Skip to content

Commit 5a417fe

Browse files
authored
Merge pull request #7273 from ameukam/allow-gcb-sa-kubernetes-release-test
gcp: Allow GCB service agent for kubernetes-release-test
2 parents bd07c21 + f869fc9 commit 5a417fe

File tree

1 file changed

+8
-0
lines changed
  • infra/gcp/terraform/k8s-infra-releases-prod

1 file changed

+8
-0
lines changed

infra/gcp/terraform/k8s-infra-releases-prod/main.tf

Lines changed: 8 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -49,6 +49,14 @@ resource "google_storage_hmac_key" "fastly_reader_key" {
4949
service_account_email = google_service_account.fastly_reader.email
5050
}
5151

52+
// TODO: remove this after https://github.com/kubernetes/release/issues/3425
53+
resource "google_storage_bucket_iam_member" "release_object_admin" {
54+
bucket = module.k8s_releases_prod.bucket_name
55+
role = "roles/storage.objectAdmin"
56+
member = "serviceAccount:[email protected]"
57+
depends_on = [module.k8s_releases_prod]
58+
}
59+
5260
resource "google_storage_bucket_iam_member" "fastly_reader" {
5361
bucket = module.k8s_releases_prod.bucket_name
5462
role = "roles/storage.objectViewer"

0 commit comments

Comments
 (0)