File tree Expand file tree Collapse file tree 1 file changed +3
-0
lines changed
modules/shared_vpc_access Expand file tree Collapse file tree 1 file changed +3
-0
lines changed Original file line number Diff line number Diff line change @@ -26,6 +26,7 @@ locals {
2626 " dataproc.googleapis.com" : format (" service-%s@dataproc-accounts.iam.gserviceaccount.com" , local. service_project_number ),
2727 " dataflow.googleapis.com" : format (" service-%s@dataflow-service-producer-prod.iam.gserviceaccount.com" , local. service_project_number ),
2828 " composer.googleapis.com" : format (" service-%s@cloudcomposer-accounts.iam.gserviceaccount.com" , local. service_project_number )
29+ " vpcaccess.googleapis.com" : format (" service-%s@gcp-sa-vpcaccess.iam.gserviceaccount.com" , local. service_project_number )
2930 }
3031 gke_shared_vpc_enabled = contains (var. active_apis , " container.googleapis.com" )
3132 composer_shared_vpc_enabled = contains (var. active_apis , " composer.googleapis.com" )
@@ -39,6 +40,8 @@ locals {
3940 if "dataflow.googleapis.com" compute.networkUser role granted to dataflow service account for Dataflow on shared VPC subnets
4041 See: https://cloud.google.com/kubernetes-engine/docs/how-to/cluster-shared-vpc
4142 https://cloud.google.com/dataflow/docs/concepts/security-and-permissions#cloud_dataflow_service_account
43+ if "vpcaccess.googleapis.com" compute.networkUser role granted to Serverless VPC Access Service Agent on shared VPC subnets
44+ See: https://cloud.google.com/run/docs/configuring/connecting-shared-vpc#grant-permissions
4245 *****************************************/
4346resource "google_compute_subnetwork_iam_member" "service_shared_vpc_subnet_users" {
4447 provider = google- beta
You can’t perform that action at this time.
0 commit comments