95 lines
4.4 KiB
Markdown
95 lines
4.4 KiB
Markdown
# Google Cloud Source Repository Module
|
|
|
|
This module allows managing a single Cloud Source Repository, including IAM bindings and basic Cloud Build triggers.
|
|
|
|
<!-- BEGIN TOC -->
|
|
- [Examples](#examples)
|
|
- [Repository with IAM](#repository-with-iam)
|
|
- [Repository with Cloud Build trigger](#repository-with-cloud-build-trigger)
|
|
- [Files](#files)
|
|
- [Variables](#variables)
|
|
- [Outputs](#outputs)
|
|
<!-- END TOC -->
|
|
|
|
## Examples
|
|
|
|
### Repository with IAM
|
|
|
|
```hcl
|
|
module "repo" {
|
|
source = "./fabric/modules/source-repository"
|
|
project_id = "my-project"
|
|
name = "my-repo"
|
|
iam = {
|
|
"roles/source.reader" = ["user:foo@example.com"]
|
|
}
|
|
iam_bindings_additive = {
|
|
am1-reader = {
|
|
member = "user:am1@example.com"
|
|
role = "roles/source.reader"
|
|
}
|
|
}
|
|
}
|
|
# tftest modules=1 resources=3 inventory=simple.yaml
|
|
```
|
|
|
|
### Repository with Cloud Build trigger
|
|
|
|
```hcl
|
|
module "repo" {
|
|
source = "./fabric/modules/source-repository"
|
|
project_id = "my-project"
|
|
name = "my-repo"
|
|
triggers = {
|
|
foo = {
|
|
filename = "ci/workflow-foo.yaml"
|
|
included_files = ["**/*tf"]
|
|
service_account = null
|
|
substitutions = {
|
|
BAR = 1
|
|
}
|
|
template = {
|
|
branch_name = "main"
|
|
project_id = null
|
|
tag_name = null
|
|
}
|
|
}
|
|
}
|
|
}
|
|
# tftest modules=1 resources=2 inventory=trigger.yaml
|
|
```
|
|
|
|
<!-- TFDOC OPTS files:1 -->
|
|
<!-- BEGIN TFDOC -->
|
|
## Files
|
|
|
|
| name | description | resources |
|
|
|---|---|---|
|
|
| [iam.tf](./iam.tf) | IAM bindings. | <code>google_sourcerepo_repository_iam_binding</code> · <code>google_sourcerepo_repository_iam_member</code> |
|
|
| [main.tf](./main.tf) | Module-level locals and resources. | <code>google_cloudbuild_trigger</code> · <code>google_sourcerepo_repository</code> |
|
|
| [outputs.tf](./outputs.tf) | Module outputs. | |
|
|
| [variables-iam.tf](./variables-iam.tf) | None | |
|
|
| [variables.tf](./variables.tf) | Module variables. | |
|
|
| [versions.tf](./versions.tf) | Version pins. | |
|
|
|
|
## Variables
|
|
|
|
| name | description | type | required | default |
|
|
|---|---|:---:|:---:|:---:|
|
|
| [name](variables.tf#L17) | Repository name. | <code>string</code> | ✓ | |
|
|
| [project_id](variables.tf#L22) | Project used for resources. | <code>string</code> | ✓ | |
|
|
| [iam](variables-iam.tf#L17) | IAM bindings in {ROLE => [MEMBERS]} format. | <code>map(list(string))</code> | | <code>{}</code> |
|
|
| [iam_bindings](variables-iam.tf#L24) | Authoritative IAM bindings in {KEY => {role = ROLE, members = [], condition = {}}}. Keys are arbitrary. | <code title="map(object({ members = list(string) role = string condition = optional(object({ expression = string title = string description = optional(string) })) }))">map(object({…}))</code> | | <code>{}</code> |
|
|
| [iam_bindings_additive](variables-iam.tf#L39) | Individual additive IAM bindings. Keys are arbitrary. | <code title="map(object({ member = string role = string condition = optional(object({ expression = string title = string description = optional(string) })) }))">map(object({…}))</code> | | <code>{}</code> |
|
|
| [iam_by_principals](variables-iam.tf#L54) | Authoritative IAM binding in {PRINCIPAL => [ROLES]} format. Principals need to be statically defined to avoid cycle errors. Merged internally with the `iam` variable. | <code>map(list(string))</code> | | <code>{}</code> |
|
|
| [triggers](variables.tf#L27) | Cloud Build triggers. | <code title="map(object({ filename = string included_files = list(string) service_account = string substitutions = map(string) template = object({ branch_name = string project_id = string tag_name = string }) }))">map(object({…}))</code> | | <code>{}</code> |
|
|
|
|
## Outputs
|
|
|
|
| name | description | sensitive |
|
|
|---|---|:---:|
|
|
| [id](outputs.tf#L17) | Fully qualified repository id. | |
|
|
| [name](outputs.tf#L22) | Repository name. | |
|
|
| [url](outputs.tf#L27) | Repository URL. | |
|
|
<!-- END TFDOC -->
|