Skip to content

Commit 57b619c

Browse files
policyViewer Role (#33)
1 parent 4dbba7e commit 57b619c

File tree

2 files changed

+2
-2
lines changed

2 files changed

+2
-2
lines changed

modules/services/service-principal/main.tf

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -23,7 +23,7 @@ resource "google_project_iam_member" "browser" {
2323
# role permissions for CSPM (GCP Predefined Roles for Sysdig Cloud Secure Posture Management)
2424
#---------------------------------------------------------------------------------------------
2525
resource "google_project_iam_member" "cspm" {
26-
for_each = var.is_organizational ? [] : toset(["roles/cloudasset.viewer", "roles/iam.serviceAccountTokenCreator", "roles/logging.viewer", "roles/cloudfunctions.viewer", "roles/cloudbuild.builds.viewer"])
26+
for_each = var.is_organizational ? [] : toset(["roles/cloudasset.viewer", "roles/iam.serviceAccountTokenCreator", "roles/logging.viewer", "roles/cloudfunctions.viewer", "roles/cloudbuild.builds.viewer", "roles/orgpolicy.policyViewer"])
2727

2828
project = var.project_id
2929
role = each.key

modules/services/service-principal/organizational.tf

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -26,7 +26,7 @@ resource "google_organization_iam_member" "browser" {
2626
# role permissions for CSPM (GCP Predefined Roles for Sysdig Cloud Secure Posture Management)
2727
#---------------------------------------------------------------------------------------------
2828
resource "google_organization_iam_member" "cspm" {
29-
for_each = var.is_organizational ? toset(["roles/cloudasset.viewer", "roles/iam.serviceAccountTokenCreator", "roles/logging.viewer", "roles/cloudfunctions.viewer", "roles/cloudbuild.builds.viewer"]) : []
29+
for_each = var.is_organizational ? toset(["roles/cloudasset.viewer", "roles/iam.serviceAccountTokenCreator", "roles/logging.viewer", "roles/cloudfunctions.viewer", "roles/cloudbuild.builds.viewer", "roles/orgpolicy.policyViewer"]) : []
3030

3131
org_id = data.google_organization.org[0].org_id
3232
role = each.key

0 commit comments

Comments
 (0)