@@ -5,6 +5,10 @@ projects = {
5
5
project_id = " mvnjri-prod"
6
6
env = " prod"
7
7
service_accounts = {
8
+ sa-pam-enabler = {
9
+ roles = [" projects/mvnjri-prod/roles/rolecdcloudrun" , " roles/cloudsql.admin" , " roles/iam.serviceAccountAdmin" , " roles/cloudfunctions.invoker" , " roles/resourcemanager.projectIamAdmin" , " roles/cloudbuild.builds.builder" ]
10
+ description = " Service Account for running PAM entitlement grant cloud functions"
11
+ },
8
12
sa-pubsub = {
9
13
roles = [" roles/iam.serviceAccountTokenCreator" , " roles/pubsub.publisher" , " roles/pubsub.subscriber" ]
10
14
description = " Service Account for running pubsub services"
@@ -65,6 +69,10 @@ projects = {
65
69
project_id = " c4hnrd-prod"
66
70
env = " prod"
67
71
service_accounts = {
72
+ sa-pam-enabler = {
73
+ roles = [" projects/c4hnrd-prod/roles/rolecdcloudrun" , " roles/cloudsql.admin" , " roles/iam.serviceAccountAdmin" , " roles/cloudfunctions.invoker" , " roles/resourcemanager.projectIamAdmin" , " roles/cloudbuild.builds.builder" ]
74
+ description = " Service Account for running PAM entitlement grant cloud functions"
75
+ },
68
76
sa-pubsub = {
69
77
roles = [" projects/c4hnrd-prod/roles/rolequeue" , " roles/iam.serviceAccountTokenCreator" , " roles/pubsub.publisher" , " roles/pubsub.subscriber" , " roles/run.invoker" ]
70
78
description = " Service Account for running pubsub services"
@@ -118,6 +126,10 @@ projects = {
118
126
project_id = " gtksf3-prod"
119
127
env = " prod"
120
128
service_accounts = {
129
+ sa-pam-enabler = {
130
+ roles = [" projects/gtksf3-prod/roles/rolecdcloudrun" , " roles/cloudsql.admin" , " roles/iam.serviceAccountAdmin" , " roles/cloudfunctions.invoker" , " roles/resourcemanager.projectIamAdmin" , " roles/cloudbuild.builds.builder" ]
131
+ description = " Service Account for running PAM entitlement grant cloud functions"
132
+ },
121
133
sa-pubsub = {
122
134
roles = [" roles/iam.serviceAccountTokenCreator" , " roles/pubsub.publisher" , " roles/pubsub.subscriber" , " roles/run.invoker" ]
123
135
description = " Service Account for running pubsub services"
@@ -154,6 +166,10 @@ projects = {
154
166
project_id = " yfjq17-prod"
155
167
env = " prod"
156
168
service_accounts = {
169
+ sa-pam-enabler = {
170
+ roles = [" projects/yfjq17-prod/roles/rolecdcloudrun" , " roles/cloudsql.admin" , " roles/iam.serviceAccountAdmin" , " roles/cloudfunctions.invoker" , " roles/resourcemanager.projectIamAdmin" , " roles/cloudbuild.builds.builder" ]
171
+ description = " Service Account for running PAM entitlement grant cloud functions"
172
+ },
157
173
sa-pubsub = {
158
174
roles = [" roles/iam.serviceAccountTokenCreator" , " roles/pubsub.publisher" , " roles/pubsub.subscriber" ]
159
175
description = " Service Account for running pubsub services"
@@ -176,6 +192,10 @@ projects = {
176
192
project_id = " a083gt-prod"
177
193
env = " prod"
178
194
service_accounts = {
195
+ sa-pam-enabler = {
196
+ roles = [" projects/a083gt-prod/roles/rolecdcloudrun" , " roles/cloudsql.admin" , " roles/iam.serviceAccountAdmin" , " roles/cloudfunctions.invoker" , " roles/resourcemanager.projectIamAdmin" , " roles/cloudbuild.builds.builder" ]
197
+ description = " Service Account for running PAM entitlement grant cloud functions"
198
+ },
179
199
sa-pubsub = {
180
200
roles = [" roles/iam.serviceAccountTokenCreator" , " roles/pubsub.publisher" , " roles/pubsub.subscriber" , " roles/run.invoker" ]
181
201
description = " Service Account for running pubsub services"
@@ -236,6 +256,10 @@ projects = {
236
256
project_id = " keee67-prod"
237
257
env = " prod"
238
258
service_accounts = {
259
+ sa-pam-enabler = {
260
+ roles = [" projects/keee67-prod/roles/rolecdcloudrun" , " roles/cloudsql.admin" , " roles/iam.serviceAccountAdmin" , " roles/cloudfunctions.invoker" , " roles/resourcemanager.projectIamAdmin" , " roles/cloudbuild.builds.builder" ]
261
+ description = " Service Account for running PAM entitlement grant cloud functions"
262
+ },
239
263
bn-tasks-run-invoker-prod = {
240
264
roles = [" roles/editor" , " roles/iam.serviceAccountUser" ]
241
265
description = " "
@@ -264,6 +288,10 @@ projects = {
264
288
project_id = " eogruh-prod"
265
289
env = " prod"
266
290
service_accounts = {
291
+ sa-pam-enabler = {
292
+ roles = [" projects/eogruh-prod/roles/rolecdcloudrun" , " roles/cloudsql.admin" , " roles/iam.serviceAccountAdmin" , " roles/cloudfunctions.invoker" , " roles/resourcemanager.projectIamAdmin" , " roles/cloudbuild.builds.builder" ]
293
+ description = " Service Account for running PAM entitlement grant cloud functions"
294
+ },
267
295
sa-pubsub = {
268
296
roles = [" roles/iam.serviceAccountTokenCreator" , " roles/pubsub.publisher" , " roles/pubsub.subscriber" ]
269
297
description = " Service Account for running pubsub services"
@@ -331,6 +359,10 @@ projects = {
331
359
project_id = " k973yf-prod"
332
360
env = " prod"
333
361
service_accounts = {
362
+ sa-pam-enabler = {
363
+ roles = [" projects/k973yf-prod/roles/rolecdcloudrun" , " roles/cloudsql.admin" , " roles/iam.serviceAccountAdmin" , " roles/cloudfunctions.invoker" , " roles/resourcemanager.projectIamAdmin" , " roles/cloudbuild.builds.builder" ]
364
+ description = " Service Account for running PAM entitlement grant cloud functions"
365
+ },
334
366
sa-pubsub = {
335
367
roles = [" roles/iam.serviceAccountTokenCreator" , " roles/pubsub.publisher" , " roles/pubsub.subscriber" ]
336
368
description = " Service Account for running pubsub services"
0 commit comments