-
Notifications
You must be signed in to change notification settings - Fork 1.7k
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
BigqueryTableIamMember doesn't support IAM conditions #18645
BigqueryTableIamMember doesn't support IAM conditions #18645
Comments
Confirmed issue! When trying to create the resource
|
Confirmed as well. Thanks for reporting the issue, I will forward the internal version of this issue to the Table/IAM API team. |
@kvudata and others impacted - I received the following guidance from the BigQuery Security and Governance team:
Could you try setting the condition on e.g. In terms of documentations, I double checked that https://cloud.google.com/iam/docs/resource-types-with-conditional-roles doesn't mention BigQuery, but we'll update https://registry.terraform.io/providers/hashicorp/google/latest/docs/resources/bigquery_table_iam#google_bigquery_table_iam_member to remove the example config since it's invalid. |
Yes, I've managed to workaround this by using google_project_iam_member. |
Thank you for confirming. We'll be removing the misleading example on the Terraform resource documentations about setting IAM conditions on Table and others. |
I'm going to lock this issue because it has been closed for 30 days ⏳. This helps our maintainers find and focus on the active issues. |
Community Note
Terraform Version & Provider Version(s)
Terraform v1.6.3
on linux_amd64
Affected Resource(s)
google_bigquery_table_iam_member
Terraform Configuration
(slightly modified)
Debug Output
No response
Expected Behavior
The resource should've been created successfully
Actual Behavior
Fails with an error
Steps to reproduce
terraform apply
Important Factoids
No response
References
Per https://cloud.google.com/iam/docs/resource-types-with-conditional-roles, it looks like BigQuery tables do not support conditions so it seems like a bug for the provider to provide that in the API.
b/351528828
The text was updated successfully, but these errors were encountered: