This sample creates an organizational layout with two folder levels, where the first level is usually mapped to one business unit or team (infra, data, analytics) and the second level represents enviroments (prod, test). It also sets up all prerequisites for automation (GCS state buckets, service accounts, etc.), and the correct roles on those to enforce separation of duties at the environment level.
This layout is well suited for medium-sized infrastructures managed by different sets of teams, and especially where the foundational infrastructure needs to be managed centrally, as the top-level automation service accounts for each environment allow cross-team management of the base resources (projects, IAM, etc.).
Refer to the [section-level README](../README.md) for general considerations about this type of samples, and usage instructions.
## Managed resources and services
This sample creates several distinct groups of resources:
- one top-level folder per business unit/team
- one top-level folder for shared services
- one second-level folder for each environment in all the business unit top-level folders
- one project in the shared folder to hold Terraform-related resources
- one project in the shared folder to set up and host centralized audit log exports
- one project in the shared folder to hold services used across environments like GCS, GCR, KMS, Cloud Build, etc.
The number of resources in this sample is kept to a minimum so as to make it generally applicable, more resources can be easily added by leveraging the full array of [Cloud Foundation Toolkit modules](https://github.com/terraform-google-modules), especially in the shared services project.
## Shared services
This sample uses a top-level folder to encapsulate projects that host resources that are not specific to a single environment. If no shared services are needed,the Terraform and audit modules can be easily attached to the root node, and the shared services folder and project removed from `main.tf`.
| *generate_service_account_keys* | Generate and store service account keys in the state file. | <codetitle="">bool</code> | | <codetitle="">false</code> |
| *project_services* | Service APIs enabled by default in new projects. | <codetitle="list(string)">list(string)</code> | | <codetitle="[ "resourceviews.googleapis.com", "stackdriver.googleapis.com", ]">...</code> |
| *shared_bindings_members* | List of comma-delimited IAM-format members for the additional shared project bindings. | <codetitle="list(string)">list(string)</code> | | <codetitle="">[]</code> |
| *shared_bindings_roles* | List of roles for additional shared project bindings. | <codetitle="list(string)">list(string)</code> | | <codetitle="">[]</code> |
| *terraform_owners* | Terraform project owners, in IAM format. | <codetitle="list(string)">list(string)</code> | | <codetitle="">[]</code> |