observability_role input of the service modules. |