50 lines
1.6 KiB
YAML
50 lines
1.6 KiB
YAML
# Copyright 2025 Google LLC
|
|
#
|
|
# Licensed under the Apache License, Version 2.0 (the "License");
|
|
# you may not use this file except in compliance with the License.
|
|
# You may obtain a copy of the License at
|
|
#
|
|
# http://www.apache.org/licenses/LICENSE-2.0
|
|
#
|
|
# Unless required by applicable law or agreed to in writing, software
|
|
# distributed under the License is distributed on an "AS IS" BASIS,
|
|
# WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
|
|
# See the License for the specific language governing permissions and
|
|
# limitations under the License.
|
|
|
|
# yaml-language-server: $schema=../../../schemas/project.schema.json
|
|
|
|
parent: $folder_ids:applications/dev
|
|
iam_by_principals:
|
|
$iam_principals:app0-devs:
|
|
- roles/viewer
|
|
iam_bindings_additive:
|
|
vm_default_logging:
|
|
member: $iam_principals:service_accounts/dev-app0-be-0/vm-default
|
|
role: roles/logging.logWriter
|
|
vm_default_monitoring:
|
|
member: $iam_principals:service_accounts/dev-app0-be-0/vm-default
|
|
role: roles/monitoring.metricWriter
|
|
service_accounts:
|
|
vm-default:
|
|
display_name: VM default service account.
|
|
services:
|
|
- compute.googleapis.com
|
|
- logging.googleapis.com
|
|
- monitoring.googleapis.com
|
|
shared_vpc_service_config:
|
|
host_project: $project_ids:dev-net-spoke-0
|
|
service_agent_iam:
|
|
roles/compute.networkUser:
|
|
- $service_agents:compute
|
|
automation:
|
|
project: $project_ids:prod-iac-core-0
|
|
bucket:
|
|
name: tf-state
|
|
service_accounts:
|
|
ro: {}
|
|
rw:
|
|
iam_sa_roles:
|
|
$service_account_ids:dev-app0-be-0/automation/ro:
|
|
- roles.iam.serviceAccountTokenCreator
|