2025-12-03 16:12:20 +00:00
|
|
|
resource "google_service_account" "terraform_sa" {
|
2025-12-04 09:06:11 +01:00
|
|
|
account_id = "${var.projet_main}-tf-sa"
|
|
|
|
|
project = var.projet_main
|
2025-12-03 16:12:20 +00:00
|
|
|
display_name = "Terraform service account for ${var.project}"
|
|
|
|
|
}
|
|
|
|
|
|
|
|
|
|
resource "google_project_iam_member" "sa_compute_admin" {
|
2025-12-04 09:06:11 +01:00
|
|
|
project = var.projet_main
|
2025-12-03 16:12:20 +00:00
|
|
|
role = "roles/compute.instanceAdmin.v1"
|
|
|
|
|
member = "serviceAccount:${google_service_account.terraform_sa.email}"
|
|
|
|
|
}
|
|
|
|
|
|
|
|
|
|
resource "google_project_iam_member" "sa_os_login" {
|
2025-12-04 09:06:11 +01:00
|
|
|
project = var.projet_main
|
2025-12-03 16:12:20 +00:00
|
|
|
role = "roles/compute.osLogin"
|
|
|
|
|
member = "serviceAccount:${google_service_account.terraform_sa.email}"
|
|
|
|
|
}
|
|
|
|
|
|
|
|
|
|
resource "google_service_account_key" "terraform_sa_key" {
|
|
|
|
|
service_account_id = google_service_account.terraform_sa.name
|
|
|
|
|
}
|
|
|
|
|
|
|
|
|
|
resource "google_project_metadata" "oslogin" {
|
2025-12-04 09:06:11 +01:00
|
|
|
project = var.projet_main
|
2025-12-03 16:12:20 +00:00
|
|
|
metadata = {
|
|
|
|
|
enable-oslogin = "TRUE"
|
|
|
|
|
}
|
|
|
|
|
}
|