# Google Cloud Source Repository Module This module allows managing a single Cloud Source Repository, including IAM bindings and basic Cloud Build triggers. - [Examples](#examples) - [Repository with IAM](#repository-with-iam) - [Repository with Cloud Build trigger](#repository-with-cloud-build-trigger) - [Files](#files) - [Variables](#variables) - [Outputs](#outputs) ## Examples ### Repository with IAM ```hcl module "repo" { source = "./fabric/modules/source-repository" project_id = "my-project" name = "my-repo" iam = { "roles/source.reader" = ["user:foo@example.com"] } iam_bindings_additive = { am1-reader = { member = "user:am1@example.com" role = "roles/source.reader" } } } # tftest modules=1 resources=3 inventory=simple.yaml ``` ### Repository with Cloud Build trigger ```hcl module "repo" { source = "./fabric/modules/source-repository" project_id = "my-project" name = "my-repo" triggers = { foo = { filename = "ci/workflow-foo.yaml" included_files = ["**/*tf"] service_account = null substitutions = { BAR = 1 } template = { branch_name = "main" project_id = null tag_name = null } } } } # tftest modules=1 resources=2 inventory=trigger.yaml ``` ## Files | name | description | resources | |---|---|---| | [iam.tf](./iam.tf) | IAM bindings. | google_sourcerepo_repository_iam_binding · google_sourcerepo_repository_iam_member | | [main.tf](./main.tf) | Module-level locals and resources. | google_cloudbuild_trigger · google_sourcerepo_repository | | [outputs.tf](./outputs.tf) | Module outputs. | | | [variables-iam.tf](./variables-iam.tf) | None | | | [variables.tf](./variables.tf) | Module variables. | | | [versions.tf](./versions.tf) | Version pins. | | ## Variables | name | description | type | required | default | |---|---|:---:|:---:|:---:| | [name](variables.tf#L17) | Repository name. | string | ✓ | | | [project_id](variables.tf#L22) | Project used for resources. | string | ✓ | | | [iam](variables-iam.tf#L17) | IAM bindings in {ROLE => [MEMBERS]} format. | map(list(string)) | | {} | | [iam_bindings](variables-iam.tf#L24) | Authoritative IAM bindings in {KEY => {role = ROLE, members = [], condition = {}}}. Keys are arbitrary. | map(object({…})) | | {} | | [iam_bindings_additive](variables-iam.tf#L39) | Individual additive IAM bindings. Keys are arbitrary. | map(object({…})) | | {} | | [iam_by_principals](variables-iam.tf#L54) | Authoritative IAM binding in {PRINCIPAL => [ROLES]} format. Principals need to be statically defined to avoid cycle errors. Merged internally with the `iam` variable. | map(list(string)) | | {} | | [triggers](variables.tf#L27) | Cloud Build triggers. | map(object({…})) | | {} | ## Outputs | name | description | sensitive | |---|---|:---:| | [id](outputs.tf#L17) | Fully qualified repository id. | | | [name](outputs.tf#L22) | Repository name. | | | [url](outputs.tf#L27) | Repository URL. | |