2020-04-07 09:47:07 -07:00
/ * *
2023-02-21 03:24:40 -08:00
* Copyright 2023 Google LLC
2020-04-07 09:47:07 -07:00
*
* Licensed under the Apache License , Version 2 . 0 ( the " License " ) ;
* you may not use this file except in compliance with the License .
* You may obtain a copy of the License at
*
* http : //www.apache.org/licenses/LICENSE-2.0
*
* Unless required by applicable law or agreed to in writing , software
* distributed under the License is distributed on an " AS IS " BASIS ,
* WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND , either express or implied .
* See the License for the specific language governing permissions and
* limitations under the License .
* /
2021-10-08 09:26:04 -07:00
variable " contacts " {
2022-01-31 01:45:34 -08:00
description = " List of essential contacts for this resource. Must be in the form EMAIL -> [NOTIFICATION_TYPES]. Valid notification types are ALL, SUSPENSION, SECURITY, TECHNICAL, BILLING, LEGAL, PRODUCT_UPDATES. "
2021-10-08 09:26:04 -07:00
type = map ( list ( string ) )
default = { }
2022-01-29 01:08:17 -08:00
nullable = false
2021-10-08 09:26:04 -07:00
}
2020-04-07 09:47:07 -07:00
variable " custom_roles " {
description = " Map of role name => list of permissions to create in this project. "
type = map ( list ( string ) )
default = { }
2022-01-29 01:08:17 -08:00
nullable = false
2020-04-07 09:47:07 -07:00
}
2021-10-08 09:26:04 -07:00
variable " firewall_policies " {
2021-12-12 23:41:02 -08:00
description = " Hierarchical firewall policy rules created in the organization. "
2021-10-08 09:26:04 -07:00
type = map ( map ( object ( {
2021-12-12 23:41:02 -08:00
action = string
2021-10-08 09:26:04 -07:00
description = string
direction = string
2021-12-12 23:41:02 -08:00
logging = bool
ports = map ( list ( string ) )
2021-10-08 09:26:04 -07:00
priority = number
ranges = list ( string )
target_resources = list ( string )
2021-12-12 23:41:02 -08:00
target_service_accounts = list ( string )
# preview = bool
2021-10-08 09:26:04 -07:00
} ) ) )
default = { }
}
2021-12-31 03:36:14 -08:00
variable " firewall_policy_association " {
description = " The hierarchical firewall policy to associate to this folder. Must be either a key in the `firewall_policies` map or the id of a policy defined somewhere else. "
2021-12-12 23:41:02 -08:00
type = map ( string )
default = { }
2022-01-29 01:08:17 -08:00
nullable = false
2021-12-12 23:41:02 -08:00
}
variable " firewall_policy_factory " {
description = " Configuration for the firewall policy factory. "
type = object ( {
cidr_file = string
policy_name = string
rules_file = string
} )
default = null
2021-10-08 09:26:04 -07:00
}
2021-04-11 05:48:16 -07:00
variable " group_iam " {
description = " Authoritative IAM binding for organization groups, in {GROUP_EMAIL => [ROLES]} format. Group emails need to be static. Can be used in combination with the `iam` variable. "
type = map ( list ( string ) )
default = { }
2022-01-29 01:08:17 -08:00
nullable = false
2021-04-11 05:48:16 -07:00
}
2020-11-04 06:44:28 -08:00
variable " iam " {
description = " IAM bindings, in {ROLE => [MEMBERS]} format. "
2020-04-07 09:47:07 -07:00
type = map ( list ( string ) )
default = { }
2022-01-29 01:08:17 -08:00
nullable = false
2020-04-07 09:47:07 -07:00
}
2020-11-04 06:44:28 -08:00
variable " iam_additive " {
description = " Non authoritative IAM bindings, in {ROLE => [MEMBERS]} format. "
2020-04-07 09:47:07 -07:00
type = map ( list ( string ) )
2020-11-09 02:29:08 -08:00
default = { }
2022-01-29 01:08:17 -08:00
nullable = false
2020-11-09 02:29:08 -08:00
}
variable " iam_additive_members " {
description = " IAM additive bindings in {MEMBERS => [ROLE]} format. This might break if members are dynamic values. "
type = map ( list ( string ) )
2020-04-07 09:47:07 -07:00
default = { }
2022-01-29 01:08:17 -08:00
nullable = false
2020-04-07 09:47:07 -07:00
}
variable " iam_audit_config " {
description = " Service audit logging configuration. Service as key, map of log permission (eg DATA_READ) and excluded members as value for each service. "
type = map ( map ( list ( string ) ) )
default = { }
2022-01-29 01:08:17 -08:00
nullable = false
2020-04-07 09:47:07 -07:00
# default = {
# allServices = {
# DATA_READ = ["user:me@example.org"]
# }
# }
}
2020-12-09 14:58:17 -08:00
variable " iam_audit_config_authoritative " {
description = " IAM Authoritative service audit logging configuration. Service as key, map of log permission (eg DATA_READ) and excluded members as value for each service. Audit config should also be authoritative when using authoritative bindings. Use with caution. "
type = map ( map ( list ( string ) ) )
default = null
# default = {
# allServices = {
# DATA_READ = ["user:me@example.org"]
# }
# }
}
2021-04-11 05:48:16 -07:00
variable " iam_bindings_authoritative " {
description = " IAM authoritative bindings, in {ROLE => [MEMBERS]} format. Roles and members not explicitly listed will be cleared. Bindings should also be authoritative when using authoritative audit config. Use with caution. "
type = map ( list ( string ) )
default = null
}
2021-10-08 09:26:04 -07:00
variable " logging_exclusions " {
description = " Logging exclusions for this organization in the form {NAME -> FILTER}. "
type = map ( string )
default = { }
2022-01-29 01:08:17 -08:00
nullable = false
2021-10-08 09:26:04 -07:00
}
variable " logging_sinks " {
2022-11-11 10:05:39 -08:00
description = " Logging sinks to create for the organization. "
2021-10-08 09:26:04 -07:00
type = map ( object ( {
2022-11-12 02:30:34 -08:00
bq_partitioned_table = optional ( bool )
description = optional ( string )
2022-11-12 10:24:41 -08:00
destination = string
disabled = optional ( bool , false )
exclusions = optional ( map ( string ) , { } )
filter = string
include_children = optional ( bool , true )
type = string
2021-10-08 09:26:04 -07:00
} ) )
2022-11-11 10:05:39 -08:00
default = { }
nullable = false
2021-12-12 23:41:02 -08:00
validation {
condition = alltrue ( [
2022-11-11 10:05:39 -08:00
for k , v in var . logging_sinks :
2022-11-12 10:24:41 -08:00
contains ( [ " bigquery " , " logging " , " pubsub " , " storage " ] , v . type )
2021-12-12 23:41:02 -08:00
] )
2022-11-12 10:24:41 -08:00
error_message = " Type must be one of 'bigquery', 'logging', 'pubsub', 'storage'. "
2022-11-11 10:05:39 -08:00
}
validation {
condition = alltrue ( [
for k , v in var . logging_sinks :
2022-11-12 10:24:41 -08:00
v . bq_partitioned_table ! = true | | v . type == " bigquery "
2022-11-11 10:05:39 -08:00
] )
2022-11-12 10:24:41 -08:00
error_message = " Can only set bq_partitioned_table when type is `bigquery`. "
2021-12-12 23:41:02 -08:00
}
2021-10-08 09:26:04 -07:00
}
2022-11-18 06:56:28 -08:00
variable " network_tags " {
FAST multitenant bootstrap and resource management, rename org-level FAST stages (#1052)
* rename stages
* remove support for external org billing, rename output files
* resman: make groups optional, align on new billing account variable
* bootstrap: multitenant outputs
* tenant bootstrap stage, untested
* fix folder name
* fix stage 0 output names
* optional creation for tag keys in organization module
* single tenant bootstrap minus tag
* rename output files, add tenant tag key
* fix organization module tag values output
* test skipping creation for tags in organization module
* single tenant bootstrap plan working
* multitenant bootstrap
