Skip to content

Commit 2963b53

Browse files
feat: Add IAM resources for KMS EKM Connection (#11378) (#19132)
[upstream:9c8ba524d15dc5a38a7bf86c734ebcb458edb358] Signed-off-by: Modular Magician <[email protected]>
1 parent 2be944a commit 2963b53

6 files changed

+609
-3
lines changed

.changelog/11378.txt

+9
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,9 @@
1+
```release-note:new-resource
2+
`google_kms_ekm_connection_iam_member`
3+
```
4+
```release-note:new-resource
5+
`google_kms_ekm_connection_iam_policy`
6+
```
7+
```release-note:new-resource
8+
`google_kms_ekm_connection_iam_binding`
9+
```

google/provider/provider_mmv1_resources.go

+6-2
Original file line numberDiff line numberDiff line change
@@ -378,6 +378,7 @@ var generatedIAMDatasources = map[string]*schema.Resource{
378378
"google_iap_web_region_backend_service_iam_policy": tpgiamresource.DataSourceIamPolicy(iap.IapWebRegionBackendServiceIamSchema, iap.IapWebRegionBackendServiceIamUpdaterProducer),
379379
"google_iap_web_type_app_engine_iam_policy": tpgiamresource.DataSourceIamPolicy(iap.IapWebTypeAppEngineIamSchema, iap.IapWebTypeAppEngineIamUpdaterProducer),
380380
"google_iap_web_type_compute_iam_policy": tpgiamresource.DataSourceIamPolicy(iap.IapWebTypeComputeIamSchema, iap.IapWebTypeComputeIamUpdaterProducer),
381+
"google_kms_ekm_connection_iam_policy": tpgiamresource.DataSourceIamPolicy(kms.KMSEkmConnectionIamSchema, kms.KMSEkmConnectionIamUpdaterProducer),
381382
"google_logging_log_view_iam_policy": tpgiamresource.DataSourceIamPolicy(logging.LoggingLogViewIamSchema, logging.LoggingLogViewIamUpdaterProducer),
382383
"google_network_security_address_group_iam_policy": tpgiamresource.DataSourceIamPolicy(networksecurity.NetworkSecurityProjectAddressGroupIamSchema, networksecurity.NetworkSecurityProjectAddressGroupIamUpdaterProducer),
383384
"google_notebooks_instance_iam_policy": tpgiamresource.DataSourceIamPolicy(notebooks.NotebooksInstanceIamSchema, notebooks.NotebooksInstanceIamUpdaterProducer),
@@ -428,8 +429,8 @@ var handwrittenIAMDatasources = map[string]*schema.Resource{
428429

