This optional module is used to configure audit log configs for a project.
module "audit_log_config" {
source = "terraform-google-modules/iam/google//modules/audit_config"
version = "~> 8.0"
project = my-project
audit_log_config = [
{
service = "pubsub.googleapis.com"
log_type = "DATA_READ"
exempted_members = [
"group:my-group@my-org.com",
"serviceAccount:my-sa@my-project.iam.gserviceaccount.com",
"user:my-user@my-org.com"
]
},
{
service = "storage.googleapis.com"
log_type = "DATA_WRITE"
exempted_members = [
"group:my-group@my-org.com",
"serviceAccount:my-sa@my-project.iam.gserviceaccount.com",
"user:my-user@my-org.com"
]
},
{
service = "pubsub.googleapis.com"
log_type = "DATA_WRITE"
exempted_members = [
"group:my-group@my-org.com",
"serviceAccount:my-sa@my-project.iam.gserviceaccount.com",
"user:my-user@my-org.com"
]
}
]
}