Skip to content

Commit

Permalink
Fix hidden transfer SA definition
Browse files Browse the repository at this point in the history
  • Loading branch information
athornton committed Feb 28, 2024
1 parent 3629dd1 commit 891e70a
Showing 1 changed file with 3 additions and 3 deletions.
6 changes: 3 additions & 3 deletions environment/deployments/roundtable/main.tf
Original file line number Diff line number Diff line change
Expand Up @@ -150,19 +150,19 @@ data "google_storage_transfer_project_service_account" "vault_backup_transfer_sa
resource "google_storage_bucket_iam_member" "vault_server_storage_transfer_source_sa" {
bucket = module.storage_bucket.name
role = "roles/storage.objectViewer"
member = "serviceAccount:${data.google_storage_transfer_project_service_account.vault_backup_transfer_sa}.iam.gserviceaccount.com"
member = "serviceAccount:${data.google_storage_transfer_project_service_account.vault_backup_transfer_sa.email}"
}

resource "google_storage_bucket_iam_member" "vault_server_storage_transfer_source_sa_r" {
bucket = module.storage_bucket.name
role = "roles/storage.legacyBucketReader"
member = "serviceAccount:${data.google_storage_transfer_project_service_account.vault_backup_transfer_sa}.iam.gserviceaccount.com"
member = "serviceAccount:${data.google_storage_transfer_project_service_account.vault_backup_transfer_sa.email}"
}

resource "google_storage_bucket_iam_member" "vault_server_storage_transfer_sink_sa" {
bucket = module.storage_bucket_b.name
role = "roles/storage.legacyBucketWriter"
member = "serviceAccount:${data.google_storage_transfer_project_service_account.vault_backup_transfer_sa}.iam.gserviceaccount.com"
member = "serviceAccount:${data.google_storage_transfer_project_service_account.vault_backup_transfer_sa.email}"
}

resource "google_storage_bucket_iam_member" "vault_server_storage_transfer_sink_sa_r" {
Expand Down

0 comments on commit 891e70a

Please sign in to comment.