Skip to content

Commit b908119

Browse files
authored
Merge pull request #21 from paulpalamarchuk/rework_sa_roles_for_cleanup
Reworked SA roles for old-projects cleanup.
2 parents 4c6c87c + 1bb18ba commit b908119

File tree

1 file changed

+11
-4
lines changed

1 file changed

+11
-4
lines changed

modules/project_cleanup/main.tf

Lines changed: 11 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -24,10 +24,17 @@ resource "google_service_account" "project_cleaner_function" {
2424
display_name = "Project Cleaner Function"
2525
}
2626

27-
resource "google_organization_iam_member" "project_owner" {
28-
org_id = var.organization_id
29-
role = "roles/owner"
30-
member = "serviceAccount:${google_service_account.project_cleaner_function.email}"
27+
module "sa-organization-roles" {
28+
source = "terraform-google-modules/iam/google//modules/organizations_iam"
29+
version = "4.0.0"
30+
organizations = [var.organization_id]
31+
mode = "additive"
32+
33+
bindings = {
34+
"roles/resourcemanager.projectDeleter" = ["serviceAccount:${google_service_account.project_cleaner_function.email}"]
35+
"roles/resourcemanager.folderViewer" = ["serviceAccount:${google_service_account.project_cleaner_function.email}"]
36+
"roles/resourcemanager.lienModifier" = ["serviceAccount:${google_service_account.project_cleaner_function.email}"]
37+
}
3138
}
3239

3340
module "scheduled_project_cleaner" {

0 commit comments

Comments
 (0)