如何使用Terraform创建Google OAuth2.0客户端凭据?
用Google Terraform提供商配置OAuth客户端与Branding
- 配置OAuth客户端:使用
google_oauth_client资源创建和管理OAuth 2.0客户端,示例配置如下:
resource "google_oauth_client" "my_app_client" { name = "my-app-oauth-client" project = "my-gcp-project" redirect_uris = ["https://my-app-domain.com/auth/callback"] scopes = ["openid", "email", "profile"] }
- 配置Branding(OAuth同意屏幕):使用
google_identity_branding资源设置OAuth consent screen的品牌信息,示例:
resource "google_identity_branding" "my_app_branding" { project = "my-gcp-project" title = "My Application" logo { filename = "./assets/app-logo.png" } consent_screen { privacy_policy_url = "https://my-app-domain.com/privacy" terms_of_service_url = "https://my-app-domain.com/terms" } }
- 补充说明:
- 确保使用的Google Terraform提供商版本≥4.0,部分资源在旧版本中未支持;
- 操作前需拥有GCP项目的
identity.admin或iam.securityAdmin权限; - 若涉及IAP(身份感知代理)的品牌配置,可使用
google_iap_branding资源。
内容的提问来源于stack exchange,提问作者Aidan
相关产品推荐
相关产品推荐

