We read every piece of feedback, and take your input very seriously.
To see all available qualifiers, see our documentation.
1 parent c453f1f commit b08e07bCopy full SHA for b08e07b
1 file changed
gcp/tf/invoker.tf
@@ -22,3 +22,12 @@ resource "google_service_account_iam_binding" "invoker_impersonators" {
22
role = "roles/iam.serviceAccountTokenCreator"
23
members = ["serviceAccount:${each.value}"]
24
}
25
+
26
+// Allow agents to create open id token
27
+resource "google_service_account_iam_binding" "invoker_idtoken" {
28
+ for_each = var.invoker_impersonators
29
30
+ service_account_id = google_service_account.invoker.id
31
+ role = "roles/iam.serviceAccountOpenIdTokenCreator"
32
+ members = ["serviceAccount:${each.value}"]
33
+}
0 commit comments