Skip to content

Commit 77d5c8a

Browse files
Implement IapSettings resource. (#12183) (#835)
[upstream:d8e9428040dcbf5e36a4fc53dfee9e2f792f20f8] Signed-off-by: Modular Magician <[email protected]>
1 parent f4dbc33 commit 77d5c8a

File tree

4 files changed

+169
-0
lines changed

4 files changed

+169
-0
lines changed

iap_settings_basic/backing_file.tf

Lines changed: 15 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,15 @@
1+
# This file has some scaffolding to make sure that names are unique and that
2+
# a region and zone are selected when you try to create your Terraform resources.
3+
4+
locals {
5+
name_suffix = "${random_pet.suffix.id}"
6+
}
7+
8+
resource "random_pet" "suffix" {
9+
length = 2
10+
}
11+
12+
provider "google" {
13+
region = "us-central1"
14+
zone = "us-central1-c"
15+
}

iap_settings_basic/main.tf

Lines changed: 68 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,68 @@
1+
data "google_project" "project" {
2+
}
3+
4+
resource "google_compute_region_backend_service" "default" {
5+
name = "iap-settings-tf-${local.name_suffix}"
6+
region = "us-central1"
7+
health_checks = [google_compute_health_check.default.id]
8+
connection_draining_timeout_sec = 10
9+
session_affinity = "CLIENT_IP"
10+
}
11+
12+
resource "google_compute_health_check" "default" {
13+
name = "iap-bs-health-check-${local.name_suffix}"
14+
check_interval_sec = 1
15+
timeout_sec = 1
16+
17+
tcp_health_check {
18+
port = "80"
19+
}
20+
}
21+
22+
resource "google_iap_settings" "iap_settings" {
23+
name = "projects/${data.google_project.project.number}/iap_web/compute-us-central1/services/${google_compute_region_backend_service.default.name}"
24+
access_settings {
25+
identity_sources = ["WORKFORCE_IDENTITY_FEDERATION"]
26+
allowed_domains_settings {
27+
domains = ["test.abc.com"]
28+
enable = true
29+
}
30+
cors_settings {
31+
allow_http_options = true
32+
}
33+
reauth_settings {
34+
method = "SECURE_KEY"
35+
max_age = "305s"
36+
policy_type = "MINIMUM"
37+
}
38+
gcip_settings {
39+
login_page_uri = "https://test.com/?apiKey=abc"
40+
}
41+
oauth_settings {
42+
login_hint = "test"
43+
}
44+
workforce_identity_settings {
45+
workforce_pools = ["wif-pool"]
46+
oauth2 {
47+
client_id = "test-client-id"
48+
client_secret = "test-client-secret"
49+
}
50+
}
51+
}
52+
application_settings {
53+
cookie_domain = "test.abc.com"
54+
csm_settings {
55+
rctoken_aud = "test-aud-set"
56+
}
57+
access_denied_page_settings {
58+
access_denied_page_uri = "test-uri"
59+
generate_troubleshooting_uri = true
60+
remediation_token_generation_enabled = false
61+
}
62+
attribute_propagation_settings {
63+
output_credentials = ["HEADER"]
64+
expression = "attributes.saml_attributes.filter(attribute, attribute.name in [\"test1\", \"test2\"])"
65+
enable = false
66+
}
67+
}
68+
}

iap_settings_basic/motd

Lines changed: 7 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,7 @@
1+
===
2+
3+
These examples use real resources that will be billed to the
4+
Google Cloud Platform project you use - so make sure that you
5+
run "terraform destroy" before quitting!
6+
7+
===

iap_settings_basic/tutorial.md

Lines changed: 79 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,79 @@
1+
# Iap Settings Basic - Terraform
2+
3+
## Setup
4+
5+
<walkthrough-author name="[email protected]" analyticsId="UA-125550242-1" tutorialName="iap_settings_basic" repositoryUrl="https://github.com/terraform-google-modules/docs-examples"></walkthrough-author>
6+
7+
Welcome to Terraform in Google Cloud Shell! We need you to let us know what project you'd like to use with Terraform.
8+
9+
<walkthrough-project-billing-setup></walkthrough-project-billing-setup>
10+
11+
Terraform provisions real GCP resources, so anything you create in this session will be billed against this project.
12+
13+
## Terraforming!
14+
15+
Let's use {{project-id}} with Terraform! Click the Cloud Shell icon below to copy the command
16+
to your shell, and then run it from the shell by pressing Enter/Return. Terraform will pick up
17+
the project name from the environment variable.
18+
19+
```bash
20+
export GOOGLE_CLOUD_PROJECT={{project-id}}
21+
```
22+
23+
After that, let's get Terraform started. Run the following to pull in the providers.
24+
25+
```bash
26+
terraform init
27+
```
28+
29+
With the providers downloaded and a project set, you're ready to use Terraform. Go ahead!
30+
31+
```bash
32+
terraform apply
33+
```
34+
35+
Terraform will show you what it plans to do, and prompt you to accept. Type "yes" to accept the plan.
36+
37+
```bash
38+
yes
39+
```
40+
41+
42+
## Post-Apply
43+
44+
### Editing your config
45+
46+
Now you've provisioned your resources in GCP! If you run a "plan", you should see no changes needed.
47+
48+
```bash
49+
terraform plan
50+
```
51+
52+
So let's make a change! Try editing a number, or appending a value to the name in the editor. Then,
53+
run a 'plan' again.
54+
55+
```bash
56+
terraform plan
57+
```
58+
59+
Afterwards you can run an apply, which implicitly does a plan and shows you the intended changes
60+
at the 'yes' prompt.
61+
62+
```bash
63+
terraform apply
64+
```
65+
66+
```bash
67+
yes
68+
```
69+
70+
## Cleanup
71+
72+
Run the following to remove the resources Terraform provisioned:
73+
74+
```bash
75+
terraform destroy
76+
```
77+
```bash
78+
yes
79+
```

0 commit comments

Comments
 (0)