Skip to content

Commit

Permalink
Add required role to see data access logs (#12300)
Browse files Browse the repository at this point in the history
  • Loading branch information
KacperMalachowski authored Oct 31, 2024
1 parent 6e817da commit 929c313
Showing 1 changed file with 8 additions and 0 deletions.
8 changes: 8 additions & 0 deletions configs/terraform/environments/prod/iam.tf
Original file line number Diff line number Diff line change
Expand Up @@ -18,3 +18,11 @@ resource "google_project_iam_member" "kyma_developer_admin_logging_viewer" {
role = "roles/logging.viewer"
member = "group:${var.kyma_developer_admin_email}"
}

# roles/logging.privateLogViewer is required to see Data Access audit logs
resource "google_project_iam_member" "kyma_developer_admin_private_logging_viewer" {
provider = google.kyma_project
project = var.kyma_project_gcp_project_id
role = "roles/logging.privateLogViewer"
member = "group:${var.kyma_developer_admin_email}"
}

0 comments on commit 929c313

Please sign in to comment.