-
Notifications
You must be signed in to change notification settings - Fork 3
/
storage.tf
49 lines (37 loc) · 1.24 KB
/
storage.tf
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
# Storage bucket for public files.
resource "google_storage_bucket" "public" {
count = var.enable_storage ? 1 : 0
name = "${var.subdomain_prefix}storage.${var.top_domain}"
location = var.storage_bucket_location
storage_class = var.storage_bucket_class
uniform_bucket_level_access = false
force_destroy = true
cors {
origin = ["*"]
method = ["*"]
response_header = ["*"]
max_age_seconds = 3600
}
}
# Allow access to the public bucket.
resource "google_storage_bucket_iam_member" "public" {
count = var.enable_storage ? 1 : 0
bucket = google_storage_bucket.public[0].name
role = "roles/storage.legacyObjectReader"
member = "allUsers"
}
# Storage bucket for private files.
resource "google_storage_bucket" "private" {
count = var.enable_storage ? 1 : 0
name = "${var.subdomain_prefix}private-storage.${var.top_domain}"
location = var.storage_bucket_location
storage_class = var.storage_bucket_class
uniform_bucket_level_access = false
force_destroy = true
cors {
origin = ["*"]
method = ["*"]
response_header = ["*"]
max_age_seconds = 3600
}
}