google/resource-snippets/iam-v1/roles.jinja (36 lines of code) (raw):
# Copyright 2018 Google Inc. All rights reserved.
#
# Licensed under the Apache License, Version 2.0 (the "License");
# you may not use this file except in compliance with the License.
# You may obtain a copy of the License at
#
# http://www.apache.org/licenses/LICENSE-2.0
#
# Unless required by applicable law or agreed to in writing, software
# distributed under the License is distributed on an "AS IS" BASIS,
# WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
# See the License for the specific language governing permissions and
# limitations under the License.
resources:
- name: role
{% if properties["isOrgnizationRole"] == true %}
type: gcp-types/iam-v1:organizations.roles
{% else %}
type: gcp-types/iam-v1:projects.roles
{% endif %}
properties:
{% if properties["isOrgnizationRole"] == true %}
parent: organizations/{{ properties["orgnizationId"] }}
{% else %}
parent: projects/{{ env["project"] }}
{% endif %}
roleId: {{ properties["roleId"] }}
role:
title: A test role
stage: EAP
description: {{ properties["description"] }}
includedPermissions:
- bigquery.datasets.delete
{% if properties["additionalPermission"] %}
- {{ properties["additionalPermission"] }}
{% endif %}