-
Notifications
You must be signed in to change notification settings - Fork 1
/
README.yaml
72 lines (60 loc) · 2.3 KB
/
README.yaml
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
---
#
# This is the canonical configuration for the `README.md`
# Run `make readme` to rebuild the `README.md`
#
# Name of this project
name : Terraform GCP KMS
# License of this project
license: "APACHE"
# Canonical GitHub repo
github_repo: clouddrove/terraform-gcp-kms
# Badges to display
badges:
- name: "Latest Release"
image: "https://img.shields.io/github/release/clouddrove/terraform-gcp-kms.svg"
url: "https://github.com/clouddrove/terraform-gcp-kms/releases/latest"
- name: "tfsec"
image: "https://github.com/clouddrove/terraform-gcp-kms/actions/workflows/tfsec.yml/badge.svg"
url: "https://github.com/clouddrove/terraform-gcp-kms/actions/workflows/tfsec.yml"
- name: "Licence"
image: "https://img.shields.io/badge/License-APACHE-blue.svg"
url: "LICENSE.md"
- name: "Changelog"
image: "https://img.shields.io/badge/Changelog-blue"
url: "CHANGELOG.md"
prerequesties:
- name: Terraform
url: https://learn.hashicorp.com/terraform/getting-started/install.html
version: ">= 1.6.6"
providers:
- name: gcp
url: https://cloud.google.com/
version: ">= 3.50, < 5.0"
module_dependencies:
- name: Labels Module
url: https://github.com/clouddrove/terraform-gcp-labels
description: Provides resource tagging.
# description of this project
description: |-
Terraform module to create KMS resource on google.
# How to use this project
# How to use this project
usage: |-
Here are some examples of how you can use this module in your inventory structure:
### Default KMS
```hcl
module "kms_key" {
source = "clouddrove/kms/google"
version = "1.0.0"
environment = var.environment
label_order = var.label_order
prevent_destroy = false # when prevent_destroy is true (long-lived key) # when prevent_destroy is false (short-lived key)
google_kms_crypto_key_iam_binding_enabled = true
project_id = var.gcp_project_id
location = var.location
keys = ["dev"] # add key names in list
service_accounts = ["serviceAccount:service-xxxxxxxxxxxxxxx.gserviceaccount.com"]
role = "roles/cloudkms.cryptoKeyEncrypterDecrypter"
}
```