* tfdoc
* fix check links error messages
* fix links
* tfdoc
* fix links
* rename fast tests, fix bootstrap tests
* multitenant stages have their own folder, simplify stage numbering
* stage renumbering
* wip
* rename tests
* exclude fast providers in fixture
* stage 0 tests
* stage 1 tests
* network stages tests
* stage tests
* tfdoc
* fix links
* tfdoc
* multitenant tests
* remove local files
* stage links command
* fix links script, TODO
* wip
* wip single tenant bootstrap
* working tenant bootstrap
* update gitignore
* remove local files
* tfdoc
* remove local files
* allow tests for tenant bootstrap stage
* tenant bootstrap proxies stage 1 tfvars
* stage 2 and 3 service accounts and IAM in tenant bootstrap
* wip
* wip
* wip
* drop multitenant bootstrap
* tfdoc
* add missing stage 2 SAs, fix org-level IAM condition
* wip
* wip
* optional tag value creation in organization module
* stage 1 working
* linting
* linting
* READMEs
* wip
* Make stage-links script work in old macos bash
* stage links command help
* fix output file names
* diagrams
* fix svg
* stage 0 skeleton and diagram
* test svg
* test svg
* test diagram
* diagram
* readme
* fix stage links script
* stage 0 readme
* README changes
* stage readmes
* fix outputs order
* fix link
* fix tests
* stage 1 test
* skip stage example
* boilerplate
* fix tftest skip
* default bootstrap stage log sinks to log buckets
* add logging to tenant bootstrap
* move iam variables out of tenant config
* fix cicd, reintroduce missing variable
* use optional in stage 1 cicd variable
* rename extras stage
* rename and move identity providers local, use optional for cicd variable
* tfdoc
* add support for wif pool and providers, ci/cd
* tfdoc
* fix links
* better handling of modules repository
* add missing role on logging project
* fix cicd pools in locals, test cicd
* fix workflow extension
* fix module source replacement
* allow tenant bootstrap cicd sa to impersonate resman sa
* tenant workflow templates fix for no providers file
* fix output files, push github workflow template to new repository
* remove try from outpout files
* align stage 1 cicd internals to stage 0
* tfdoc
* tests
* fix tests
* tests
* improve variable descriptions
* use optional in fast features
* actually create tenant log sinks, and allow the resman sa to do it
* test
* tests
* aaaand tests again
* fast features tenant override
* fast features tenant override
* fix wording
* add missing comment
* configure pf service accounts
* add missing comment
* tfdoc
* tests
* IAM docs
* update copyright
---------
Co-authored-by: Julio Castillo <jccb@google.com>
2023-02-04 06:00:45 -08:00
description = " Network tags by key name. If `id` is provided, key creation is skipped. The `iam` attribute behaves like the similarly named one at module level. "
2022-11-18 06:56:28 -08:00
type = map ( object ( {
description = optional ( string , " Managed by the Terraform organization module. " )
iam = optional ( map ( list ( string ) ) , { } )
FAST multitenant bootstrap and resource management, rename org-level FAST stages (#1052)
* rename stages
* remove support for external org billing, rename output files
* resman: make groups optional, align on new billing account variable
* bootstrap: multitenant outputs
* tenant bootstrap stage, untested
* fix folder name
* fix stage 0 output names
* optional creation for tag keys in organization module
* single tenant bootstrap minus tag
* rename output files, add tenant tag key
* fix organization module tag values output
* test skipping creation for tags in organization module
* single tenant bootstrap plan working
* multitenant bootstrap
* tfdoc
* fix check links error messages
* fix links
* tfdoc
* fix links
* rename fast tests, fix bootstrap tests
* multitenant stages have their own folder, simplify stage numbering
* stage renumbering
* wip
* rename tests
* exclude fast providers in fixture
* stage 0 tests
* stage 1 tests
* network stages tests
* stage tests
* tfdoc
* fix links
* tfdoc
* multitenant tests
* remove local files
* stage links command
* fix links script, TODO
* wip
* wip single tenant bootstrap
* working tenant bootstrap
* update gitignore
* remove local files
* tfdoc
* remove local files
* allow tests for tenant bootstrap stage
* tenant bootstrap proxies stage 1 tfvars
* stage 2 and 3 service accounts and IAM in tenant bootstrap
* wip
* wip
* wip
* drop multitenant bootstrap
* tfdoc
* add missing stage 2 SAs, fix org-level IAM condition
* wip
* wip
* optional tag value creation in organization module
* stage 1 working
* linting
* linting
* READMEs
* wip
* Make stage-links script work in old macos bash
* stage links command help
* fix output file names
* diagrams
* fix svg
* stage 0 skeleton and diagram
* test svg
* test svg
* test diagram
* diagram
* readme
* fix stage links script
* stage 0 readme
* README changes
* stage readmes
* fix outputs order
* fix link
* fix tests
* stage 1 test
* skip stage example
* boilerplate
* fix tftest skip
* default bootstrap stage log sinks to log buckets
* add logging to tenant bootstrap
* move iam variables out of tenant config
* fix cicd, reintroduce missing variable
* use optional in stage 1 cicd variable
* rename extras stage
* rename and move identity providers local, use optional for cicd variable
* tfdoc
* add support for wif pool and providers, ci/cd
* tfdoc
* fix links
* better handling of modules repository
* add missing role on logging project
* fix cicd pools in locals, test cicd
* fix workflow extension
* fix module source replacement
* allow tenant bootstrap cicd sa to impersonate resman sa
* tenant workflow templates fix for no providers file
* fix output files, push github workflow template to new repository
* remove try from outpout files
* align stage 1 cicd internals to stage 0
* tfdoc
* tests
* fix tests
* tests
* improve variable descriptions
* use optional in fast features
* actually create tenant log sinks, and allow the resman sa to do it
* test
* tests
* aaaand tests again
* fast features tenant override
* fast features tenant override
* fix wording
* add missing comment
* configure pf service accounts
* add missing comment
* tfdoc
* tests
* IAM docs
* update copyright
---------
Co-authored-by: Julio Castillo <jccb@google.com>
2023-02-04 06:00:45 -08:00
id = optional ( string )
2022-11-18 06:56:28 -08:00
network = string # project_id/vpc_name
values = optional ( map ( object ( {
description = optional ( string , " Managed by the Terraform organization module. " )
iam = optional ( map ( list ( string ) ) , { } )
} ) ) , { } )
} ) )
nullable = false
default = { }
validation {
condition = alltrue ( [
for k , v in var . network_tags : v ! = null
] )
error_message = " Use an empty map instead of null as value. "
}
}
2022-10-28 03:55:16 -07:00
variable " org_policies " {
description = " Organization policies applied to this organization keyed by policy name. "
2020-04-07 09:47:07 -07:00
type = map ( object ( {
2022-10-28 03:55:16 -07:00
inherit_from_parent = optional ( bool ) # for list policies only.
reset = optional ( bool )
rules = optional ( list ( object ( {
allow = optional ( object ( {
all = optional ( bool )
values = optional ( list ( string ) )
} ) )
deny = optional ( object ( {
all = optional ( bool )
values = optional ( list ( string ) )
} ) )
2023-02-21 03:24:40 -08:00
enforce = optional ( bool ) # for boolean policies only.