429430
// Resources
430431
// Generated resources: 450
431-
// Generated IAM resources: 255
432-
// Total generated resources: 705
432+
// Generated IAM resources: 258
433+
// Total generated resources: 708
433434
var generatedResources = map[string]*schema.Resource{
434435
"google_folder_access_approval_settings": accessapproval.ResourceAccessApprovalFolderSettings(),
435436
"google_organization_access_approval_settings": accessapproval.ResourceAccessApprovalOrganizationSettings(),
@@ -913,6 +914,9 @@ var generatedResources = map[string]*schema.Resource{
913914
"google_kms_crypto_key": kms.ResourceKMSCryptoKey(),
914915
"google_kms_crypto_key_version": kms.ResourceKMSCryptoKeyVersion(),
915916
"google_kms_ekm_connection": kms.ResourceKMSEkmConnection(),
917+
"google_kms_ekm_connection_iam_binding": tpgiamresource.ResourceIamBinding(kms.KMSEkmConnectionIamSchema, kms.KMSEkmConnectionIamUpdaterProducer, kms.KMSEkmConnectionIdParseFunc),
918+
"google_kms_ekm_connection_iam_member": tpgiamresource.ResourceIamMember(kms.KMSEkmConnectionIamSchema, kms.KMSEkmConnectionIamUpdaterProducer, kms.KMSEkmConnectionIdParseFunc),
919+
"google_kms_ekm_connection_iam_policy": tpgiamresource.ResourceIamPolicy(kms.KMSEkmConnectionIamSchema, kms.KMSEkmConnectionIamUpdaterProducer, kms.KMSEkmConnectionIdParseFunc),
916920
"google_kms_key_ring": kms.ResourceKMSKeyRing(),
917921
"google_kms_key_ring_import_job": kms.ResourceKMSKeyRingImportJob(),
918922
"google_kms_secret_ciphertext": kms.ResourceKMSSecretCiphertext(),
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,249 @@
1+
// Copyright (c) HashiCorp, Inc.
2+
// SPDX-License-Identifier: MPL-2.0
3+
4+
// ----------------------------------------------------------------------------
5+
//
6+
// *** AUTO GENERATED CODE *** Type: MMv1 ***
7+
//
8+
// ----------------------------------------------------------------------------
9+
//
10+
// This file is automatically generated by Magic Modules and manual
11+
// changes will be clobbered when the file is regenerated.
12+
//
13+
// Please read more about how to change this file in
14+
// .github/CONTRIBUTING.md.
15+
//
16+
// ----------------------------------------------------------------------------
17+
18+
package kms
19+
20+
import (
21+
"fmt"
22+
23+
"github.com/hashicorp/errwrap"
24+
"github.com/hashicorp/terraform-plugin-sdk/v2/helper/schema"
25+
"google.golang.org/api/cloudresourcemanager/v1"
26+
27+
"github.com/hashicorp/terraform-provider-google/google/tpgiamresource"
28+
"github.com/hashicorp/terraform-provider-google/google/tpgresource"
29+
transport_tpg "github.com/hashicorp/terraform-provider-google/google/transport"
30+
)
31+
32+
var KMSEkmConnectionIamSchema = map[string]*schema.Schema{
33+
"project": {
34+
Type: schema.TypeString,
35+
Computed: true,
36+
Optional: true,
37+
ForceNew: true,
38+
},
39+
"location": {
40+
Type: schema.TypeString,
41+
Computed: true,
42+
Optional: true,
43+
ForceNew: true,
44+
},
45+
"name": {
46+
Type: schema.TypeString,
47+
Required: true,
48+
ForceNew: true,
49+
DiffSuppressFunc: tpgresource.CompareSelfLinkOrResourceName,
50+
},
51+
}
52+
53+
type KMSEkmConnectionIamUpdater struct {
54+
project string
55+
location string
56+
name string
57+
d tpgresource.TerraformResourceData
58+
Config *transport_tpg.Config
59+
}
60+
61+
func KMSEkmConnectionIamUpdaterProducer(d tpgresource.TerraformResourceData, config *transport_tpg.Config) (tpgiamresource.ResourceIamUpdater, error) {
62+
values := make(map[string]string)
63+
64+
project, _ := tpgresource.GetProject(d, config)
65+
if project != "" {
66+
if err := d.Set("project", project); err != nil {
67+
return nil, fmt.Errorf("Error setting project: %s", err)
68+
}
69+
}
70+
values["project"] = project
71+
location, _ := tpgresource.GetLocation(d, config)
72+
if location != "" {
73+
if err := d.Set("location", location); err != nil {
74+
return nil, fmt.Errorf("Error setting location: %s", err)
75+
}
76+
}
77+
values["location"] = location
78+
if v, ok := d.GetOk("name"); ok {
79+
values["name"] = v.(string)
80+
}
81+
82+
// We may have gotten either a long or short name, so attempt to parse long name if possible
83+
m, err := tpgresource.GetImportIdQualifiers([]string{"projects/(?P<project>[^/]+)/locations/(?P<location>[^/]+)/ekmConnections/(?P<name>[^/]+)", "(?P<project>[^/]+)/(?P<location>[^/]+)/(?P<name>[^/]+)", "(?P<location>[^/]+)/(?P<name>[^/]+)"}, d, config, d.Get("name").(string))
84+
if err != nil {
85+
return nil, err
86+
}
87+
88+
for k, v := range m {
89+
values[k] = v
90+
}
91+
92+
u := &KMSEkmConnectionIamUpdater{
93+
project: values["project"],
94+
location: values["location"],
95+
name: values["name"],
96+
d: d,
97+
Config: config,
98+
}
99+
100+
if err := d.Set("project", u.project); err != nil {
