Skip to content

Commit 13eaea6

Browse files
authored
Adjust the IAM queries for secret manager. (#151)
Signed-off-by: Matt Moore <[email protected]>
1 parent bff7df7 commit 13eaea6

File tree

2 files changed

+8
-2
lines changed

2 files changed

+8
-2
lines changed

modules/configmap/main.tf

Lines changed: 4 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -48,7 +48,10 @@ resource "google_monitoring_alert_policy" "anomalous-secret-access" {
4848
condition_matched_log {
4949
filter = <<EOT
5050
protoPayload.serviceName="secretmanager.googleapis.com"
51-
protoPayload.request.name: ("projects/${var.project_id}/secrets/${var.name}/" OR "projects/${data.google_project.project.number}/secrets/${var.name}/")
51+
(
52+
protoPayload.request.name: ("projects/${var.project_id}/secrets/${var.name}/" OR "projects/${data.google_project.project.number}/secrets/${var.name}/") OR
53+
protoPayload.request.parent=("projects/${var.project_id}/secrets/${var.name}" OR "projects/${data.google_project.project.number}/secrets/${var.name}")
54+
)
5255
5356
-- Ignore the identity that is intended to access this.
5457
-(

modules/secret/main.tf

Lines changed: 4 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -50,7 +50,10 @@ resource "google_monitoring_alert_policy" "anomalous-secret-access" {
5050
condition_matched_log {
5151
filter = <<EOT
5252
protoPayload.serviceName="secretmanager.googleapis.com"
53-
protoPayload.request.name: ("projects/${var.project_id}/secrets/${var.name}/" OR "projects/${data.google_project.project.number}/secrets/${var.name}/")
53+
(
54+
protoPayload.request.name: ("projects/${var.project_id}/secrets/${var.name}/" OR "projects/${data.google_project.project.number}/secrets/${var.name}/") OR
55+
protoPayload.request.parent=("projects/${var.project_id}/secrets/${var.name}" OR "projects/${data.google_project.project.number}/secrets/${var.name}")
56+
)
5457
5558
-- Ignore the identity that is intended to access this.
5659
-(

0 commit comments

Comments
 (0)