condition = optional ( object ( {
2022-10-28 03:55:16 -07:00
description = optional ( string )
expression = optional ( string )
location = optional ( string )
title = optional ( string )
2023-02-21 03:24:40 -08:00
} ) , { } )
2022-10-28 03:55:16 -07:00
} ) ) , [ ] )
2020-04-07 09:47:07 -07:00
} ) )
2022-01-29 01:08:17 -08:00
default = { }
nullable = false
2020-04-07 09:47:07 -07:00
}
2022-02-20 02:14:18 -08:00
2022-11-08 00:34:38 -08:00
variable " org_policies_data_path " {
description = " Path containing org policies in YAML format. "
type = string
default = null
}
variable " org_policy_custom_constraints " {
description = " Organization policiy custom constraints keyed by constraint name. "
type = map ( object ( {
display_name = optional ( string )
description = optional ( string )
action_type = string
condition = string
method_types = list ( string )
resource_types = list ( string )
} ) )
default = { }
nullable = false
}
variable " org_policy_custom_constraints_data_path " {
description = " Path containing org policy custom constraints in YAML format. "
type = string
default = null
}
2022-10-28 08:27:33 -07:00
variable " organization_id " {
description = " Organization id in organizations/nnnnnn format. "
type = string
validation {
condition = can ( regex ( " ^organizations/[0-9]+ " , var . organization_id ) )
error_message = " The organization_id must in the form organizations/nnn. "
}
}
2022-11-19 03:47:07 -08:00
variable " tag_bindings " {
description = " Tag bindings for this organization, in key => tag value id format. "
type = map ( string )
default = null
}
2022-11-18 06:56:28 -08:00
variable " tags " {
FAST multitenant bootstrap and resource management, rename org-level FAST stages (#1052)
* rename stages
* remove support for external org billing, rename output files
* resman: make groups optional, align on new billing account variable
* bootstrap: multitenant outputs
* tenant bootstrap stage, untested
* fix folder name
* fix stage 0 output names
* optional creation for tag keys in organization module
* single tenant bootstrap minus tag
* rename output files, add tenant tag key
* fix organization module tag values output
* test skipping creation for tags in organization module
* single tenant bootstrap plan working
* multitenant bootstrap
* tfdoc
* fix check links error messages
* fix links
* tfdoc
* fix links
* rename fast tests, fix bootstrap tests
* multitenant stages have their own folder, simplify stage numbering
* stage renumbering
* wip
* rename tests
* exclude fast providers in fixture
* stage 0 tests
* stage 1 tests
* network stages tests
* stage tests
* tfdoc
* fix links
* tfdoc
* multitenant tests
* remove local files
* stage links command
* fix links script, TODO
* wip
* wip single tenant bootstrap
* working tenant bootstrap
* update gitignore
* remove local files
* tfdoc
* remove local files
* allow tests for tenant bootstrap stage
* tenant bootstrap proxies stage 1 tfvars
* stage 2 and 3 service accounts and IAM in tenant bootstrap
* wip
* wip
* wip
* drop multitenant bootstrap
* tfdoc
* add missing stage 2 SAs, fix org-level IAM condition
* wip
* wip
* optional tag value creation in organization module
* stage 1 working
* linting
* linting
* READMEs
* wip
* Make stage-links script work in old macos bash
* stage links command help
* fix output file names
* diagrams
* fix svg
* stage 0 skeleton and diagram
* test svg
* test svg
* test diagram
* diagram
* readme
* fix stage links script
* stage 0 readme
* README changes
* stage readmes
* fix outputs order
* fix link
* fix tests
* stage 1 test
* skip stage example
* boilerplate
* fix tftest skip
* default bootstrap stage log sinks to log buckets
* add logging to tenant bootstrap
* move iam variables out of tenant config
* fix cicd, reintroduce missing variable
* use optional in stage 1 cicd variable
* rename extras stage
* rename and move identity providers local, use optional for cicd variable
* tfdoc
* add support for wif pool and providers, ci/cd
* tfdoc
* fix links
* better handling of modules repository
* add missing role on logging project
* fix cicd pools in locals, test cicd
