* Introduce iam_by_principals_conditional * Add iam_by_principals_conditional to project factory * Update IAM ADR * Update project factory readme * Sync FAST schemas * Update organization schema * Add resman tests for iam_by_principals_conditional * Update PF project-defaults.tf * Update copyright
13 lines
368 B
HCL
13 lines
368 B
HCL
parent = "organizations/12345678"
|
|
name = "folder-a"
|
|
iam_by_principals_conditional = {
|
|
"user:one@example.com" = {
|
|
roles = ["roles/owner", "roles/viewer"]
|
|
condition = {
|
|
title = "expires_after_2024_12_31"
|
|
description = "Expiring at midnight of 2024-12-31"
|
|
expression = "request.time < timestamp(\"2025-01-01T00:00:00Z\")"
|
|
}
|
|
}
|
|
}
|