Google Service Account Module
This module allows simplified creation and management of one a service account and its IAM bindings. A key can optionally be generated and will be stored in Terraform state. To use it create a sensitive output in your root modules referencing the key
output, then extract the private key from the JSON formatted outputs.
Example
module "myproject-default-service-accounts" {
source = "./modules/iam-service-account"
project_id = "myproject"
name = "vm-default"
generate_key = true
# authoritative roles granted *on* the service accounts to other identities
iam_members = {
"roles/iam.serviceAccountUser" = ["user:foo@example.com"]
}
# non-authoritative roles granted *to* the service accounts on other resources
iam_project_roles = {
"myproject" = [
"roles/logging.logWriter",
"roles/monitoring.metricWriter",
]
}
}
Variables
name |
description |
type |
required |
default |
name |
Name of the service account to create. |
string |
✓ |
|
project_id |
Project id where service account will be created. |
string |
✓ |
|
display_name |
Display name of the service account to create. |
string |
|
Terraform-managed. |
generate_key |
Generate a key for service account. |
bool |
|
false |
iam_billing_roles |
Project roles granted to the service account, by billing account id. |
map(set(string)) |
|
{} |
iam_folder_roles |
Project roles granted to the service account, by folder id. |
map(set(string)) |
|
{} |
iam_members |
Map of members which are granted authoritative roles on the service account, keyed by role. |
map(set(string)) |
|
{} |
iam_organization_roles |
Project roles granted to the service account, by organization id. |
map(set(string)) |
|
{} |
iam_project_roles |
Project roles granted to the service account, by project id. |
map(set(string)) |
|
{} |
iam_storage_roles |
Storage roles granted to the service account, by bucket name. |
map(set(string)) |
|
{} |
prefix |
Prefix applied to service account names. |
string |
|
null |
Outputs
name |
description |
sensitive |
email |
Service account email. |
|
iam_email |
IAM-format service account email. |
|
key |
Service account key. |
✓ |
service_account |
Service account resource. |
|