File tree Expand file tree Collapse file tree 1 file changed +9
-2
lines changed
data_fusion_instance_cmek Expand file tree Collapse file tree 1 file changed +9
-2
lines changed Original file line number Diff line number Diff line change @@ -7,7 +7,7 @@ resource "google_data_fusion_instance" "cmek" {
77 key_reference = google_kms_crypto_key. crypto_key . id
88 }
99
10- depends_on = [google_kms_crypto_key_iam_member . crypto_key_member ]
10+ depends_on = [google_kms_crypto_key_iam_member . crypto_key_member_cdf_sa , google_kms_crypto_key_iam_member . crypto_key_member_gcs_sa ]
1111}
1212
1313resource "google_kms_crypto_key" "crypto_key" {
@@ -20,11 +20,18 @@ resource "google_kms_key_ring" "key_ring" {
2020 location = " us-central1"
2121}
2222
23- resource "google_kms_crypto_key_iam_member" "crypto_key_member " {
23+ resource "google_kms_crypto_key_iam_member" "crypto_key_member_cdf_sa " {
2424 crypto_key_id = google_kms_crypto_key. crypto_key . id
2525 role = " roles/cloudkms.cryptoKeyEncrypterDecrypter"
2626
2727 member = " serviceAccount:service-${ data . google_project . project . number } @gcp-sa-datafusion.iam.gserviceaccount.com"
2828}
2929
30+ resource "google_kms_crypto_key_iam_member" "crypto_key_member_gcs_sa" {
31+ crypto_key_id = google_kms_crypto_key. crypto_key . id
32+ role = " roles/cloudkms.cryptoKeyEncrypterDecrypter"
33+
34+ member = " serviceAccount:service-${ data . google_project . project . number } @gs-project-accounts.iam.gserviceaccount.com"
35+ }
36+
3037data "google_project" "project" {}
You can’t perform that action at this time.
0 commit comments