-
Notifications
You must be signed in to change notification settings - Fork 2
/
Copy pathiam.tf
47 lines (33 loc) · 1.53 KB
/
iam.tf
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
locals {
# filter all objects that define a single role
iam_role = [for iam in var.iam : iam if can(iam.role)]
# filter all objects that define multiple roles and expand them to single roles
iam_roles = flatten([for iam in var.iam :
[for role in iam.roles : merge(iam, { role = role })] if can(iam.roles)
])
iam = concat(local.iam_role, local.iam_roles)
iam_map = { for idx, iam in local.iam :
try(iam._key, "${iam.role}/${iam.condition._key}", "${iam.role}/${md5(jsonencode(iam.condition))}", iam.role) => idx
}
}
module "iam" {
source = "github.com/mineiros-io/terraform-google-subnetwork-iam.git?ref=v0.2.0"
for_each = var.policy_bindings == null ? local.iam_map : {}
module_enabled = var.module_enabled
module_depends_on = var.module_depends_on
subnetwork = try(google_compute_subnetwork.subnetwork[0].name, null)
role = local.iam[each.value].role
members = try(local.iam[each.value].members, [])
computed_members_map = var.computed_members_map
condition = try(local.iam[each.value].condition, null)
authoritative = try(local.iam[each.value].authoritative, true)
}
module "policy_bindings" {
source = "github.com/mineiros-io/terraform-google-subnetwork-iam.git?ref=v0.2.0"
count = var.policy_bindings != null ? 1 : 0
module_enabled = var.module_enabled
module_depends_on = var.module_depends_on
subnetwork = try(google_compute_subnetwork.subnetwork[0].name, null)
policy_bindings = var.policy_bindings
computed_members_map = var.computed_members_map
}