member variables
tejeshnandyala opened this issue · 3 comments
is group really supported based on below
variable "members" {
description = "List of members in the standard GCP form: user:{email}, serviceAccount:{email}, group:{email}"
type = list(string)
default = []
}
Yes you can provide a group in the form group:{email}
https://cloud.google.com/access-context-manager/docs/access-level-attributes
The documentation from google here says group is not allowed :)
also i see below error when i add groups
googleapi: Error 400: AccessLevel definition has a 'member' field starting with 'group:'. Groups are not supported.
@tejeshnandyala I assumed you were talking about this variable in the example
Which is actually used by the bastion host module
terraform-google-vpc-service-controls/examples/bq-exfil-demo/main.tf
Lines 22 to 28 in 54ee979
and not with access level
terraform-google-vpc-service-controls/examples/bq-exfil-demo/org.tf
Lines 43 to 49 in 54ee979
Did you run into an issue running this example?
In our access lvl module we do specify only user/sa email