File tree Expand file tree Collapse file tree
iam_workload_identity_pool_full_federation_only_mode
iam_workload_identity_pool_full_trust_domain_mode_with_default_shared_ca
iam_workload_identity_pool_full_trust_domain_mode Expand file tree Collapse file tree Original file line number Diff line number Diff line change 1+ # This file has some scaffolding to make sure that names are unique and that
2+ # a region and zone are selected when you try to create your Terraform resources.
3+
4+ locals {
5+ name_suffix = " ${ random_pet . suffix . id } "
6+ }
7+
8+ resource "random_pet" "suffix" {
9+ length = 2
10+ }
11+
12+ provider "google" {
13+ region = " us-central1"
14+ zone = " us-central1-c"
15+ }
Original file line number Diff line number Diff line change 1+ resource "google_iam_workload_identity_pool" "example" {
2+ workload_identity_pool_id = " example-pool-${ local . name_suffix } "
3+ display_name = " Name of the pool"
4+ description = " Identity pool operates in FEDERATION_ONLY mode"
5+ disabled = true
6+ mode = " FEDERATION_ONLY"
7+ }
Original file line number Diff line number Diff line change 1+ ===
2+
3+ These examples use real resources that will be billed to the
4+ Google Cloud Platform project you use - so make sure that you
5+ run "terraform destroy" before quitting!
6+
7+ ===
Original file line number Diff line number Diff line change 1+ # Iam Workload Identity Pool Full Federation Only Mode - Terraform
2+
3+ ## Setup
4+
5+ <walkthrough-author name =" rileykarson@google.com " analyticsId =" UA-125550242-1 " tutorialName =" iam_workload_identity_pool_full_federation_only_mode " repositoryUrl =" https://github.com/terraform-google-modules/docs-examples " ></walkthrough-author >
6+
7+ Welcome to Terraform in Google Cloud Shell! We need you to let us know what project you'd like to use with Terraform.
8+
9+ <walkthrough-project-billing-setup ></walkthrough-project-billing-setup >
10+
11+ Terraform provisions real GCP resources, so anything you create in this session will be billed against this project.
12+
13+ ## Terraforming!
14+
15+ Let's use {{project-id}} with Terraform! Click the Cloud Shell icon below to copy the command
16+ to your shell, and then run it from the shell by pressing Enter/Return. Terraform will pick up
17+ the project name from the environment variable.
18+
19+ ``` bash
20+ export GOOGLE_CLOUD_PROJECT={{project-id}}
21+ ```
22+
23+ After that, let's get Terraform started. Run the following to pull in the providers.
24+
25+ ``` bash
26+ terraform init
27+ ```
28+
29+ With the providers downloaded and a project set, you're ready to use Terraform. Go ahead!
30+
31+ ``` bash
32+ terraform apply
33+ ```
34+
35+ Terraform will show you what it plans to do, and prompt you to accept. Type "yes" to accept the plan.
36+
37+ ``` bash
38+ yes
39+ ```
40+
41+
42+ ## Post-Apply
43+
44+ ### Editing your config
45+
46+ Now you've provisioned your resources in GCP! If you run a "plan", you should see no changes needed.
47+
48+ ``` bash
49+ terraform plan
50+ ```
51+
52+ So let's make a change! Try editing a number, or appending a value to the name in the editor. Then,
53+ run a 'plan' again.
54+
55+ ``` bash
56+ terraform plan
57+ ```
58+
59+ Afterwards you can run an apply, which implicitly does a plan and shows you the intended changes
60+ at the 'yes' prompt.
61+
62+ ``` bash
63+ terraform apply
64+ ```
65+
66+ ``` bash
67+ yes
68+ ```
69+
70+ ## Cleanup
71+
72+ Run the following to remove the resources Terraform provisioned:
73+
74+ ``` bash
75+ terraform destroy
76+ ```
77+ ``` bash
78+ yes
79+ ```
Original file line number Diff line number Diff line change 1+ # This file has some scaffolding to make sure that names are unique and that
2+ # a region and zone are selected when you try to create your Terraform resources.
3+
4+ locals {
5+ name_suffix = " ${ random_pet . suffix . id } "
6+ }
7+
8+ resource "random_pet" "suffix" {
9+ length = 2
10+ }
11+
12+ provider "google" {
13+ region = " us-central1"
14+ zone = " us-central1-c"
15+ }
Original file line number Diff line number Diff line change 1+ resource "google_iam_workload_identity_pool" "example" {
2+ workload_identity_pool_id = " example-pool-${ local . name_suffix } "
3+ display_name = " Name of the pool"
4+ description = " Identity pool operates in TRUST_DOMAIN mode"
5+ disabled = true
6+ mode = " TRUST_DOMAIN"
7+ inline_certificate_issuance_config {
8+ ca_pools = {
9+ " us-central1" : " projects/project-bar/locations/us-central1/caPools/ca-pool-bar"
10+ " asia-east2" : " projects/project-foo/locations/asia-east2/caPools/ca-pool-foo"
11+ }
12+ lifetime = " 86400s"
13+ rotation_window_percentage = 50
14+ key_algorithm = " ECDSA_P256"
15+ }
16+ inline_trust_config {
17+ additional_trust_bundles {
18+ trust_domain = " example.com"
19+ trust_anchors {
20+ pem_certificate = file (" test-fixtures/trust_anchor_1.pem" )
21+ }
22+ trust_anchors {
23+ pem_certificate = file (" test-fixtures/trust_anchor_2.pem" )
24+ }
25+ }
26+ additional_trust_bundles {
27+ trust_domain = " example.net"
28+ trust_anchors {
29+ pem_certificate = file (" test-fixtures/trust_anchor_3.pem" )
30+ }
31+ trust_anchors {
32+ pem_certificate = file (" test-fixtures/trust_anchor_4.pem" )
33+ }
34+ }
35+ }
36+ }
Original file line number Diff line number Diff line change 1+ ===
2+
3+ These examples use real resources that will be billed to the
4+ Google Cloud Platform project you use - so make sure that you
5+ run "terraform destroy" before quitting!
