Skip to content

Commit 3c926af

Browse files
committed
fix: not applying the correct perms to cluster roles
1 parent 82e41e8 commit 3c926af

File tree

2 files changed

+8
-8
lines changed

2 files changed

+8
-8
lines changed

modules/helm_release/main.tf

Lines changed: 4 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -5,10 +5,10 @@ locals {
55
}
66

77
image_tags = {
8-
"migrations.image.tag" = "6e2185a",
9-
"webservice.image.tag" = "6e2185a",
10-
"event-worker.image.tag" = "6e2185a",
11-
"job-policy-checker.image.tag" = "6e2185a",
8+
"migrations.image.tag" = "8cce786",
9+
"webservice.image.tag" = "8adc7da",
10+
"event-worker.image.tag" = "8cce786",
11+
"job-policy-checker.image.tag" = "8cce786",
1212
}
1313

1414
postgres_settings = {

modules/service_accounts/main.tf

Lines changed: 4 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -22,31 +22,31 @@ locals {
2222
}
2323

2424
resource "google_service_account_iam_member" "gke_workload_identity" {
25-
for_each = toset(local.members)
25+
for_each = { for idx, member in local.members : idx => member }
2626

2727
service_account_id = google_service_account.gke.id
2828
role = "roles/iam.workloadIdentityUser"
2929
member = each.value
3030
}
3131

3232
resource "google_project_iam_member" "gke_workload_sa_admin" {
33-
for_each = toset(local.members)
33+
for_each = { for idx, member in local.members : idx => member }
3434

3535
project = local.project_id
3636
role = "roles/iam.serviceAccountAdmin"
3737
member = each.value
3838
}
3939

4040
resource "google_project_iam_member" "gke_workload_sa_user" {
41-
for_each = toset(local.members)
41+
for_each = { for idx, member in local.members : idx => member }
4242

4343
project = local.project_id
4444
role = "roles/iam.serviceAccountUser"
4545
member = each.value
4646
}
4747

4848
resource "google_project_iam_member" "gke_workload_sa_token_creator" {
49-
for_each = toset(local.members)
49+
for_each = { for idx, member in local.members : idx => member }
5050

5151
project = local.project_id
5252
role = "roles/iam.serviceAccountTokenCreator"

0 commit comments

Comments
 (0)