Comments (5)
Thank you for your quick replies. Yes, we set the org_id variable. Also, we do have roles/resourcemanager.organizationViewer
explicitly enabled on the Service Account which has the creds Project Factory uses to create these projects.
from terraform-google-project-factory.
Do you think you could share the full IAM roles info on one of the projects where you saw this issue? (Feel free to send privately: [email protected])
from terraform-google-project-factory.
Do you know what permission you were missing?
This unfortunately is a hard issue to resolve due to how Terraform works, but https://github.com/terraform-google-modules/terraform-google-project-factory/blob/master/docs/TROUBLESHOOTING.md#unable-to-query-status-of-default-gce-service-account should address that.
@adrienthebo One though, could we also see if running terraform plan -refresh=false
lets you work through the state deadlock.
from terraform-google-project-factory.
A quick inspection of the error message indicates that the service account may have not had the resourcemanager.organizations.get
permission, typically granted through roles/resourcemanager.organizationViewer
. I believe that #21 allows users to bypass that requirement by directly providing the organization ID - when you invoked Terraform with the project-factory did you set the org_id
variable?
@morgante will do - I'll make a note to test that path.
from terraform-google-project-factory.
FWIW, and not entirely sure whether or not this is helpful info, but I have seen this issue too. For now, I had to comment out the null_resource
that removes default service accounts. I just remove the SAs manually.
from terraform-google-project-factory.
Related Issues (20)
- shared_vpc_subnets doesnt limit the subnets which are shared with a service project HOT 1
- migrate from gsuite to googleworskpace HOT 1
- How do I use lien_reason? HOT 2
- Add support for binding a tag with project HOT 2
- Please add parent_folder to the output. HOT 2
- Support GCP and GCP-Beta Provider Versions ~>5.0 HOT 3
- Unable to add multiple Quotas for the same metric. HOT 1
- Add option to add project in VPC SC in Dry Run Mode
- Allow soft_delete_policy configuration for bucket HOT 1
- Error when reading or editing Service Account & Project Services HOT 1
- add variable "disable_default_iam_recipients" to project-factory (into budget sub module) HOT 1
- Support google_monitoring_monitored_project HOT 1
- vpc_service_control_attach_dry_run not supported HOT 1
- getting an error on the default service account parameter with 10.0.2 version of the project factory module
- Error with default service account create_ignore_already_exists HOT 1
- don't support datastream api in module shared_vpc_access HOT 1
- Service account [email protected] does not exist HOT 1
- enable_shared_vpc_service_project is not working HOT 1
- Grant network user on shared VPC to service project's cloud run serviceaccount.
- tag_binding_values not working in "terraform-google-modules/project-factory/google"
Recommend Projects
-
React
A declarative, efficient, and flexible JavaScript library for building user interfaces.
-
Vue.js
🖖 Vue.js is a progressive, incrementally-adoptable JavaScript framework for building UI on the web.
-
Typescript
TypeScript is a superset of JavaScript that compiles to clean JavaScript output.
-
TensorFlow
An Open Source Machine Learning Framework for Everyone
-
Django
The Web framework for perfectionists with deadlines.
-
Laravel
A PHP framework for web artisans
-
D3
Bring data to life with SVG, Canvas and HTML. 📊📈🎉
-
Recommend Topics
-
javascript
JavaScript (JS) is a lightweight interpreted programming language with first-class functions.
-
web
Some thing interesting about web. New door for the world.
-
server
A server is a program made to process requests and deliver data to clients.
-
Machine learning
Machine learning is a way of modeling and interpreting data that allows a piece of software to respond intelligently.
-
Visualization
Some thing interesting about visualization, use data art
-
Game
Some thing interesting about game, make everyone happy.
Recommend Org
-
Facebook
We are working to build community through open source technology. NB: members must have two-factor auth.
-
Microsoft
Open source projects and samples from Microsoft.
-
Google
Google ❤️ Open Source for everyone.
-
Alibaba
Alibaba Open Source for everyone
-
D3
Data-Driven Documents codes.
-
Tencent
China tencent open source team.
from terraform-google-project-factory.