Skip to content

Commit 7300458

Browse files
Update GCP SA roles to allow listing clusters/instances for CIEM at Org level (#9)
1 parent fdd9fb7 commit 7300458

File tree

1 file changed

+1
-1
lines changed

1 file changed

+1
-1
lines changed

modules/services/service-principal/organizational.tf

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -37,7 +37,7 @@ resource "google_organization_iam_member" "cloudasset_viewer" {
3737
# role permissions for CIEM (GCP Predefined Roles for Sysdig Cloud Identity Management)
3838
#---------------------------------------------------------------------------------------
3939
resource "google_organization_iam_member" "identity_mgmt" {
40-
for_each = var.is_organizational ? toset(["roles/recommender.viewer", "roles/iam.serviceAccountViewer", "roles/iam.organizationRoleViewer"]) : []
40+
for_each = var.is_organizational ? toset(["roles/recommender.viewer", "roles/iam.serviceAccountViewer", "roles/iam.organizationRoleViewer", "roles/container.clusterViewer", "roles/compute.viewer"]) : []
4141

4242
org_id = data.google_organization.org[0].org_id
4343
role = each.key

0 commit comments

Comments
 (0)