Skip to content

Commit

Permalink
fix: Allow support admin access to cluster
Browse files Browse the repository at this point in the history
  • Loading branch information
gtoonstra committed Mar 20, 2024
1 parent 9159a9e commit 253a962
Showing 1 changed file with 3 additions and 6 deletions.
9 changes: 3 additions & 6 deletions iam.tf
Original file line number Diff line number Diff line change
Expand Up @@ -4,11 +4,8 @@

locals {
viewer_role = var.restricted_viewer_role ? "roles/viewer" : "roles/compute.viewer"
project_roles = var.restricted_roles ? [
"${var.project_id}=>roles/secretmanager.secretAccessor"
] : [
project_roles = var.restricted_roles ? [] : [
"${var.project_id}=>${local.viewer_role}",
"${var.project_id}=>roles/secretmanager.secretAccessor"
]
}

Expand All @@ -32,10 +29,10 @@ module "project-iam-bindings" {
"roles/iap.tunnelResourceAccessor" = [
"group:datafold-onprem-support@datafold.com"
]
"roles/secretmanager.secretAccessor" = [
"roles/container.admin" = [
"group:datafold-onprem-support@datafold.com"
]
"roles/iam.serviceAccountUser" = [
"roles/container.clusterAdmin" = [
"group:datafold-onprem-support@datafold.com"
]
}
Expand Down

0 comments on commit 253a962

Please sign in to comment.