Skip to content

Commit 4f7ff72

Browse files
authored
Add service account admin permissions to terraform service accounts (#4022)
Signed-off-by: Erika Pacheco <[email protected]>
1 parent f39099b commit 4f7ff72

File tree

2 files changed

+2
-0
lines changed

2 files changed

+2
-0
lines changed

iac/cal-itp-data-infra-staging/iam/us/project_iam_member.tf

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -227,6 +227,7 @@ resource "google_project_iam_member" "github-actions-terraform" {
227227
"roles/editor",
228228
"roles/storage.admin",
229229
"roles/iam.roleAdmin",
230+
"roles/iam.serviceAccountAdmin",
230231
"roles/logging.configWriter"
231232
])
232233
role = each.key

iac/cal-itp-data-infra/iam/us/project_iam_member.tf

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -542,6 +542,7 @@ resource "google_project_iam_member" "github-actions-terraform" {
542542
for_each = toset([
543543
"roles/resourcemanager.projectIamAdmin",
544544
"roles/iam.roleAdmin",
545+
"roles/iam.serviceAccountAdmin",
545546
"roles/editor",
546547
"roles/storage.admin"
547548
])

0 commit comments

Comments
 (0)