explicitly set pubsub permission for cloud asset robot account

This commit is contained in:
Ludovico Magnocavallo 2020-07-30 18:11:11 +02:00
parent 6c5b35d0e2
commit 2f70e811ae
1 changed files with 8 additions and 0 deletions

View File

@ -59,6 +59,14 @@ module "pubsub" {
project_id = module.project.project_id
name = var.name
subscriptions = { "${var.name}-default" = null }
iam_roles = [
"roles/pubsub.publisher"
]
iam_members = {
"roles/pubsub.publisher" = [
"serviceAccount:${module.project.service_accounts.robots.cloudasset}"
]
}
}
module "service-account" {