* fix workflow extension
* fix module source replacement
* allow tenant bootstrap cicd sa to impersonate resman sa
* tenant workflow templates fix for no providers file
* fix output files, push github workflow template to new repository
* remove try from outpout files
* align stage 1 cicd internals to stage 0
* tfdoc
* tests
* fix tests
* tests
* improve variable descriptions
* use optional in fast features
* actually create tenant log sinks, and allow the resman sa to do it
* test
* tests
* aaaand tests again
* fast features tenant override
* fast features tenant override
* fix wording
* add missing comment
* configure pf service accounts
* add missing comment
* tfdoc
* tests
* IAM docs
* update copyright
---------
Co-authored-by: Julio Castillo <jccb@google.com>
2023-02-04 06:00:45 -08:00
description = " Tags by key name. If `id` is provided, key or value creation is skipped. The `iam` attribute behaves like the similarly named one at module level. "
2022-11-18 06:56:28 -08:00
type = map ( object ( {
description = optional ( string , " Managed by the Terraform organization module. " )
iam = optional ( map ( list ( string ) ) , { } )
FAST multitenant bootstrap and resource management, rename org-level FAST stages (#1052)
* rename stages
* remove support for external org billing, rename output files
* resman: make groups optional, align on new billing account variable
* bootstrap: multitenant outputs
* tenant bootstrap stage, untested
* fix folder name
* fix stage 0 output names
* optional creation for tag keys in organization module
* single tenant bootstrap minus tag
* rename output files, add tenant tag key
* fix organization module tag values output
* test skipping creation for tags in organization module
* single tenant bootstrap plan working
* multitenant bootstrap
* tfdoc
* fix check links error messages
* fix links
* tfdoc
* fix links
* rename fast tests, fix bootstrap tests
* multitenant stages have their own folder, simplify stage numbering
* stage renumbering
* wip
* rename tests
* exclude fast providers in fixture
* stage 0 tests
* stage 1 tests
* network stages tests
* stage tests
* tfdoc
* fix links
* tfdoc
* multitenant tests
* remove local files
* stage links command
* fix links script, TODO
* wip
* wip single tenant bootstrap
* working tenant bootstrap
* update gitignore
* remove local files
* tfdoc
* remove local files
* allow tests for tenant bootstrap stage
* tenant bootstrap proxies stage 1 tfvars
* stage 2 and 3 service accounts and IAM in tenant bootstrap
* wip
* wip
* wip
* drop multitenant bootstrap
* tfdoc
* add missing stage 2 SAs, fix org-level IAM condition
* wip
* wip
* optional tag value creation in organization module
* stage 1 working
* linting
* linting
* READMEs
* wip
* Make stage-links script work in old macos bash
* stage links command help
* fix output file names
* diagrams
* fix svg
* stage 0 skeleton and diagram
* test svg
* test svg
* test diagram
* diagram
* readme
* fix stage links script
* stage 0 readme
* README changes
* stage readmes
* fix outputs order
* fix link
* fix tests
* stage 1 test
* skip stage example
* boilerplate
* fix tftest skip
* default bootstrap stage log sinks to log buckets
* add logging to tenant bootstrap
* move iam variables out of tenant config
* fix cicd, reintroduce missing variable
* use optional in stage 1 cicd variable
* rename extras stage
* rename and move identity providers local, use optional for cicd variable
* tfdoc
* add support for wif pool and providers, ci/cd
* tfdoc
* fix links
* better handling of modules repository
* add missing role on logging project
* fix cicd pools in locals, test cicd
* fix workflow extension
* fix module source replacement
* allow tenant bootstrap cicd sa to impersonate resman sa
* tenant workflow templates fix for no providers file
* fix output files, push github workflow template to new repository
* remove try from outpout files
* align stage 1 cicd internals to stage 0
* tfdoc
* tests
* fix tests
* tests
* improve variable descriptions
* use optional in fast features
* actually create tenant log sinks, and allow the resman sa to do it
