Fix/dlpagent (#1868)

Create DLP Service Account on service activation.
This commit is contained in:
ddaluka 2023-11-20 18:41:01 +05:30 committed by GitHub
parent c642c13a31
commit 543ea6e7f3
No known key found for this signature in database
GPG Key ID: 4AEE18F83AFDEB23
4 changed files with 4 additions and 2 deletions

View File

@ -228,7 +228,7 @@ module "data-platform" {
}
prefix = "myprefix"
}
# tftest modules=43 resources=290
# tftest modules=43 resources=293
```
## Customizations

View File

@ -229,7 +229,7 @@ module "data-platform" {
prefix = "myprefix"
}
# tftest modules=23 resources=137
# tftest modules=23 resources=138
```
## Customizations

View File

@ -219,6 +219,7 @@ This table lists all affected services and roles that you need to grant to servi
| cloudasset.googleapis.com | cloudasset | roles/cloudasset.serviceAgent |
| cloudbuild.googleapis.com | cloudbuild | roles/cloudbuild.builds.builder |
| dataplex.googleapis.com | dataplex | roles/dataplex.serviceAgent |
| dlp.googleapis.com | dlp | roles/dlp.serviceAgent |
| gkehub.googleapis.com | fleet | roles/gkehub.serviceAgent |
| meshconfig.googleapis.com | servicemesh | roles/anthosservicemesh.serviceAgent |
| multiclusteringress.googleapis.com | multicluster-ingress | roles/multiclusteringress.serviceAgent |

View File

@ -169,6 +169,7 @@
# dlp ="organizations-ORGANIZATION_NUMBER@gcp-sa-riskmanager"
- name: "dlp"
service_agent: "service-%s@dlp-api.iam.gserviceaccount.com"
jit: true
- name: "documentai"
service_agent: "service-%s@gcp-sa-prod-dai-core.iam.gserviceaccount.com"
- name: "edgecontainer"