Skip to content

Commit e287d35

Browse files
authored
Merge pull request #33 from charlieegan3/remove-extra-iam-member
Remove surplus iam member
2 parents 04ee721 + ddd3ea6 commit e287d35

File tree

2 files changed

+5
-4
lines changed

2 files changed

+5
-4
lines changed

deployment/terraform/gke-datagatherer/googlecloud-scanner-serviceaccount.tf

Lines changed: 4 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -18,7 +18,7 @@ provider "google" {
1818
resource "google_service_account" "preflight_scanner_service_account" {
1919
account_id = "preflight-scanner"
2020
display_name = "Service account for getting cluster information with workload identity"
21-
project = var.scanner_gcp_project_id
21+
project = var.scanner_gcp_project_id
2222
}
2323

2424
resource "google_project_iam_member" "preflight_scanner_cluster_viewer" {
@@ -30,6 +30,7 @@ resource "google_project_iam_member" "preflight_scanner_cluster_viewer" {
3030
resource "google_project_iam_binding" "preflight_scanner_workload_identity" {
3131
project = var.scanner_gcp_project_id
3232
role = "roles/iam.workloadIdentityUser"
33-
members = ["serviceAccount:${var.scanner_gcp_project_id}.svc.id.goog[preflight-scanner/preflight-scanner]",
34-
"serviceAccount:${google_service_account.preflight_scanner_service_account.email}"]
33+
members = [
34+
"serviceAccount:${var.scanner_gcp_project_id}.svc.id.goog[preflight-scanner/preflight-scanner]",
35+
]
3536
}

deployment/terraform/results-bucket/googlecloud-reports-bucket-scanner-sa.tf

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -20,5 +20,5 @@ resource "google_service_account_key" "preflight-scanner-reports-writter-key" {
2020

2121
resource "local_file" "preflight-scanner-reports-writter-key-file" {
2222
sensitive_content = base64decode(google_service_account_key.preflight-scanner-reports-writter-key.private_key)
23-
filename = "${path.module}/../../kubernetes/overlays/scanner/secrets/credentials.json"
23+
filename = "${path.module}/../../kubernetes/overlays/scanner/secrets/credentials.json"
2424
}

0 commit comments

Comments
 (0)