Skip to content

Commit 0821f24

Browse files
committed
chore: use less privileged roles for deploying bigquery module
1 parent ce105bb commit 0821f24

File tree

7 files changed

+4
-16
lines changed

7 files changed

+4
-16
lines changed

metadata.display.yaml

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -22,7 +22,7 @@ spec:
2222
info:
2323
title: terraform-google-bigquery
2424
source:
25-
repo: https://github.com/ayushmjain/terraform-google-bigquery
25+
repo: https://github.com/terraform-google-modules/terraform-google-bigquery
2626
sourceType: git
2727
ui:
2828
input:

metadata.yaml

Lines changed: 2 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -22,9 +22,9 @@ spec:
2222
info:
2323
title: terraform-google-bigquery
2424
source:
25-
repo: https://github.com/ayushmjain/terraform-google-bigquery
25+
repo: https://github.com/terraform-google-modules/terraform-google-bigquery
2626
sourceType: git
27-
version: 1.0.4
27+
version: 9.0.0
2828
actuationTool:
2929
flavor: Terraform
3030
version: ">= 1.3"
@@ -382,8 +382,6 @@ spec:
382382
- level: Project
383383
roles:
384384
- roles/bigquery.admin
385-
- roles/cloudkms.cryptoKeyEncrypterDecrypter
386-
- roles/owner
387385
services:
388386
- cloudkms.googleapis.com
389387
- cloudresourcemanager.googleapis.com

modules/authorization/metadata.yaml

Lines changed: 0 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -94,8 +94,6 @@ spec:
9494
- level: Project
9595
roles:
9696
- roles/bigquery.admin
97-
- roles/cloudkms.cryptoKeyEncrypterDecrypter
98-
- roles/owner
9997
services:
10098
- cloudkms.googleapis.com
10199
- cloudresourcemanager.googleapis.com

modules/data_warehouse/metadata.yaml

Lines changed: 0 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -136,8 +136,6 @@ spec:
136136
- level: Project
137137
roles:
138138
- roles/bigquery.admin
139-
- roles/cloudkms.cryptoKeyEncrypterDecrypter
140-
- roles/owner
141139
services:
142140
- cloudkms.googleapis.com
143141
- cloudresourcemanager.googleapis.com

modules/scheduled_queries/metadata.yaml

Lines changed: 0 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -60,8 +60,6 @@ spec:
6060
- level: Project
6161
roles:
6262
- roles/bigquery.admin
63-
- roles/cloudkms.cryptoKeyEncrypterDecrypter
64-
- roles/owner
6563
services:
6664
- cloudkms.googleapis.com
6765
- cloudresourcemanager.googleapis.com

modules/udf/metadata.yaml

Lines changed: 0 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -64,8 +64,6 @@ spec:
6464
- level: Project
6565
roles:
6666
- roles/bigquery.admin
67-
- roles/cloudkms.cryptoKeyEncrypterDecrypter
68-
- roles/owner
6967
services:
7068
- cloudkms.googleapis.com
7169
- cloudresourcemanager.googleapis.com

test/setup/iam.tf

Lines changed: 1 addition & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -16,9 +16,7 @@
1616

1717
locals {
1818
int_required_roles = [
19-
"roles/bigquery.admin",
20-
"roles/cloudkms.cryptoKeyEncrypterDecrypter",
21-
"roles/owner" // TODO: Descope
19+
"roles/bigquery.admin"
2220
]
2321
}
2422

0 commit comments

Comments
 (0)