|
13 | 13 | # limitations under the License. |
14 | 14 |
|
15 | 15 | locals { |
16 | | - # go/keep-sorted start |
17 | | - abfs_iam_roles = [ |
18 | | - "roles/artifactregistry.reader", |
19 | | - "roles/logging.logWriter", |
20 | | - "roles/monitoring.metricWriter", |
21 | | - "roles/monitoring.viewer", |
22 | | - "roles/spanner.databaseUser", |
23 | | - "roles/stackdriver.resourceMetadata.writer", |
24 | | - "roles/storage.objectAdmin", |
25 | | - ] |
26 | | - abfs_service_account_email = local.create_service_account ? google_service_account.abfs[0].email : data.google_service_account.abfs[0].email |
27 | | - abfs_service_account_unique_id = local.create_service_account ? google_service_account.abfs[0].unique_id : data.google_service_account.abfs[0].unique_id |
28 | | - create_service_account = var.abfs_service_account_id == "" |
29 | | - # go/keep-sorted end |
| 16 | + create_server_service_account = var.server_service_account_id == "" |
| 17 | + server_service_account = local.create_server_service_account ? google_service_account.server[0] : data.google_service_account.server[0] |
| 18 | + |
| 19 | + create_uploader_service_account = var.uploader_service_account_id == "" |
| 20 | + uploader_service_account = local.create_uploader_service_account ? google_service_account.uploader[0] : data.google_service_account.uploader[0] |
| 21 | + |
| 22 | + create_client_service_account = var.client_service_account_id == "" |
| 23 | + client_service_account = var.create_client_instance_resource ? (local.create_client_service_account ? google_service_account.client[0] : data.google_service_account.client[0]) : null |
| 24 | +} |
| 25 | + |
| 26 | +# Service Account - Server |
| 27 | + |
| 28 | +moved { |
| 29 | + from = google_service_account.abfs[0] |
| 30 | + to = google_service_account.server[0] |
| 31 | +} |
| 32 | + |
| 33 | +data "google_service_account" "server" { |
| 34 | + count = local.create_server_service_account ? 0 : 1 |
| 35 | + |
| 36 | + project = data.google_project.project.project_id |
| 37 | + account_id = var.server_service_account_id |
| 38 | +} |
| 39 | + |
| 40 | +resource "google_service_account" "server" { |
| 41 | + count = local.create_server_service_account ? 1 : 0 |
| 42 | + |
| 43 | + project = data.google_project.project.project_id |
| 44 | + account_id = var.server_service_account_name |
| 45 | + display_name = "Service Account for ABFS Server" |
| 46 | + |
| 47 | + lifecycle { |
| 48 | + # Prevent the service account that may have been granted an ABFS license from being deleted. |
| 49 | + prevent_destroy = true |
| 50 | + } |
| 51 | +} |
| 52 | + |
| 53 | +# Service Account - Uploader |
| 54 | + |
| 55 | +data "google_service_account" "uploader" { |
| 56 | + count = local.create_uploader_service_account ? 0 : 1 |
| 57 | + |
| 58 | + project = data.google_project.project.project_id |
| 59 | + account_id = var.uploader_service_account_id |
| 60 | +} |
| 61 | + |
| 62 | +resource "google_service_account" "uploader" { |
| 63 | + count = local.create_uploader_service_account ? 1 : 0 |
| 64 | + |
| 65 | + project = data.google_project.project.project_id |
| 66 | + account_id = var.uploader_service_account_name |
| 67 | + display_name = "Service Account for ABFS Uploader" |
| 68 | + |
| 69 | + lifecycle { |
| 70 | + # Prevent the service account that may have been granted an ABFS license from being deleted. |
| 71 | + prevent_destroy = true |
| 72 | + } |
30 | 73 | } |
31 | 74 |
|
32 | | -data "google_service_account" "abfs" { |
33 | | - count = local.create_service_account ? 0 : 1 |
| 75 | +# Service Account - Client |
| 76 | + |
| 77 | +data "google_service_account" "client" { |
| 78 | + count = var.create_client_instance_resource && ! local.create_client_service_account ? 1 : 0 |
34 | 79 |
|
35 | 80 | project = data.google_project.project.project_id |
36 | | - account_id = var.abfs_service_account_id |
| 81 | + account_id = var.client_service_account_id |
37 | 82 | } |
38 | 83 |
|
39 | | -resource "google_service_account" "abfs" { |
40 | | - count = local.create_service_account ? 1 : 0 |
| 84 | +resource "google_service_account" "client" { |
| 85 | + count = var.create_client_instance_resource && local.create_client_service_account ? 1 : 0 |
41 | 86 |
|
42 | 87 | project = data.google_project.project.project_id |
43 | | - account_id = var.abfs_service_account_name |
44 | | - display_name = "Service Account for ABFS" |
| 88 | + account_id = var.client_service_account_name |
| 89 | + display_name = "Service Account for ABFS Client" |
45 | 90 |
|
46 | 91 | lifecycle { |
47 | 92 | # Prevent the service account that may have been granted an ABFS license from being deleted. |
48 | 93 | prevent_destroy = true |
49 | 94 | } |
50 | 95 | } |
51 | 96 |
|
52 | | -resource "google_project_iam_member" "abfs_iam" { |
53 | | - for_each = toset(local.abfs_iam_roles) |
| 97 | +module "project-iam-bindings" { |
| 98 | + source = "terraform-google-modules/iam/google//modules/projects_iam" |
| 99 | + version = "8.1.0" |
54 | 100 |
|
55 | | - project = data.google_project.project.project_id |
56 | | - role = each.value |
57 | | - member = "serviceAccount:${local.abfs_service_account_email}" |
| 101 | + projects = [data.google_project.project.project_id] |
| 102 | + mode = "authoritative" |
| 103 | + |
| 104 | + bindings = { |
| 105 | + "roles/logging.logWriter" = [local.server_service_account.member, local.uploader_service_account.member], |
| 106 | + "roles/monitoring.metricWriter" = [local.server_service_account.member, local.uploader_service_account.member], |
| 107 | + "roles/monitoring.viewer" = [local.server_service_account.member, local.uploader_service_account.member], |
| 108 | + "roles/spanner.databaseUser" = [local.server_service_account.member], |
| 109 | + "roles/stackdriver.resourceMetadata.writer" = [local.server_service_account.member, local.uploader_service_account.member], |
| 110 | + "roles/storage.objectAdmin" = [local.server_service_account.member], |
| 111 | + } |
58 | 112 |
|
59 | 113 | depends_on = [ |
60 | 114 | module.project-services, |
61 | | - data.google_service_account.abfs, |
62 | | - google_service_account.abfs |
| 115 | + local.server_service_account, |
| 116 | + local.uploader_service_account, |
| 117 | + local.client_service_account, |
63 | 118 | ] |
64 | 119 | } |
0 commit comments