terraform-google-modules/terraform-google-bootstrap

cloudbuild_enabled: user does not have impersonation permission on the trigger service account specified

apeabody opened this issue · 1 comments

TL;DR

During int test for cloudbuild_enabled: user does not have impersonation permission on the trigger service account specified

Expected behavior

No response

Observed behavior

       
         with module.cloudbuild_enabled.module.cloudbuild_bootstrap.google_cloudbuild_trigger.main_trigger["gcp-networks"],
         on ../../../modules/cloudbuild/main.tf line 181, in resource "google_cloudbuild_trigger" "main_trigger":
        181: resource "google_cloudbuild_trigger" "main_trigger" {
       
       
       Error: Error creating Trigger: googleapi: Error 403: generic::permission_denied: user does not have impersonation permission on the trigger service account specified: projects/cft-test-cb-seed-0905/serviceAccounts/org-terraform@cft-test-cb-seed-0905.iam.gserviceaccount.com
       
         with module.cloudbuild_enabled.module.cloudbuild_bootstrap.google_cloudbuild_trigger.main_trigger["gcp-org"],
         on ../../../modules/cloudbuild/main.tf line 181, in resource "google_cloudbuild_trigger" "main_trigger":
        181: resource "google_cloudbuild_trigger" "main_trigger" {
       
       
       Error: Error creating Trigger: googleapi: Error 403: generic::permission_denied: user does not have impersonation permission on the trigger service account specified: projects/cft-test-cb-seed-0905/serviceAccounts/org-terraform@cft-test-cb-seed-0905.iam.gserviceaccount.com
       
         with module.cloudbuild_enabled.module.cloudbuild_bootstrap.google_cloudbuild_trigger.main_trigger["gcp-projects"],
         on ../../../modules/cloudbuild/main.tf line 181, in resource "google_cloudbuild_trigger" "main_trigger":
        181: resource "google_cloudbuild_trigger" "main_trigger" {
       
       
       Error: Error creating Trigger: googleapi: Error 403: generic::permission_denied: user does not have impersonation permission on the trigger service account specified: projects/cft-test-cb-seed-0905/serviceAccounts/org-terraform@cft-test-cb-seed-0905.iam.gserviceaccount.com
       
         with module.cloudbuild_enabled.module.cloudbuild_bootstrap.google_cloudbuild_trigger.non_main_trigger["gcp-networks"],
         on ../../../modules/cloudbuild/main.tf line 216, in resource "google_cloudbuild_trigger" "non_main_trigger":
        216: resource "google_cloudbuild_trigger" "non_main_trigger" {
       
       
       Error: Error creating Trigger: googleapi: Error 403: generic::permission_denied: user does not have impersonation permission on the trigger service account specified: projects/cft-test-cb-seed-0905/serviceAccounts/org-terraform@cft-test-cb-seed-0905.iam.gserviceaccount.com
       
         with module.cloudbuild_enabled.module.cloudbuild_bootstrap.google_cloudbuild_trigger.non_main_trigger["gcp-projects"],
         on ../../../modules/cloudbuild/main.tf line 216, in resource "google_cloudbuild_trigger" "non_main_trigger":
        216: resource "google_cloudbuild_trigger" "non_main_trigger" {
       
       
       Error: Error creating Trigger: googleapi: Error 403: generic::permission_denied: user does not have impersonation permission on the trigger service account specified: projects/cft-test-cb-seed-0905/serviceAccounts/org-terraform@cft-test-cb-seed-0905.iam.gserviceaccount.com
       
         with module.cloudbuild_enabled.module.cloudbuild_bootstrap.google_cloudbuild_trigger.non_main_trigger["gcp-org"],
         on ../../../modules/cloudbuild/main.tf line 216, in resource "google_cloudbuild_trigger" "non_main_trigger":
        216: resource "google_cloudbuild_trigger" "non_main_trigger" {

Terraform Configuration

int test

Terraform Version

Terraform v1.2.4
       + provider registry.terraform.io/hashicorp/google v4.27.0
       + provider registry.terraform.io/hashicorp/google-beta v4.27.0
       + provider registry.terraform.io/hashicorp/null v2.1.2
       + provider registry.terraform.io/hashicorp/random v2.3.1
       + provider registry.terraform.io/hashicorp/time v0.7.2

Additional information

No response

Appears to have been transitory.