Skip to content

Commit 4f5c7fe

Browse files
authored
fix(google_permissions): Use developer workgroups for default admin entitlement (#333)
There are some tenants that do not use a workgroup named the same as the tenant. These tenants use .globals.extra_attributes.workgroup to specify the workgroup with permissions to operate the service. This module assumed that the workgroup would always match the tenant.
1 parent 191f21e commit 4f5c7fe

File tree

1 file changed

+1
-1
lines changed

1 file changed

+1
-1
lines changed

google_permissions/pam_entitlement.tf

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -43,7 +43,7 @@ locals {
4343
# Create the map with the hard-coded value and append the distinct principals
4444
entitlement_wg_map = var.app_code != "" ? merge(
4545
{
46-
"default" : ["workgroup:${var.app_code}/developers"] # this the default value for the default system entitlement
46+
"default" : var.developer_ids # this the default value for the default system entitlement
4747
},
4848
{
4949
for name, add_entitlement in try(local.additional_entitlements, []) : add_entitlement.key => add_entitlement.entitlement.principals

0 commit comments

Comments
 (0)