mirror of
https://github.com/google/nomulus.git
synced 2025-04-30 12:07:51 +02:00
This allows us to not ship the proxy with certificates/private keys. The secret is still encrypted by KMS. Reading the secret only happens once when the first EPP request comes in, which should not incur any tangible performance penalty. ------------- Created by MOE: https://github.com/google/moe MOE_MIGRATED_REVID=191771680
10 lines
385 B
HCL
10 lines
385 B
HCL
resource "google_storage_bucket" "proxy_certificate" {
|
|
name = "${var.proxy_certificate_bucket}"
|
|
storage_class = "MULTI_REGIONAL"
|
|
}
|
|
|
|
resource "google_storage_bucket_iam_member" "member" {
|
|
bucket = "${google_storage_bucket.proxy_certificate.name}"
|
|
role = "roles/storage.objectViewer"
|
|
member = "serviceAccount:${google_service_account.proxy_service_account.email}"
|
|
}
|