* test
* tests
* aaaand tests again
* fast features tenant override
* fast features tenant override
* fix wording
* add missing comment
* configure pf service accounts
* add missing comment
* tfdoc
* tests
* IAM docs
* update copyright
---------
Co-authored-by: Julio Castillo <jccb@google.com>
2023-02-04 06:00:45 -08:00
id = optional ( string )
2022-11-18 06:56:28 -08:00
values = optional ( map ( object ( {
description = optional ( string , " Managed by the Terraform organization module. " )
iam = optional ( map ( list ( string ) ) , { } )
FAST multitenant bootstrap and resource management, rename org-level FAST stages (#1052)
* rename stages
* remove support for external org billing, rename output files
* resman: make groups optional, align on new billing account variable
* bootstrap: multitenant outputs
* tenant bootstrap stage, untested
* fix folder name
* fix stage 0 output names
* optional creation for tag keys in organization module
* single tenant bootstrap minus tag
* rename output files, add tenant tag key
* fix organization module tag values output
* test skipping creation for tags in organization module
* single tenant bootstrap plan working
* multitenant bootstrap
* tfdoc
* fix check links error messages
* fix links
* tfdoc
* fix links
* rename fast tests, fix bootstrap tests
* multitenant stages have their own folder, simplify stage numbering
* stage renumbering
* wip
* rename tests
* exclude fast providers in fixture
* stage 0 tests
* stage 1 tests
* network stages tests
* stage tests
* tfdoc
* fix links
* tfdoc
* multitenant tests
* remove local files
* stage links command
* fix links script, TODO
* wip
* wip single tenant bootstrap
* working tenant bootstrap
* update gitignore
* remove local files
* tfdoc
* remove local files
* allow tests for tenant bootstrap stage
* tenant bootstrap proxies stage 1 tfvars
* stage 2 and 3 service accounts and IAM in tenant bootstrap
* wip
* wip
* wip
* drop multitenant bootstrap
* tfdoc
* add missing stage 2 SAs, fix org-level IAM condition
* wip
* wip
* optional tag value creation in organization module
* stage 1 working
* linting
* linting
* READMEs
* wip
* Make stage-links script work in old macos bash
* stage links command help
* fix output file names
* diagrams
* fix svg
* stage 0 skeleton and diagram
* test svg
* test svg
* test diagram
* diagram
* readme
* fix stage links script
* stage 0 readme
* README changes
* stage readmes
* fix outputs order
* fix link
* fix tests
* stage 1 test
* skip stage example
* boilerplate
* fix tftest skip
* default bootstrap stage log sinks to log buckets
* add logging to tenant bootstrap
* move iam variables out of tenant config
* fix cicd, reintroduce missing variable
* use optional in stage 1 cicd variable
* rename extras stage
* rename and move identity providers local, use optional for cicd variable
* tfdoc
* add support for wif pool and providers, ci/cd
* tfdoc
* fix links
* better handling of modules repository
* add missing role on logging project
* fix cicd pools in locals, test cicd
* fix workflow extension
* fix module source replacement
* allow tenant bootstrap cicd sa to impersonate resman sa
* tenant workflow templates fix for no providers file
* fix output files, push github workflow template to new repository
* remove try from outpout files
* align stage 1 cicd internals to stage 0
* tfdoc
* tests
* fix tests
* tests
* improve variable descriptions
* use optional in fast features
* actually create tenant log sinks, and allow the resman sa to do it
* test
* tests
* aaaand tests again
* fast features tenant override
* fast features tenant override
* fix wording
* add missing comment
* configure pf service accounts
* add missing comment
* tfdoc
* tests
* IAM docs
* update copyright
---------
Co-authored-by: Julio Castillo <jccb@google.com>
2023-02-04 06:00:45 -08:00
id = optional ( string )
2022-11-18 06:56:28 -08:00
} ) ) , { } )
} ) )
nullable = false
default = { }
validation {
condition = alltrue ( [
for k , v in var . tags : v ! = null
] )
error_message = " Use an empty map instead of null as value. "
}
}