Skip to content

Commit b794b62

Browse files
committed
Update some IAM roles
1 parent f1fda4e commit b794b62

File tree

1 file changed

+8
-4
lines changed

1 file changed

+8
-4
lines changed

tf/iam.tf

+8-4
Original file line numberDiff line numberDiff line change
@@ -17,10 +17,14 @@ resource "google_service_account" "circleci_deployer" {
1717

1818
resource "google_project_iam_custom_role" "circleci-deployment-role" {
1919
description = "CircleCI deployment role"
20-
permissions = ["artifactregistry.repositories.uploadArtifacts"] // Just give it a very small permission
21-
project = "darklang-next"
22-
role_id = "circleciDeploymentRole"
23-
title = "CircleCI deployment role"
20+
permissions = [
21+
"artifactregistry.repositories.uploadArtifacts",
22+
"run.services.get",
23+
"run.services.update"
24+
]
25+
project = "darklang-next"
26+
role_id = "circleciDeploymentRole"
27+
title = "CircleCI deployment role"
2428
}
2529

2630
# resource "google_project_iam_member" "circleci_deployer_member_object_viewer" {

0 commit comments

Comments
 (0)