6+
7+ ===
Original file line number Diff line number Diff line change 1+ # Iam Workload Identity Pool Full Trust Domain Mode - Terraform
2+
3+ ## Setup
4+
5+ <walkthrough-author name =" rileykarson@google.com " analyticsId =" UA-125550242-1 " tutorialName =" iam_workload_identity_pool_full_trust_domain_mode " repositoryUrl =" https://github.com/terraform-google-modules/docs-examples " ></walkthrough-author >
6+
7+ Welcome to Terraform in Google Cloud Shell! We need you to let us know what project you'd like to use with Terraform.
8+
9+ <walkthrough-project-billing-setup ></walkthrough-project-billing-setup >
10+
11+ Terraform provisions real GCP resources, so anything you create in this session will be billed against this project.
12+
13+ ## Terraforming!
14+
15+ Let's use {{project-id}} with Terraform! Click the Cloud Shell icon below to copy the command
16+ to your shell, and then run it from the shell by pressing Enter/Return. Terraform will pick up
17+ the project name from the environment variable.
18+
19+ ``` bash
20+ export GOOGLE_CLOUD_PROJECT={{project-id}}
21+ ```
22+
23+ After that, let's get Terraform started. Run the following to pull in the providers.
24+
25+ ``` bash
26+ terraform init
27+ ```
28+
29+ With the providers downloaded and a project set, you're ready to use Terraform. Go ahead!
30+
31+ ``` bash
32+ terraform apply
33+ ```
34+
35+ Terraform will show you what it plans to do, and prompt you to accept. Type "yes" to accept the plan.
36+
37+ ``` bash
38+ yes
39+ ```
40+
41+
42+ ## Post-Apply
43+
44+ ### Editing your config
45+
46+ Now you've provisioned your resources in GCP! If you run a "plan", you should see no changes needed.
47+
48+ ``` bash
49+ terraform plan
50+ ```
51+
52+ So let's make a change! Try editing a number, or appending a value to the name in the editor. Then,
53+ run a 'plan' again.
54+
55+ ``` bash
56+ terraform plan
57+ ```
58+
59+ Afterwards you can run an apply, which implicitly does a plan and shows you the intended changes
60+ at the 'yes' prompt.
61+
62+ ``` bash
63+ terraform apply
64+ ```
65+
66+ ``` bash
67+ yes
68+ ```
69+
70+ ## Cleanup
71+
72+ Run the following to remove the resources Terraform provisioned:
73+
74+ ``` bash
75+ terraform destroy
76+ ```
77+ ``` bash
78+ yes
79+ ```
Original file line number Diff line number Diff line change 1+ # This file has some scaffolding to make sure that names are unique and that
2+ # a region and zone are selected when you try to create your Terraform resources.
3+
4+ locals {
5+ name_suffix = " ${ random_pet . suffix . id } "
6+ }
7+
8+ resource "random_pet" "suffix" {
9+ length = 2
10+ }
11+
12+ provider "google" {
13+ region = " us-central1"
14+ zone = " us-central1-c"
15+ }
Original file line number Diff line number Diff line change 1+ resource "google_iam_workload_identity_pool" "example" {
2+ workload_identity_pool_id = " example-pool-${ local . name_suffix } "
3+ display_name = " Name of the pool"
4+ description = " Identity pool operates in TRUST_DOMAIN mode"
5+ disabled = true
6+ mode = " TRUST_DOMAIN"
7+ inline_certificate_issuance_config {
8+ use_default_shared_ca = true
9+ lifetime = " 86400s"
10+ rotation_window_percentage = 50
11+ key_algorithm = " ECDSA_P256"
12+ }
13+ inline_trust_config {
14+ additional_trust_bundles {
15+ trust_domain = " example.com"
16+ trust_anchors {
17+ pem_certificate = file (" test-fixtures/trust_anchor_1.pem" )
18+ }
19+ trust_anchors {
20+ pem_certificate = file (" test-fixtures/trust_anchor_2.pem" )
21+ }
22+ }
23+ additional_trust_bundles {
24+ trust_domain = " example.net"
25+ trust_anchors {
26+ pem_certificate = file (" test-fixtures/trust_anchor_3.pem" )
27+ }
28+ trust_anchors {
29+ pem_certificate = file (" test-fixtures/trust_anchor_4.pem" )
30+ }
31+ }
32+ }
33+ }
You can’t perform that action at this time.
0 commit comments