diff --git a/autogen/main/sa.tf.tmpl b/autogen/main/sa.tf.tmpl index d2db09190..68a0a67f1 100644 --- a/autogen/main/sa.tf.tmpl +++ b/autogen/main/sa.tf.tmpl @@ -76,3 +76,9 @@ resource "google_project_iam_member" "cluster_service_account-gcr" { member = "serviceAccount:${google_service_account.cluster_service_account[0].email}" } +resource "google_project_iam_member" "cluster_service_account-artifact-registry" { + count = var.create_service_account && var.grant_registry_access ? 1 : 0 + project = var.registry_project_id == "" ? var.project_id : var.registry_project_id + role = "roles/artifactregistry.reader" + member = "serviceAccount:${google_service_account.cluster_service_account[0].email}" +} diff --git a/modules/beta-private-cluster-update-variant/sa.tf b/modules/beta-private-cluster-update-variant/sa.tf index 6e3593141..6b79badb2 100644 --- a/modules/beta-private-cluster-update-variant/sa.tf +++ b/modules/beta-private-cluster-update-variant/sa.tf @@ -76,3 +76,9 @@ resource "google_project_iam_member" "cluster_service_account-gcr" { member = "serviceAccount:${google_service_account.cluster_service_account[0].email}" } +resource "google_project_iam_member" "cluster_service_account-artifact-registry" { + count = var.create_service_account && var.grant_registry_access ? 1 : 0 + project = var.registry_project_id == "" ? var.project_id : var.registry_project_id + role = "roles/artifactregistry.reader" + member = "serviceAccount:${google_service_account.cluster_service_account[0].email}" +} diff --git a/modules/beta-private-cluster/sa.tf b/modules/beta-private-cluster/sa.tf index 6e3593141..6b79badb2 100644 --- a/modules/beta-private-cluster/sa.tf +++ b/modules/beta-private-cluster/sa.tf @@ -76,3 +76,9 @@ resource "google_project_iam_member" "cluster_service_account-gcr" { member = "serviceAccount:${google_service_account.cluster_service_account[0].email}" } +resource "google_project_iam_member" "cluster_service_account-artifact-registry" { + count = var.create_service_account && var.grant_registry_access ? 1 : 0 + project = var.registry_project_id == "" ? var.project_id : var.registry_project_id + role = "roles/artifactregistry.reader" + member = "serviceAccount:${google_service_account.cluster_service_account[0].email}" +} diff --git a/modules/beta-public-cluster-update-variant/sa.tf b/modules/beta-public-cluster-update-variant/sa.tf index 6e3593141..6b79badb2 100644 --- a/modules/beta-public-cluster-update-variant/sa.tf +++ b/modules/beta-public-cluster-update-variant/sa.tf @@ -76,3 +76,9 @@ resource "google_project_iam_member" "cluster_service_account-gcr" { member = "serviceAccount:${google_service_account.cluster_service_account[0].email}" } +resource "google_project_iam_member" "cluster_service_account-artifact-registry" { + count = var.create_service_account && var.grant_registry_access ? 1 : 0 + project = var.registry_project_id == "" ? var.project_id : var.registry_project_id + role = "roles/artifactregistry.reader" + member = "serviceAccount:${google_service_account.cluster_service_account[0].email}" +} diff --git a/modules/beta-public-cluster/sa.tf b/modules/beta-public-cluster/sa.tf index 6e3593141..6b79badb2 100644 --- a/modules/beta-public-cluster/sa.tf +++ b/modules/beta-public-cluster/sa.tf @@ -76,3 +76,9 @@ resource "google_project_iam_member" "cluster_service_account-gcr" { member = "serviceAccount:${google_service_account.cluster_service_account[0].email}" } +resource "google_project_iam_member" "cluster_service_account-artifact-registry" { + count = var.create_service_account && var.grant_registry_access ? 1 : 0 + project = var.registry_project_id == "" ? var.project_id : var.registry_project_id + role = "roles/artifactregistry.reader" + member = "serviceAccount:${google_service_account.cluster_service_account[0].email}" +} diff --git a/modules/private-cluster-update-variant/sa.tf b/modules/private-cluster-update-variant/sa.tf index 6e3593141..6b79badb2 100644 --- a/modules/private-cluster-update-variant/sa.tf +++ b/modules/private-cluster-update-variant/sa.tf @@ -76,3 +76,9 @@ resource "google_project_iam_member" "cluster_service_account-gcr" { member = "serviceAccount:${google_service_account.cluster_service_account[0].email}" } +resource "google_project_iam_member" "cluster_service_account-artifact-registry" { + count = var.create_service_account && var.grant_registry_access ? 1 : 0 + project = var.registry_project_id == "" ? var.project_id : var.registry_project_id + role = "roles/artifactregistry.reader" + member = "serviceAccount:${google_service_account.cluster_service_account[0].email}" +} diff --git a/modules/private-cluster/sa.tf b/modules/private-cluster/sa.tf index 6e3593141..6b79badb2 100644 --- a/modules/private-cluster/sa.tf +++ b/modules/private-cluster/sa.tf @@ -76,3 +76,9 @@ resource "google_project_iam_member" "cluster_service_account-gcr" { member = "serviceAccount:${google_service_account.cluster_service_account[0].email}" } +resource "google_project_iam_member" "cluster_service_account-artifact-registry" { + count = var.create_service_account && var.grant_registry_access ? 1 : 0 + project = var.registry_project_id == "" ? var.project_id : var.registry_project_id + role = "roles/artifactregistry.reader" + member = "serviceAccount:${google_service_account.cluster_service_account[0].email}" +} diff --git a/sa.tf b/sa.tf index 6e3593141..6b79badb2 100644 --- a/sa.tf +++ b/sa.tf @@ -76,3 +76,9 @@ resource "google_project_iam_member" "cluster_service_account-gcr" { member = "serviceAccount:${google_service_account.cluster_service_account[0].email}" } +resource "google_project_iam_member" "cluster_service_account-artifact-registry" { + count = var.create_service_account && var.grant_registry_access ? 1 : 0 + project = var.registry_project_id == "" ? var.project_id : var.registry_project_id + role = "roles/artifactregistry.reader" + member = "serviceAccount:${google_service_account.cluster_service_account[0].email}" +}