61 lines
4.0 KiB
Markdown
61 lines
4.0 KiB
Markdown
# Google Cloud Unit Folders Module
|
|
|
|
This module allows creation and management of an organizational hierarchy "unit" composed of a parent folder (usually mapped to a business unit or team), and a set of child folders (usually mapped to environments) each with a corresponding set of service accounts, IAM bindings and GCS buckets.
|
|
|
|
## Example
|
|
|
|
```hcl
|
|
module "folders-unit" {
|
|
source = "./modules/folders-unit"
|
|
name = "Business Intelligence"
|
|
short_name = "bi"
|
|
automation_project_id = "automation-project-394yr923811"
|
|
billing_account_id = "015617-16GHBC-AF02D9"
|
|
organization_id = "506128240800"
|
|
root_node = "folders/93469270123701"
|
|
prefix = "unique-prefix"
|
|
environments = {
|
|
dev = "Development",
|
|
test = "Testing",
|
|
prod = "Production"
|
|
}
|
|
service_account_keys = true
|
|
}
|
|
# tftest:modules=1:resources=37
|
|
```
|
|
|
|
|
|
<!-- BEGIN TFDOC -->
|
|
|
|
## Variables
|
|
|
|
| name | description | type | required | default |
|
|
|---|---|:---:|:---:|:---:|
|
|
| automation_project_id | Project id used for automation service accounts. | <code>string</code> | ✓ | |
|
|
| billing_account_id | Country billing account account. | <code>string</code> | ✓ | |
|
|
| name | Top folder name. | <code>string</code> | ✓ | |
|
|
| organization_id | Organization id in organizations/nnnnnn format. | <code>string</code> | ✓ | |
|
|
| root_node | Root node in folders/folder_id or organizations/org_id format. | <code>string</code> | ✓ | |
|
|
| short_name | Short name used as GCS bucket and service account prefixes, do not use capital letters or spaces. | <code>string</code> | ✓ | |
|
|
| environments | Unit environments short names. | <code>map(string)</code> | | <code title="{ non-prod = "Non production" prod = "Production" }">{…}</code> |
|
|
| gcs_defaults | Defaults use for the state GCS buckets. | <code>map(string)</code> | | <code title="{ location = "EU" storage_class = "MULTI_REGIONAL" }">{…}</code> |
|
|
| iam | IAM bindings for the top-level folder in {ROLE => [MEMBERS]} format. | <code>map(list(string))</code> | | <code>{}</code> |
|
|
| iam_billing_config | Grant billing user role to service accounts, defaults to granting on the billing account. | <code title="object({ grant = bool target_org = bool })">object({…})</code> | | <code title="{ grant = true target_org = false }">{…}</code> |
|
|
| iam_enviroment_roles | IAM roles granted to the environment service account on the environment sub-folder. | <code>list(string)</code> | | <code title="[ "roles/compute.networkAdmin", "roles/owner", "roles/resourcemanager.folderAdmin", "roles/resourcemanager.projectCreator", ]">[…]</code> |
|
|
| iam_xpn_config | Grant Shared VPC creation roles to service accounts, defaults to granting at folder level. | <code title="object({ grant = bool target_org = bool })">object({…})</code> | | <code title="{ grant = true target_org = false }">{…}</code> |
|
|
| prefix | Optional prefix used for GCS bucket names to ensure uniqueness. | <code>string</code> | | <code>null</code> |
|
|
| service_account_keys | Generate and store service account keys in the state file. | <code>bool</code> | | <code>false</code> |
|
|
|
|
## Outputs
|
|
|
|
| name | description | sensitive |
|
|
|---|---|:---:|
|
|
| env_folders | Unit environments folders. | |
|
|
| env_gcs_buckets | Unit environments tfstate gcs buckets. | |
|
|
| env_sa_keys | Unit environments service account keys. | ✓ |
|
|
| env_service_accounts | Unit environments service accounts. | |
|
|
| unit_folder | Unit top level folder. | |
|
|
|
|
<!-- END TFDOC -->
|
|
|