-
Notifications
You must be signed in to change notification settings - Fork 712
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
chore(KMS): cleanup isolated and redundant KMS resources #1271
chore(KMS): cleanup isolated and redundant KMS resources #1271
Conversation
…ng related variables and tests
…s KMS project is intended for use resources in the shared services common environment, not for org-level resources
…nces of prj-$env-$bu-kms that will be removed. Only intended to use prj-$env-kms
…d not be used. replace references to it with module.env_kms configured in Stage 2.
…was missed in earlier commits
…a keyring in environment-wide org projects. Also remove some leftover references to KMS in cai-monitoring
…hecking for env_bu_kms_project that has been removed. env_kms_project is created in stage 2 and tested in envs_test.go)
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Maybe regarding CMEK in 0-bootstrap
it cloud be made optional since the common KMS project does not exist yet and the user may need to enable CMEK on the Terraform state bucket
You're right Daniel, I was working through some incremental changes and seeing the CI results, it has produced this error when tearing down the bootstrap stage:
I'll revise this. And regarding "Maybe regarding CMEK in 0-bootstrapit cloud be made optional since the common KMS project does not exist yet and the user may need to enable CMEK on the Terraform state bucket"... |
All checks are green... @daniel-cit and @apeabody , can I get approval please? |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
LGTM
LGTM |
Pull request was closed
df5817e
into
terraform-google-modules:master
Address #1248: