Skip to content

Commit e42d390

Browse files
committed
rm ciem roles from pub sub integrations
1 parent 1770cda commit e42d390

File tree

1 file changed

+0
-9
lines changed

1 file changed

+0
-9
lines changed

modules/integrations/pub-sub/organizational.tf

Lines changed: 0 additions & 9 deletions
Original file line numberDiff line numberDiff line change
@@ -83,13 +83,4 @@ resource "google_organization_iam_member" "custom" {
8383
org_id = data.google_organization.org[0].org_id
8484
role = google_organization_iam_custom_role.custom_ingestion_auth_role[0].id
8585
member = "serviceAccount:${google_service_account.push_auth.email}"
86-
}
87-
88-
# adding ciem role with permissions to the service account for org
89-
resource "google_organization_iam_member" "identity_mgmt" {
90-
for_each = var.is_organizational ? toset(["roles/recommender.viewer", "roles/iam.serviceAccountViewer", "roles/iam.organizationRoleViewer", "roles/container.clusterViewer", "roles/compute.viewer"]) : []
91-
92-
org_id = data.google_organization.org[0].org_id
93-
role = each.key
94-
member = "serviceAccount:${google_service_account.push_auth.email}"
9586
}

0 commit comments

Comments
 (0)