Skip to content

Commit

Permalink
fix: adding roles/storage.objectViewer and enabling library scanning …
Browse files Browse the repository at this point in the history
…by default (#7)
  • Loading branch information
Mike Laramie authored Mar 9, 2022
1 parent 9b3c05c commit 6ea75eb
Showing 1 changed file with 9 additions and 2 deletions.
11 changes: 9 additions & 2 deletions main.tf
Original file line number Diff line number Diff line change
Expand Up @@ -39,20 +39,27 @@ resource "google_project_service" "required_apis_for_gar_integration" {
}

// Role(s) for a GAR integration
resource "google_project_iam_member" "for_gar_integration" {
resource "google_project_iam_member" "gar_reader" {
project = local.project_id
role = "roles/artifactregistry.reader"
member = "serviceAccount:${local.service_account_json_key.client_email}"
}

resource "google_project_iam_member" "storage_reader" {
project = local.project_id
role = "roles/storage.objectViewer"
member = "serviceAccount:${local.service_account_json_key.client_email}"
}

# wait for X seconds for things to settle down in the GCP side
# before trying to create the Lacework external integration
resource "time_sleep" "wait_time" {
create_duration = var.wait_time
depends_on = [
module.lacework_gar_svc_account,
google_project_service.required_apis_for_gar_integration,
google_project_iam_member.for_gar_integration
google_project_iam_member.gar_reader,
google_project_iam_member.storage_reader
]
}

Expand Down

0 comments on commit 6ea75eb

Please sign in to comment.