Create a trigger using Terraform (service account)
Stay organized with collections
Save and categorize content based on your preferences.
Creates a service account and grants permissions.
Explore further
For detailed documentation that includes this code sample, see the following:
Code sample
Except as otherwise noted, the content of this page is licensed under the Creative Commons Attribution 4.0 License, and code samples are licensed under the Apache 2.0 License. For details, see the Google Developers Site Policies. Java is a registered trademark of Oracle and/or its affiliates.
[[["Easy to understand","easyToUnderstand","thumb-up"],["Solved my problem","solvedMyProblem","thumb-up"],["Other","otherUp","thumb-up"]],[["Hard to understand","hardToUnderstand","thumb-down"],["Incorrect information or sample code","incorrectInformationOrSampleCode","thumb-down"],["Missing the information/samples I need","missingTheInformationSamplesINeed","thumb-down"],["Other","otherDown","thumb-down"]],[],[[["\u003cp\u003eThis Terraform configuration creates a service account named "eventarc-workflows-sa" for use with Eventarc triggers and Workflows.\u003c/p\u003e\n"],["\u003cp\u003eThe configuration grants the created service account the "roles/workflows.invoker" role, allowing it to invoke Workflows.\u003c/p\u003e\n"],["\u003cp\u003eIt also assigns the "roles/eventarc.eventReceiver" role to the service account, which provides the ability to receive events.\u003c/p\u003e\n"],["\u003cp\u003eThe service account is further granted the "roles/logging.logWriter" role, enabling it to write logs.\u003c/p\u003e\n"]]],[],null,["# Create a trigger using Terraform (service account)\n\nCreates a service account and grants permissions.\n\nExplore further\n---------------\n\n\nFor detailed documentation that includes this code sample, see the following:\n\n- [Create a trigger using Terraform](/eventarc/docs/creating-triggers-terraform)\n\nCode sample\n-----------\n\n### Terraform\n\n\nTo learn how to apply or remove a Terraform configuration, see\n[Basic Terraform commands](/docs/terraform/basic-commands).\n\n\nFor more information, see the\n[Terraform provider reference documentation](https://registry.terraform.io/providers/hashicorp/google/latest/docs).\n\n # Used to retrieve project information later\n data \"google_project\" \"project\" {}\n\n # Create a service account for Eventarc trigger and Workflows\n resource \"google_service_account\" \"eventarc\" {\n account_id = \"eventarc-workflows-sa\"\n display_name = \"Eventarc Workflows Service Account\"\n }\n\n # Grant permission to invoke Workflows\n resource \"google_project_iam_member\" \"workflowsinvoker\" {\n project = data.google_project.project.id\n role = \"roles/workflows.invoker\"\n member = \"serviceAccount:${google_service_account.eventarc.email}\"\n }\n\n # Grant permission to receive events\n resource \"google_project_iam_member\" \"eventreceiver\" {\n project = data.google_project.project.id\n role = \"roles/eventarc.eventReceiver\"\n member = \"serviceAccount:${google_service_account.eventarc.email}\"\n }\n\n # Grant permission to write logs\n resource \"google_project_iam_member\" \"logwriter\" {\n project = data.google_project.project.id\n role = \"roles/logging.logWriter\"\n member = \"serviceAccount:${google_service_account.eventarc.email}\"\n }\n\nWhat's next\n-----------\n\n\nTo search and filter code samples for other Google Cloud products, see the\n[Google Cloud sample browser](/docs/samples?product=eventarc)."]]