From 5527d753c0df415c6c1491edc7a21e2dfc80455f Mon Sep 17 00:00:00 2001 From: dick Date: Thu, 4 Dec 2025 10:15:25 +0100 Subject: [PATCH] iam debut --- terraform/environments/dev/main.tf | 6 ++++++ terraform/modules/iam/main.tf | 25 +++++++++++++++++++++++++ terraform/modules/iam/outputs.tf | 8 ++++++++ terraform/modules/iam/variables.tf | 8 ++++++++ 4 files changed, 47 insertions(+) diff --git a/terraform/environments/dev/main.tf b/terraform/environments/dev/main.tf index bed3a53..1c99f9c 100644 --- a/terraform/environments/dev/main.tf +++ b/terraform/environments/dev/main.tf @@ -34,3 +34,9 @@ module "compute" { backend_subnet_id = module.network.subnet_ids["backend"] database_subnet_id = module.network.subnet_ids["database"] } + +module "iam" { + source = "../../modules/iam" + project_id = var.project_id + ssh_public_key_path = "/home/adriendick18/.ssh/id_ed25519.pub" +} diff --git a/terraform/modules/iam/main.tf b/terraform/modules/iam/main.tf index e69de29..812790d 100644 --- a/terraform/modules/iam/main.tf +++ b/terraform/modules/iam/main.tf @@ -0,0 +1,25 @@ +resource "google_service_account" "terraform_sa" { + account_id = "terraform" + display_name = "Service Account Terraform" +} + +resource "google_service_account_key" "terraform_sa_key" { + service_account_id = google_service_account.terraform_sa.name + public_key_type = "TYPE_X509_PEM_FILE" +} + +resource "google_project_iam_binding" "terraform_sa_viewer" { + project = var.project_id + role = "roles/viewer" + + members = [ + "serviceAccount:${google_service_account.terraform_sa.email}" + ] +} + +data "google_client_openid_userinfo" "me" {} + +resource "google_os_login_ssh_public_key" "me_ssh_key" { + user = data.google_client_openid_userinfo.me.email + key = file(var.ssh_public_key_path) +} diff --git a/terraform/modules/iam/outputs.tf b/terraform/modules/iam/outputs.tf index e69de29..ee51f64 100644 --- a/terraform/modules/iam/outputs.tf +++ b/terraform/modules/iam/outputs.tf @@ -0,0 +1,8 @@ +output "service_account_email" { + value = google_service_account.terraform_sa.email +} + +output "service_account_key" { + value = google_service_account_key.terraform_sa_key.private_key + sensitive = true +} diff --git a/terraform/modules/iam/variables.tf b/terraform/modules/iam/variables.tf index e69de29..e88ddbb 100644 --- a/terraform/modules/iam/variables.tf +++ b/terraform/modules/iam/variables.tf @@ -0,0 +1,8 @@ +variable "project_id" { + type = string +} + +variable "ssh_public_key_path" { + type = string + description = "Chemin vers la clé publique SSH" +}