Skip to content

Commit 686c9ce

Browse files
committed
Remove roles/cloudbuild.builds.editor from cloud build service account
1 parent c80a695 commit 686c9ce

File tree

1 file changed

+0
-6
lines changed
  • deployment/modules/gcp/cloudbuild

1 file changed

+0
-6
lines changed

deployment/modules/gcp/cloudbuild/main.tf

Lines changed: 0 additions & 6 deletions
Original file line numberDiff line numberDiff line change
@@ -43,12 +43,6 @@ resource "google_service_account" "cloudbuild_service_account" {
4343
display_name = "Service Account for Cloud Build (${var.env})"
4444
}
4545

46-
resource "google_project_iam_member" "cloudbuild_builds_editor" {
47-
project = var.project_id
48-
role = "roles/cloudbuild.builds.editor"
49-
member = "serviceAccount:${google_service_account.cloudbuild_service_account.email}"
50-
}
51-
5246
resource "google_project_iam_member" "logging_log_writer" {
5347
project = var.project_id
5448
role = "roles/logging.logWriter"

0 commit comments

Comments
 (0)