101+
return nil, fmt.Errorf("Error setting project: %s", err)
102+
}
103+
if err := d.Set("location", u.location); err != nil {
104+
return nil, fmt.Errorf("Error setting location: %s", err)
105+
}
106+
if err := d.Set("name", u.GetResourceId()); err != nil {
107+
return nil, fmt.Errorf("Error setting name: %s", err)
108+
}
109+
110+
return u, nil
111+
}
112+
113+
func KMSEkmConnectionIdParseFunc(d *schema.ResourceData, config *transport_tpg.Config) error {
114+
values := make(map[string]string)
115+
116+
project, _ := tpgresource.GetProject(d, config)
117+
if project != "" {
118+
values["project"] = project
119+
}
120+
121+
location, _ := tpgresource.GetLocation(d, config)
122+
if location != "" {
123+
values["location"] = location
124+
}
125+
126+
m, err := tpgresource.GetImportIdQualifiers([]string{"projects/(?P<project>[^/]+)/locations/(?P<location>[^/]+)/ekmConnections/(?P<name>[^/]+)", "(?P<project>[^/]+)/(?P<location>[^/]+)/(?P<name>[^/]+)", "(?P<location>[^/]+)/(?P<name>[^/]+)"}, d, config, d.Id())
127+
if err != nil {
128+
return err
129+
}
130+
131+
for k, v := range m {
132+
values[k] = v
133+
}
134+
135+
u := &KMSEkmConnectionIamUpdater{
136+
project: values["project"],
137+
location: values["location"],
138+
name: values["name"],
139+
d: d,
140+
Config: config,
141+
}
142+
if err := d.Set("name", u.GetResourceId()); err != nil {
143+
return fmt.Errorf("Error setting name: %s", err)
144+
}
145+
d.SetId(u.GetResourceId())
146+
return nil
147+
}
148+
149+
func (u *KMSEkmConnectionIamUpdater) GetResourceIamPolicy() (*cloudresourcemanager.Policy, error) {
150+
url, err := u.qualifyEkmConnectionUrl("getIamPolicy")
151+
if err != nil {
152+
return nil, err
153+
}
154+
155+
project, err := tpgresource.GetProject(u.d, u.Config)
156+
if err != nil {
157+
return nil, err
158+
}
159+
var obj map[string]interface{}
160+
url, err = transport_tpg.AddQueryParams(url, map[string]string{"options.requestedPolicyVersion": fmt.Sprintf("%d", tpgiamresource.IamPolicyVersion)})
161+
if err != nil {
162+
return nil, err
163+
}
164+
165+
userAgent, err := tpgresource.GenerateUserAgentString(u.d, u.Config.UserAgent)
166+
if err != nil {
167+
return nil, err
168+
}
169+
170+
policy, err := transport_tpg.SendRequest(transport_tpg.SendRequestOptions{
171+
Config: u.Config,
172+
Method: "GET",
173+
Project: project,
174+
RawURL: url,
175+
UserAgent: userAgent,
176+
Body: obj,
177+
})
178+
if err != nil {
179+
return nil, errwrap.Wrapf(fmt.Sprintf("Error retrieving IAM policy for %s: {{err}}", u.DescribeResource()), err)
180+
}
181+
182+
out := &cloudresourcemanager.Policy{}
183+
err = tpgresource.Convert(policy, out)
184+
if err != nil {
185+
return nil, errwrap.Wrapf("Cannot convert a policy to a resource manager policy: {{err}}", err)
186+
}
187+
188+
return out, nil
189+
}
190+
191+
func (u *KMSEkmConnectionIamUpdater) SetResourceIamPolicy(policy *cloudresourcemanager.Policy) error {
192+
json, err := tpgresource.ConvertToMap(policy)
193+
if err != nil {
194+
return err
195+
}
196+
197+
obj := make(map[string]interface{})
198+
obj["policy"] = json
199+
200+
url, err := u.qualifyEkmConnectionUrl("setIamPolicy")
201+
if err != nil {
202+
return err
203+
}
204+
project, err := tpgresource.GetProject(u.d, u.Config)
205+
if err != nil {
206+
return err
207+
}
208+
209+
userAgent, err := tpgresource.GenerateUserAgentString(u.d, u.Config.UserAgent)
210+
if err != nil {
211+
return err
212+
}
213+
214+
_, err = transport_tpg.SendRequest(transport_tpg.SendRequestOptions{
215+
Config: u.Config,
216+
Method: "POST",
217+
Project: project,
218+
RawURL: url,
219+
UserAgent: userAgent,
220+
Body: obj,
221+
Timeout: u.d.Timeout(schema.TimeoutCreate),
222+
})
223+
if err != nil {
224+
return errwrap.Wrapf(fmt.Sprintf("Error setting IAM policy for %s: {{err}}", u.DescribeResource()), err)
225+
}
226+
227+
return nil
228+
}
229+
230+
func (u *KMSEkmConnectionIamUpdater) qualifyEkmConnectionUrl(methodIdentifier string) (string, error) {
231+
urlTemplate := fmt.Sprintf("{{KMSBasePath}}%s:%s", fmt.Sprintf("projects/%s/locations/%s/ekmConnections/%s", u.project, u.location, u.name), methodIdentifier)
232+
url, err := tpgresource.ReplaceVars(u.d, u.Config, urlTemplate)
233+
if err != nil {
234+
return "", err
235+
}
236+
return url, nil
237+
}
238+
239+
func (u *KMSEkmConnectionIamUpdater) GetResourceId() string {
240+
return fmt.Sprintf("projects/%s/locations/%s/ekmConnections/%s", u.project, u.location, u.name)
241+
}
242+
243+
func (u *KMSEkmConnectionIamUpdater) GetMutexKey() string {
244+
return fmt.Sprintf("iam-kms-ekmconnection-%s", u.GetResourceId())
245+
}
246+
247+
func (u *KMSEkmConnectionIamUpdater) DescribeResource() string {
248+
return fmt.Sprintf("kms ekmconnection %q", u.GetResourceId())
249+
}

