Remove Netsec Authz Service Agent (#3445)

* Remove Netsec Authz Service Agent

* fix tests
This commit is contained in:
Julio Castillo
2025-10-20 21:36:03 +02:00
committed by GitHub
parent 0faaba4e45
commit 792003ff97
16 changed files with 29 additions and 36 deletions

View File

@@ -54,4 +54,4 @@ module "recipe_apigee_swp" {
subnet_proxy_only_ip_cidr_range = "10.16.2.0/24" subnet_proxy_only_ip_cidr_range = "10.16.2.0/24"
} }
} }
# tftest modules=10 resources=44 # tftest modules=10 resources=43

View File

@@ -1163,13 +1163,6 @@
role: null role: null
is_primary: true is_primary: true
aliases: [] aliases: []
- name: ns-authz
display_name: Google Cloud Network Security Authz Service Account
api: networksecurity.googleapis.com
identity: service-${project_number}@gcp-sa-ns-authz.${universe_domain}iam.gserviceaccount.com
role: roles/networksecurity.authzServiceAgent
is_primary: false
aliases: []
- name: osconfig-rollout - name: osconfig-rollout
display_name: Google Cloud OS Config Rollout Service Agent display_name: Google Cloud OS Config Rollout Service Agent
api: osconfig.googleapis.com api: osconfig.googleapis.com

View File

@@ -2776,7 +2776,7 @@ counts:
google_organization_iam_custom_role: 7 google_organization_iam_custom_role: 7
google_project: 3 google_project: 3
google_project_iam_binding: 16 google_project_iam_binding: 16
google_project_iam_member: 18 google_project_iam_member: 17
google_project_service: 33 google_project_service: 33
google_project_service_identity: 9 google_project_service_identity: 9
google_service_account: 16 google_service_account: 16
@@ -2793,5 +2793,5 @@ counts:
google_tags_tag_value_iam_binding: 4 google_tags_tag_value_iam_binding: 4
local_file: 9 local_file: 9
modules: 46 modules: 46
resources: 311 resources: 310
terraform_data: 2 terraform_data: 2

View File

@@ -36,10 +36,10 @@ counts:
google_network_connectivity_spoke: 2 google_network_connectivity_spoke: 2
google_project: 3 google_project: 3
google_project_iam_binding: 2 google_project_iam_binding: 2
google_project_iam_member: 24 google_project_iam_member: 22
google_project_service: 28 google_project_service: 28
google_project_service_identity: 22 google_project_service_identity: 22
google_storage_bucket_object: 2 google_storage_bucket_object: 2
google_tags_tag_binding: 3 google_tags_tag_binding: 3
modules: 23 modules: 23
resources: 191 resources: 189

View File

@@ -40,11 +40,11 @@ counts:
google_monitoring_monitored_project: 2 google_monitoring_monitored_project: 2
google_project: 3 google_project: 3
google_project_iam_binding: 2 google_project_iam_binding: 2
google_project_iam_member: 24 google_project_iam_member: 22
google_project_service: 28 google_project_service: 28
google_project_service_identity: 22 google_project_service_identity: 22
google_storage_bucket_object: 2 google_storage_bucket_object: 2
google_tags_tag_binding: 3 google_tags_tag_binding: 3
modules: 28 modules: 28
random_id: 3 random_id: 3
resources: 208 resources: 206

View File

@@ -38,11 +38,11 @@ counts:
google_monitoring_monitored_project: 2 google_monitoring_monitored_project: 2
google_project: 3 google_project: 3
google_project_iam_binding: 2 google_project_iam_binding: 2
google_project_iam_member: 24 google_project_iam_member: 22
google_project_service: 28 google_project_service: 28
google_project_service_identity: 22 google_project_service_identity: 22
google_storage_bucket_object: 2 google_storage_bucket_object: 2
google_tags_tag_binding: 3 google_tags_tag_binding: 3
modules: 30 modules: 30
random_id: 17 random_id: 17
resources: 255 resources: 253

View File

@@ -43,11 +43,11 @@ counts:
google_network_connectivity_spoke: 4 google_network_connectivity_spoke: 4
google_project: 3 google_project: 3
google_project_iam_binding: 2 google_project_iam_binding: 2
google_project_iam_member: 24 google_project_iam_member: 22
google_project_service: 28 google_project_service: 28
google_project_service_identity: 22 google_project_service_identity: 22
google_storage_bucket_object: 2 google_storage_bucket_object: 2
google_tags_tag_binding: 3 google_tags_tag_binding: 3
modules: 38 modules: 38
random_id: 6 random_id: 6
resources: 275 resources: 273

