From 66d4c5b3332571f416c06041701a29c5dc82857e Mon Sep 17 00:00:00 2001 From: Bharath KKB Date: Mon, 7 Mar 2022 18:47:31 -0600 Subject: [PATCH] fix: always grant view permissions at org to CB SA for TFV (#645) --- 0-bootstrap/main.tf | 8 -------- 1 file changed, 8 deletions(-) diff --git a/0-bootstrap/main.tf b/0-bootstrap/main.tf index ede6c4ee3..67a477643 100644 --- a/0-bootstrap/main.tf +++ b/0-bootstrap/main.tf @@ -177,19 +177,11 @@ data "google_project" "cloudbuild" { } resource "google_organization_iam_member" "org_cb_sa_iam_viewer" { - count = var.parent_folder == "" ? 1 : 0 org_id = var.org_id role = "roles/iam.securityReviewer" member = "serviceAccount:${data.google_project.cloudbuild.number}@cloudbuild.gserviceaccount.com" } -resource "google_folder_iam_member" "org_cb_sa_iam_viewer" { - count = var.parent_folder != "" ? 1 : 0 - folder = var.parent_folder - role = "roles/iam.securityReviewer" - member = "serviceAccount:${data.google_project.cloudbuild.number}@cloudbuild.gserviceaccount.com" -} - resource "google_organization_iam_member" "org_cb_sa_browser" { count = var.parent_folder == "" ? 1 : 0 org_id = var.org_id