This module allows simplified creation and management of one a service account and its IAM bindings. A key can optionally be generated and will be stored in Terraform state. To use it create a sensitive output in your root modules referencing the `key` output, then extract the private key from the JSON formatted outputs. Alternatively, the `key` can be generated with `openssl` library and only public part uploaded to the Service Account, for more refer to the [Onprem SA Key Management](../../cloud-operations/onprem-sa-key-management/) example.
| display_name | Display name of the service account to create. | <code>string</code> | | <code>"Terraform-managed."</code> |
| generate_key | Generate a key for service account. | <code>bool</code> | | <code>false</code> |
| iam | IAM bindings on the service account in {ROLE => [MEMBERS]} format. | <code>map(list(string))</code> | | <code>{}</code> |
| iam_billing_roles | Project roles granted to the service account, by billing account id. | <code>map(list(string))</code> | | <code>{}</code> |
| iam_folder_roles | Project roles granted to the service account, by folder id. | <code>map(list(string))</code> | | <code>{}</code> |
| iam_organization_roles | Project roles granted to the service account, by organization id. | <code>map(list(string))</code> | | <code>{}</code> |
| iam_project_roles | Project roles granted to the service account, by project id. | <code>map(list(string))</code> | | <code>{}</code> |
| iam_storage_roles | Storage roles granted to the service account, by bucket name. | <code>map(list(string))</code> | | <code>{}</code> |
| prefix | Prefix applied to service account names. | <code>string</code> | | <code>null</code> |
| public_keys_directory | Path to public keys data files to upload to the service account (should have `.pem` extension). | <code>string</code> | | <code>""</code> |
| service_account_create | Create service account. When set to false, uses a data source to reference an existing service account. | <code>bool</code> | | <code>true</code> |