使用 Terraform 建立觸發條件 (服務帳戶)
透過集合功能整理內容
你可以依據偏好儲存及分類內容。
建立服務帳戶並授予權限。
深入探索
如需包含這個程式碼範例的詳細說明文件,請參閱下列內容:
程式碼範例
除非另有註明,否則本頁面中的內容是採用創用 CC 姓名標示 4.0 授權,程式碼範例則為阿帕契 2.0 授權。詳情請參閱《Google Developers 網站政策》。Java 是 Oracle 和/或其關聯企業的註冊商標。
[[["容易理解","easyToUnderstand","thumb-up"],["確實解決了我的問題","solvedMyProblem","thumb-up"],["其他","otherUp","thumb-up"]],[["難以理解","hardToUnderstand","thumb-down"],["資訊或程式碼範例有誤","incorrectInformationOrSampleCode","thumb-down"],["缺少我需要的資訊/範例","missingTheInformationSamplesINeed","thumb-down"],["翻譯問題","translationIssue","thumb-down"],["其他","otherDown","thumb-down"]],[],[[["\u003cp\u003eThis Terraform configuration creates a service account named "eventarc-workflows-sa" for use with Eventarc triggers and Workflows.\u003c/p\u003e\n"],["\u003cp\u003eThe configuration grants the created service account the "roles/workflows.invoker" role, allowing it to invoke Workflows.\u003c/p\u003e\n"],["\u003cp\u003eIt also assigns the "roles/eventarc.eventReceiver" role to the service account, which provides the ability to receive events.\u003c/p\u003e\n"],["\u003cp\u003eThe service account is further granted the "roles/logging.logWriter" role, enabling it to write logs.\u003c/p\u003e\n"]]],[],null,["# Create a trigger using Terraform (service account)\n\nCreates a service account and grants permissions.\n\nExplore further\n---------------\n\n\nFor detailed documentation that includes this code sample, see the following:\n\n- [Create a trigger using Terraform](/eventarc/docs/creating-triggers-terraform)\n\nCode sample\n-----------\n\n### Terraform\n\n\nTo learn how to apply or remove a Terraform configuration, see\n[Basic Terraform commands](/docs/terraform/basic-commands).\n\n\nFor more information, see the\n[Terraform provider reference documentation](https://registry.terraform.io/providers/hashicorp/google/latest/docs).\n\n # Used to retrieve project information later\n data \"google_project\" \"project\" {}\n\n # Create a service account for Eventarc trigger and Workflows\n resource \"google_service_account\" \"eventarc\" {\n account_id = \"eventarc-workflows-sa\"\n display_name = \"Eventarc Workflows Service Account\"\n }\n\n # Grant permission to invoke Workflows\n resource \"google_project_iam_member\" \"workflowsinvoker\" {\n project = data.google_project.project.id\n role = \"roles/workflows.invoker\"\n member = \"serviceAccount:${google_service_account.eventarc.email}\"\n }\n\n # Grant permission to receive events\n resource \"google_project_iam_member\" \"eventreceiver\" {\n project = data.google_project.project.id\n role = \"roles/eventarc.eventReceiver\"\n member = \"serviceAccount:${google_service_account.eventarc.email}\"\n }\n\n # Grant permission to write logs\n resource \"google_project_iam_member\" \"logwriter\" {\n project = data.google_project.project.id\n role = \"roles/logging.logWriter\"\n member = \"serviceAccount:${google_service_account.eventarc.email}\"\n }\n\nWhat's next\n-----------\n\n\nTo search and filter code samples for other Google Cloud products, see the\n[Google Cloud sample browser](/docs/samples?product=eventarc)."]]