You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Please vote on this issue by adding a 馃憤 reaction to the original issue to help the community and maintainers prioritize this request.
Please do not leave +1 or me too comments, they generate extra noise for issue followers and do not help prioritize the request.
If you are interested in working on this issue or have submitted a pull request, please leave a comment.
If an issue is assigned to the modular-magician user, it is either in the process of being autogenerated, or is planned to be autogenerated soon. If an issue is assigned to a user, that user is claiming responsibility for the issue. If an issue is assigned to hashibot, a community member has claimed the issue already.
Terraform Version
0.12.20
Affected Resource(s)
IAM
google_project_iam_binding
Terraform Configuration Files
resource "google_project_iam_binding" "container_engine_robot_loadbancer" {
provider = google-beta
depends_on = [google_project_service.enable_kubernetes_engine_api]
members = ["serviceAccount:service-${google_project.tenant_project.number}@container-engine-robot.iam.gserviceaccount.com"]
role = "roles/container.serviceAgent"
project = google_project.tenant_project.project_id
condition {
title = "intenal load balancer condition"
description = "intenal load balancer condition for role roles/container.serviceAgent"
expression = "compute.isForwardingRuleCreationOperation() && compute.matchLoadBalancingSchemes(['INTERNAL','INTERNAL_MANAGED','INTERNAL_SELF_MANAGED']) || !compute.isForwardingRuleCreationOperation()"
}
}
Debug Output
Panic Output
Expected Behavior
Ideally the role should be added once
Actual Behavior
The role is added twice
When the Kubernetes API is enabled (role without condition)
Community Note
modular-magician
user, it is either in the process of being autogenerated, or is planned to be autogenerated soon. If an issue is assigned to a user, that user is claiming responsibility for the issue. If an issue is assigned tohashibot
, a community member has claimed the issue already.Terraform Version
0.12.20
Affected Resource(s)
IAM
Terraform Configuration Files
resource "google_project_iam_binding" "container_engine_robot_loadbancer" {
provider = google-beta
depends_on = [google_project_service.enable_kubernetes_engine_api]
members = ["serviceAccount:service-${google_project.tenant_project.number}@container-engine-robot.iam.gserviceaccount.com"]
role = "roles/container.serviceAgent"
project = google_project.tenant_project.project_id
condition {
title = "intenal load balancer condition"
description = "intenal load balancer condition for role roles/container.serviceAgent"
expression = "compute.isForwardingRuleCreationOperation() && compute.matchLoadBalancingSchemes(['INTERNAL','INTERNAL_MANAGED','INTERNAL_SELF_MANAGED']) || !compute.isForwardingRuleCreationOperation()"
}
}
Debug Output
Panic Output
Expected Behavior
Ideally the role should be added once
Actual Behavior
The role is added twice
Steps to Reproduce
terraform apply
Important Factoids
References
https://www.terraform.io/docs/providers/google/r/google_project_iam.html
b/304725267
The text was updated successfully, but these errors were encountered: