Skip to content

Commit dbf9b33

Browse files
committed
Add 'secretmanager.versions.access' to Terraform service account to be able to set up Composer variables
[#4363]
1 parent 00606e4 commit dbf9b33

File tree

2 files changed

+3
-1
lines changed

2 files changed

+3
-1
lines changed

iac/cal-itp-data-infra-staging/iam/us/project_iam_member.tf

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -232,6 +232,7 @@ resource "google_project_iam_member" "github-actions-terraform" {
232232
"roles/resourcemanager.projectIamAdmin",
233233
"roles/run.admin",
234234
"roles/storage.admin",
235+
"roles/secretmanager.secretAccessor",
235236
])
236237
role = each.key
237238
member = "serviceAccount:${google_service_account.github-actions-terraform.email}"

iac/cal-itp-data-infra/iam/us/project_iam_member.tf

Lines changed: 2 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -558,7 +558,8 @@ resource "google_project_iam_member" "github-actions-terraform" {
558558
"roles/iam.workloadIdentityPoolAdmin",
559559
"roles/editor",
560560
"roles/storage.admin",
561-
"roles/logging.configWriter"
561+
"roles/logging.configWriter",
562+
"roles/secretmanager.secretAccessor",
562563
])
563564
role = each.key
564565
member = "serviceAccount:${google_service_account.github-actions-terraform.email}"

0 commit comments

Comments
 (0)