google/services/kms/resource_kms_ekm_connection_test.go

+55-1
Original file line numberDiff line numberDiff line change
@@ -63,7 +63,7 @@ data "google_project" "vpc-project" {
6363
data "google_project" "project" {
6464
}
6565
resource "google_kms_ekm_connection" "example-ekmconnection" {
66-
name = "tf_test_ekmconnection_example%{random_suffix}"
66+
name = "tf_test_ekmconnection_example%{random_suffix}"
6767
location = "us-central1"
6868
key_management_mode = "MANUAL"
6969
service_resolvers {
@@ -74,6 +74,60 @@ resource "google_kms_ekm_connection" "example-ekmconnection" {
7474
}
7575
}
7676
}
77+
resource "google_kms_ekm_connection" "example-ekmconnection-iam" {
78+
count = 2
79+
name = "tf_test_ekmconnection_example%{random_suffix}${count.index}"
80+
location = "us-central1"
81+
key_management_mode = "MANUAL"
82+
service_resolvers {
83+
service_directory_service = data.google_secret_manager_secret_version.servicedirectoryservice.secret_data
84+
hostname = data.google_secret_manager_secret_version.hostname.secret_data
85+
server_certificates {
86+
raw_der = data.google_secret_manager_secret_version.raw_der.secret_data
87+
}
88+
}
89+
}
90+
91+
resource "google_kms_ekm_connection_iam_member" "add_viewer" {
92+
name = google_kms_ekm_connection.example-ekmconnection-iam[0].id
93+
location = "us-central1"
94+
role = "roles/cloudkms.viewer"
95+
member = "serviceAccount:service-${data.google_project.project.number}@gcp-sa-ekms.iam.gserviceaccount.com"
96+
97+
condition {
98+
title = "expires_after_2029_12_31"
99+
description = "Expiring at midnight of 2029-12-31"
100+
expression = "request.time < timestamp(\"2030-01-01T00:00:00Z\")"
101+
}
102+
}
103+
104+
resource "google_kms_ekm_connection_iam_binding" "ekm_admin" {
105+
name = google_kms_ekm_connection.example-ekmconnection-iam[1].id
106+
location = "us-central1"
107+
role = "roles/cloudkms.ekmConnectionsAdmin"
108+
members = ["serviceAccount:service-${data.google_project.project.number}@gcp-sa-ekms.iam.gserviceaccount.com"]
109+
110+
condition {
111+
title = "expires_after_2029_12_31"
112+
description = "Expiring at midnight of 2029-12-31"
113+
expression = "request.time < timestamp(\"2030-01-01T00:00:00Z\")"
114+
}
115+
}
116+
117+
data "google_iam_policy" "ekm_sa" {
118+
binding {
119+
role = "roles/cloudcontrolspartner.ekmServiceAgent"
120+
members = [
121+
"serviceAccount:service-${data.google_project.project.number}@gcp-sa-ekms.iam.gserviceaccount.com",
122+
]
123+
}
124+
}
125+
126+
resource "google_kms_ekm_connection_iam_policy" "policy" {
127+
name = google_kms_ekm_connection.example-ekmconnection.id
128+
policy_data = data.google_iam_policy.ekm_sa.policy_data
129+
location = "us-central1"
130+
}
77131
`, context)
78132
}
79133

0 commit comments

Comments
 (0)