generated from getindata/terraform-module-template
-
Notifications
You must be signed in to change notification settings - Fork 0
/
locals.tf
59 lines (52 loc) · 1.57 KB
/
locals.tf
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
locals {
context_template = lookup(var.context_templates, var.name_scheme.context_template_name, null)
default_role_naming_scheme = {
properties = ["prefix", "environment", "resource-monitor", "name"]
context_template_name = "snowflake-resource-monitor-role"
extra_values = {
prefix = "rmn"
resource-monitor = var.name
}
}
default_roles_definition = {
readonly = {
resource_monitor_grants = {
privileges = ["MONITOR"]
with_grant_option = false
all_privileges = null
}
}
admin = {
resource_monitor_grants = {
privileges = null
with_grant_option = false
all_privileges = true
}
}
}
provided_roles = { for role_name, role in var.roles : role_name => {
for k, v in role : k => v
if v != null
} }
roles_definition = module.roles_deep_merge.merged
default_roles = {
for role_name, role in local.roles_definition : role_name => role
if contains(keys(local.default_roles_definition), role_name) && var.create_default_roles
}
custom_roles = {
for role_name, role in local.roles_definition : role_name => role
if !contains(keys(local.default_roles_definition), role_name)
}
roles = {
for role_name, role in merge(
module.snowflake_default_role,
module.snowflake_custom_role
) : role_name => role
if role_name != null
}
}
module "roles_deep_merge" {
source = "Invicton-Labs/deepmerge/null"
version = "0.1.5"
maps = [local.default_roles_definition, local.provided_roles]
}