@@ -14,18 +14,18 @@ data "google_organization" "org" {
1414# ---------------------------------
1515# role permissions for onboarding
1616# ---------------------------------
17- resource "google_organization_iam_member" "onboarding_role " {
17+ resource "google_organization_iam_member" "browser " {
1818 count = var. is_organizational ? 1 : 0
1919
2020 org_id = data. google_organization . org [0 ]. org_id
2121 role = " roles/browser"
2222 member = " serviceAccount:${ google_service_account . sa . email } "
2323}
2424
25- # --------------------------------------------------------------------------------------
26- # role permissions for CSPM (GCP Predefined Roles for Sysdig Cloud Trust Relationship )
27- # --------------------------------------------------------------------------------------
28- resource "google_organization_iam_member" "trust_relationship_role " {
25+ # ---------------------------------------------------------------------------------------------
26+ # role permissions for CSPM (GCP Predefined Roles for Sysdig Cloud Secure Posture Management )
27+ # ---------------------------------------------------------------------------------------------
28+ resource "google_organization_iam_member" "cloudasset_viewer " {
2929 for_each = var. is_organizational ? toset ([" roles/cloudasset.viewer" ]) : []
3030
3131 org_id = data. google_organization . org [0 ]. org_id
@@ -36,7 +36,7 @@ resource "google_organization_iam_member" "trust_relationship_role" {
3636# ---------------------------------------------------------------------------------------
3737# role permissions for CIEM (GCP Predefined Roles for Sysdig Cloud Identity Management)
3838# ---------------------------------------------------------------------------------------
39- resource "google_organization_iam_member" "identity_mgmt_role " {
39+ resource "google_organization_iam_member" "identity_mgmt " {
4040 for_each = var. is_organizational ? toset ([" roles/recommender.viewer" , " roles/iam.serviceAccountViewer" , " roles/iam.organizationRoleViewer" ]) : []
4141
4242 org_id = data. google_organization . org [0 ]. org_id
0 commit comments