From 767adb2ae1743310b54490b32876e2dbcfa21ce4 Mon Sep 17 00:00:00 2001 From: gleb Date: Thu, 13 Jun 2024 14:25:32 +0200 Subject: [PATCH] KUBE-393: Add name to role assignments --- iam.tf | 5 ++++- 1 file changed, 4 insertions(+), 1 deletion(-) diff --git a/iam.tf b/iam.tf index 1c93953..19d30f0 100644 --- a/iam.tf +++ b/iam.tf @@ -63,13 +63,14 @@ resource "azurerm_role_definition" "castai" { resource "azurerm_role_assignment" "castai_resource_group" { principal_id = azuread_service_principal.castai.id role_definition_id = azurerm_role_definition.castai.role_definition_resource_id - + name = "${substr(var.aks_cluster_name, 0, 32)}0000" scope = "/subscriptions/${var.subscription_id}/resourceGroups/${var.resource_group}" } resource "azurerm_role_assignment" "castai_node_resource_group" { principal_id = azuread_service_principal.castai.id role_definition_id = azurerm_role_definition.castai.role_definition_resource_id + name = "${substr(var.aks_cluster_name, 0, 32)}0001" scope = "/subscriptions/${var.subscription_id}/resourceGroups/${var.node_resource_group}" } @@ -77,6 +78,8 @@ resource "azurerm_role_assignment" "castai_node_resource_group" { resource "azurerm_role_assignment" "castai_additional_resource_groups" { for_each = toset(var.additional_resource_groups) principal_id = azuread_service_principal.castai.id + name = "${substr(var.aks_cluster_name, 0, 32)}0002" + role_definition_id = azurerm_role_definition.castai.role_definition_resource_id scope = each.key }