View File

@@ -45,11 +45,11 @@ counts:
google_monitoring_monitored_project: 2 google_monitoring_monitored_project: 2
google_project: 3 google_project: 3
google_project_iam_binding: 2 google_project_iam_binding: 2
google_project_iam_member: 24 google_project_iam_member: 22
google_project_service: 28 google_project_service: 28
google_project_service_identity: 22 google_project_service_identity: 22
google_storage_bucket_object: 2 google_storage_bucket_object: 2
google_tags_tag_binding: 3 google_tags_tag_binding: 3
modules: 46 modules: 46
random_id: 6 random_id: 6
resources: 285 resources: 283

View File

@@ -45,11 +45,11 @@ counts:
google_monitoring_monitored_project: 2 google_monitoring_monitored_project: 2
google_project: 3 google_project: 3
google_project_iam_binding: 2 google_project_iam_binding: 2
google_project_iam_member: 24 google_project_iam_member: 22
google_project_service: 28 google_project_service: 28
google_project_service_identity: 22 google_project_service_identity: 22
google_storage_bucket_object: 2 google_storage_bucket_object: 2
google_tags_tag_binding: 3 google_tags_tag_binding: 3
modules: 42 modules: 42
random_id: 6 random_id: 6
resources: 261 resources: 259

View File

@@ -38,11 +38,11 @@ counts:
google_monitoring_dashboard: 6 google_monitoring_dashboard: 6
google_project: 2 google_project: 2
google_project_iam_binding: 2 google_project_iam_binding: 2
google_project_iam_member: 20 google_project_iam_member: 18
google_project_service: 22 google_project_service: 22
google_project_service_identity: 18 google_project_service_identity: 18
google_storage_bucket_object: 2 google_storage_bucket_object: 2
google_tags_tag_binding: 2 google_tags_tag_binding: 2
modules: 23 modules: 23
random_id: 6 random_id: 6
resources: 233 resources: 231

View File

@@ -32,9 +32,9 @@ counts:
google_network_connectivity_hub: 1 google_network_connectivity_hub: 1
google_network_connectivity_spoke: 3 google_network_connectivity_spoke: 3
google_project: 3 google_project: 3
google_project_iam_member: 24 google_project_iam_member: 21
google_project_service: 27 google_project_service: 27
google_project_service_identity: 21 google_project_service_identity: 21
modules: 17 modules: 17
random_id: 3 random_id: 3
resources: 139 resources: 136

View File

@@ -14,8 +14,8 @@
counts: counts:
google_project: 3 google_project: 3
google_project_iam_member: 24 google_project_iam_member: 21
google_project_service: 27 google_project_service: 27
google_project_service_identity: 21 google_project_service_identity: 21
modules: 3 modules: 3
resources: 75 resources: 72

View File

@@ -30,9 +30,9 @@ counts:
google_dns_policy: 4 google_dns_policy: 4
google_dns_record_set: 1 google_dns_record_set: 1
google_project: 3 google_project: 3
google_project_iam_member: 24 google_project_iam_member: 21
google_project_service: 27 google_project_service: 27
google_project_service_identity: 21 google_project_service_identity: 21
modules: 18 modules: 18
random_id: 3 random_id: 3
resources: 142 resources: 139

View File

@@ -27,9 +27,9 @@ counts:
google_compute_vpn_tunnel: 2 google_compute_vpn_tunnel: 2
google_dns_policy: 2 google_dns_policy: 2
google_project: 3 google_project: 3
google_project_iam_member: 24 google_project_iam_member: 21
google_project_service: 27 google_project_service: 27
google_project_service_identity: 21 google_project_service_identity: 21
modules: 11 modules: 11
random_id: 4 random_id: 4
resources: 117 resources: 114

View File

@@ -29,9 +29,9 @@ counts:
google_dns_policy: 4 google_dns_policy: 4
google_dns_record_set: 1 google_dns_record_set: 1
google_project: 3 google_project: 3
google_project_iam_member: 24 google_project_iam_member: 21
google_project_service: 27 google_project_service: 27
google_project_service_identity: 21 google_project_service_identity: 21
modules: 22 modules: 22
random_id: 15 random_id: 15
resources: 178 resources: 175

View File

@@ -54,8 +54,8 @@ ALIASES = {
} }
IGNORED_AGENTS = [ IGNORED_AGENTS = [
# Alloydb has two agents. Ignore the non-primary one # gcp-sa-ns-authz agent gets created on first create op
'c-PROJECT_NUMBER-IDENTIFIER@gcp-sa-alloydb.iam.gserviceaccount.com' 'service-PROJECT_NUMBER@gcp-sa-ns-authz.iam.gserviceaccount.com'
] ]
AGENT_NAME_OVERRIDE = { AGENT_NAME_OVERRIDE = {