基于Terraform的GCP文件夹级IAM管控及项目权限配置技术问询
Got it, let's tackle your GCP IAM permission problem here. You're trying to lock down team access to specific project resources (Compute, Cloud SQL, Network Management) via Terraform, but hitting walls with custom roles not supporting wildcards and not being able to reference predefined roles directly. Here are two practical solutions:
1. Combine Predefined Roles + Minimal Custom Role (Recommended)
The easiest and most maintainable approach is to leverage GCP's predefined roles for your core resource needs, then add a small custom role for any extra project-view permissions that aren't covered. Predefined roles are kept up-to-date by GCP, so you don't have to manually track 30+ Compute permissions.
Here's how to implement this in Terraform:
# Bind Compute Instance Admin role (covers most Compute operations) resource "google_project_iam_binding" "team_compute_access" { project = google_project.x.project_id role = "roles/compute.instanceAdmin.v1" members = [ "group:your-team-group@your-domain.com", ] } # Bind Cloud SQL Admin role for full Cloud SQL management resource "google_project_iam_binding" "team_cloudsql_access" { project = google_project.x.project_id role = "roles/cloudsql.admin" members = [ "group:your-team-group@your-domain.com", ] } # Bind Network Management Viewer role for network monitoring/management resource "google_project_iam_binding" "team_network_access" { project = google_project.x.project_id role = "roles/networkmanagement.viewer" members = [ "group:your-team-group@your-domain.com", ] } # Custom role for extra project view permissions not included in predefined roles resource "google_project_iam_custom_role" "project_view_supplement" { project = google_project.x.project_id role_id = "ProjectViewSupplement" title = "Project View Supplement Role" description = "Adds project and service usage view permissions" permissions = [ "resourcemanager.projects.get", "resourcemanager.projects.list", "serviceusage.quotas.get", "serviceusage.services.get", "serviceusage.services.list", ] } # Bind the custom supplement role to your team resource "google_project_iam_binding" "team_project_view" { project = google_project.x.project_id role = google_project_iam_custom_role.project_view_supplement.name members = [ "group:your-team-group@your-domain.com", ] }
This setup keeps your permissions clean: predefined roles handle the heavy lifting for specific resources, and the custom role fills in any gaps. You avoid manual permission lists and benefit from GCP's role updates automatically.
2. Create a Combined Custom Role Using Predefined Role Permissions
If you absolutely need a single role for your team (e.g., for auditing or simplicity), you can use Terraform's google_iam_role data source to pull permissions from predefined roles and combine them into a custom role. This avoids manually listing every Compute permission.
Here's the code:
# Fetch permissions from predefined roles data "google_iam_role" "compute_instance_admin" { name = "roles/compute.instanceAdmin.v1" } data "google_iam_role" "cloudsql_admin" { name = "roles/cloudsql.admin" } data "google_iam_role" "networkmanagement_viewer" { name = "roles/networkmanagement.viewer" } # Create a combined custom role resource "google_project_iam_custom_role" "team_combined_role" { project = google_project.x.project_id role_id = "TeamCombinedResourceRole" title = "Team Combined Resource Role" description = "Combined permissions for Compute, Cloud SQL, Network Management, and project views" # Merge permissions and remove duplicates permissions = distinct(concat( data.google_iam_role.compute_instance_admin.permissions, data.google_iam_role.cloudsql_admin.permissions, data.google_iam_role.networkmanagement_viewer.permissions, [ "resourcemanager.projects.get", "resourcemanager.projects.list", "serviceusage.quotas.get", "serviceusage.services.get", "serviceusage.services.list", ] )) } # Bind the combined role to your team resource "google_project_iam_binding" "team_combined_access" { project = google_project.x.project_id role = google_project_iam_custom_role.team_combined_role.name members = [ "group:your-team-group@your-domain.com", ] }
A few notes here:
- The
distinctfunction ensures you don't have duplicate permissions in your custom role. - Keep in mind that if GCP updates the permissions in a predefined role, your custom role will sync those changes on the next
terraform apply. This can be a pro or con depending on your change management process.
Quick Reminder
GCP custom roles don't support wildcard permissions (like compute.*) by design—this is a security measure to prevent accidental over-permissioning. So sticking to predefined roles where possible is always the best practice.
内容的提问来源于stack exchange,提问作者opti2k4

