You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何通过Terraform配置Google PAM的多角色权限绑定列表

使用Terraform为Google Privileged Access Manager创建多角色授权

Terraform的google_privileged_access_manager_entitlement资源中,role_bindings属于嵌套块,不能直接在块内部使用for_each。要实现一次性授予多个角色,你需要用Terraform的**动态块(dynamic block)**来遍历角色列表,自动生成对应的角色绑定配置。

修正后的完整代码如下:

locals {
  roles = [
    "roles/compute.instanceAdmin",
    "roles/storage.admin",
  ]
}

resource "google_privileged_access_manager_entitlement" "entitlement" {
  entitlement_id       = "ndpe-entitlement"
  location             = "global"
  max_request_duration = "43200s" #24小时
  parent               = "projects/${var.project_id}"
  requester_justification_config {
    unstructured {}
  }
  eligible_users {
    principals = [
      "group:test@google.com"
    ]
  }

  privileged_access {
    gcp_iam_access {
      # 用动态块遍历角色列表生成多个role_bindings
      dynamic "role_bindings" {
        for_each = toset(local.roles)
        content {
          role                 = role_bindings.value
          condition_expression = "request.time < timestamp(\"2024-04-23T18:30:00.000Z\")"
        }
      }
      resource      = "//cloudresourcemanager.googleapis.com/projects/my-project-name"
      resource_type = "cloudresourcemanager.googleapis.com/Project"
    }
  }
  additional_notification_targets {
    admin_email_recipients = [
      "user@example.com",
    ]
    requester_email_recipients = [
      "user@example.com"
    ]
  }
  approval_workflow {
    manual_approvals {
      require_approver_justification = true
      steps {
        approvals_needed = 1
        approver_email_recipients = [
          "user@example.com"
        ]
        approvers {
          principals = [
            "group:test@google.com"
          ]
        }
      }
    }
  }
}

关键说明:

  • 用dynamic "role_bindings"定义动态块,指定遍历local.roles集合
  • 每个迭代会生成一个独立的role_bindings嵌套块,role_bindings.value对应当前遍历到的角色
  • 保持其他配置(比如资源目标、审批流程、通知设置)不变即可

内容的提问来源于stack exchange,提问作者intotecho

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.18 05:43:22