You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

基于Terraform的GCP文件夹级IAM管控及项目权限配置技术问询

Got it, let's tackle your GCP IAM permission problem here. You're trying to lock down team access to specific project resources (Compute, Cloud SQL, Network Management) via Terraform, but hitting walls with custom roles not supporting wildcards and not being able to reference predefined roles directly. Here are two practical solutions:

The easiest and most maintainable approach is to leverage GCP's predefined roles for your core resource needs, then add a small custom role for any extra project-view permissions that aren't covered. Predefined roles are kept up-to-date by GCP, so you don't have to manually track 30+ Compute permissions.

Here's how to implement this in Terraform:

# Bind Compute Instance Admin role (covers most Compute operations)
resource "google_project_iam_binding" "team_compute_access" {
  project = google_project.x.project_id
  role    = "roles/compute.instanceAdmin.v1"
  members = [
    "group:your-team-group@your-domain.com",
  ]
}

# Bind Cloud SQL Admin role for full Cloud SQL management
resource "google_project_iam_binding" "team_cloudsql_access" {
  project = google_project.x.project_id
  role    = "roles/cloudsql.admin"
  members = [
    "group:your-team-group@your-domain.com",
  ]
}

# Bind Network Management Viewer role for network monitoring/management
resource "google_project_iam_binding" "team_network_access" {
  project = google_project.x.project_id
  role    = "roles/networkmanagement.viewer"
  members = [
    "group:your-team-group@your-domain.com",
  ]
}

# Custom role for extra project view permissions not included in predefined roles
resource "google_project_iam_custom_role" "project_view_supplement" {
  project     = google_project.x.project_id
  role_id     = "ProjectViewSupplement"
  title       = "Project View Supplement Role"
  description = "Adds project and service usage view permissions"
  permissions = [
    "resourcemanager.projects.get",
    "resourcemanager.projects.list",
    "serviceusage.quotas.get",
    "serviceusage.services.get",
    "serviceusage.services.list",
  ]
}

# Bind the custom supplement role to your team
resource "google_project_iam_binding" "team_project_view" {
  project = google_project.x.project_id
  role    = google_project_iam_custom_role.project_view_supplement.name
  members = [
    "group:your-team-group@your-domain.com",
  ]
}

This setup keeps your permissions clean: predefined roles handle the heavy lifting for specific resources, and the custom role fills in any gaps. You avoid manual permission lists and benefit from GCP's role updates automatically.

2. Create a Combined Custom Role Using Predefined Role Permissions

If you absolutely need a single role for your team (e.g., for auditing or simplicity), you can use Terraform's google_iam_role data source to pull permissions from predefined roles and combine them into a custom role. This avoids manually listing every Compute permission.

Here's the code:

# Fetch permissions from predefined roles
data "google_iam_role" "compute_instance_admin" {
  name = "roles/compute.instanceAdmin.v1"
}

data "google_iam_role" "cloudsql_admin" {
  name = "roles/cloudsql.admin"
}

data "google_iam_role" "networkmanagement_viewer" {
  name = "roles/networkmanagement.viewer"
}

# Create a combined custom role
resource "google_project_iam_custom_role" "team_combined_role" {
  project     = google_project.x.project_id
  role_id     = "TeamCombinedResourceRole"
  title       = "Team Combined Resource Role"
  description = "Combined permissions for Compute, Cloud SQL, Network Management, and project views"
  # Merge permissions and remove duplicates
  permissions = distinct(concat(
    data.google_iam_role.compute_instance_admin.permissions,
    data.google_iam_role.cloudsql_admin.permissions,
    data.google_iam_role.networkmanagement_viewer.permissions,
    [
      "resourcemanager.projects.get",
      "resourcemanager.projects.list",
      "serviceusage.quotas.get",
      "serviceusage.services.get",
      "serviceusage.services.list",
    ]
  ))
}

# Bind the combined role to your team
resource "google_project_iam_binding" "team_combined_access" {
  project = google_project.x.project_id
  role    = google_project_iam_custom_role.team_combined_role.name
  members = [
    "group:your-team-group@your-domain.com",
  ]
}

A few notes here:

  • The distinct function ensures you don't have duplicate permissions in your custom role.
  • Keep in mind that if GCP updates the permissions in a predefined role, your custom role will sync those changes on the next terraform apply. This can be a pro or con depending on your change management process.

Quick Reminder

GCP custom roles don't support wildcard permissions (like compute.*) by design—this is a security measure to prevent accidental over-permissioning. So sticking to predefined roles where possible is always the best practice.

内容的提问来源于stack exchange,提问作者opti2k4

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.09 21:32:45