Skip to content

Instantly share code, notes, and snippets.

@kborovik
Created October 15, 2024 15:51
Show Gist options
  • Save kborovik/5f9339e4dc55e6d34090d891ceaadba7 to your computer and use it in GitHub Desktop.
Save kborovik/5f9339e4dc55e6d34090d891ceaadba7 to your computer and use it in GitHub Desktop.
###############################################################################
# Google Project IAM Members
# Single stanza for all IAM bindings
###############################################################################
locals {
google_project = "example-project"
users = toset([
"user:[email protected]",
"user:[email protected]",
"user:[email protected]",
])
users_roles = toset([
"roles/viewer",
"roles/bigquery.admin",
"roles/run.admin",
"roles/run.invoker",
"roles/compute.osAdminLogin",
"roles/iap.tunnelResourceAccessor",
"roles/compute.instanceAdmin.v1",
])
}
resource "google_project_iam_member" "users" {
for_each = {
for pair in setproduct(local.users, local.users_roles) :
"${pair[0]}-${pair[1]}" => {
member = pair[0]
role = pair[1]
}
}
project = local.google_project
member = each.value.member
role = each.value.role
}
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment