Skip to content

Commit 7310051

Browse files
tjespersimrannayer
andauthored
fix!: Cleanup of old instance backups. Change role roles/cloudsql.editor to roles/cloudsql.admin (#618)
Co-authored-by: Imran Nayer <[email protected]>
1 parent 8780714 commit 7310051

File tree

1 file changed

+1
-1
lines changed

1 file changed

+1
-1
lines changed

modules/backup/main.tf

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -19,7 +19,7 @@ locals {
1919
create_service_account = var.service_account == null || var.service_account == "" ? true : false
2020
service_account = local.create_service_account ? google_service_account.sql_backup_serviceaccount[0].email : var.service_account
2121
backup_name = "sql-backup-${var.sql_instance}${var.unique_suffix}"
22-
role_name = var.enable_export_backup ? "roles/cloudsql.editor" : "roles/cloudsql.viewer"
22+
role_name = var.enable_export_backup ? "roles/cloudsql.admin" : "roles/cloudsql.viewer"
2323
export_name = var.use_sql_instance_replica_in_exporter ? "sql-export-${var.sql_instance_replica}${var.unique_suffix}" : "sql-export-${var.sql_instance}${var.unique_suffix}"
2424
notification_channels = var.create_notification_channel ? concat(var.notification_channels, [google_monitoring_notification_channel.email[0].id]) : var.notification_channels
2525
}

0 commit comments

Comments
 (0)