Skip to content

Commit 0e127ba

Browse files
authored
fix: Add iam permission required for vault version greater than 1.11 … (#198)
1 parent 07f181b commit 0e127ba

File tree

1 file changed

+6
-0
lines changed

1 file changed

+6
-0
lines changed

modules/cluster/iam.tf

Lines changed: 6 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -49,6 +49,12 @@ resource "google_kms_crypto_key_iam_member" "ck-iam" {
4949
member = local.service_account_member
5050
}
5151

52+
resource "google_kms_crypto_key_iam_member" "ck-iam-viewer" {
53+
crypto_key_id = google_kms_crypto_key.vault-init.id
54+
role = "roles/cloudkms.viewer"
55+
member = local.service_account_member
56+
}
57+
5258
resource "google_kms_crypto_key_iam_member" "tls-ck-iam" {
5359
count = var.manage_tls == false ? 1 : 0
5460

0 commit comments

Comments
 (0)