terraform-google-modules / terraform-google-vault

Deploys Vault on Compute Engine
https://registry.terraform.io/modules/terraform-google-modules/vault/google
Apache License 2.0
192 stars 127 forks source link

fix: Add iam permission required for vault version greater than 1.11 … #198

Closed dcb-imvaria closed 3 months ago

dcb-imvaria commented 10 months ago

…(#184)

github-actions[bot] commented 8 months ago

This PR is stale because it has been open 60 days with no activity. Remove stale label or comment or this will be closed in 7 days

airman604 commented 5 months ago

I also experienced the same issue trying to install Vault 1.16 and the proposed fix resolved the issue. Per https://support.hashicorp.com/hc/en-us/articles/5277291261075-Auto-unseal-using-GCP-Cloud-KMS#:~:text=2.-,credentials,-%3A%20This%20parameter only cloudkms.cryptoKeys.get permission is needed, but I think considering it's a key dedicated to Vault, using viewer is reasonable.

github-actions[bot] commented 3 months ago

This PR is stale because it has been open 60 days with no activity. Remove stale label or comment or this will be closed in 7 days

dcb-imvaria commented 3 months ago

The workflow is awaiting approval from the maintainer. Is a maintainer assigned?

ianc769 commented 3 months ago

+1 and maybe @g-awmalik or @apeabody ?

apeabody commented 3 months ago

/gcbrun

apeabody commented 3 months ago

/gcbrun