From 52d40d0714dfa9325e1e620c7cfc1e7c2ceb6259 Mon Sep 17 00:00:00 2001 From: Hayden Blauzvern Date: Thu, 25 Jan 2024 23:51:03 +0000 Subject: [PATCH] Add configuration for pubsub consumers to sigstore module Needed to configure in public instance deployment Signed-off-by: Hayden Blauzvern --- terraform/gcp/modules/sigstore/sigstore.tf | 2 ++ terraform/gcp/modules/sigstore/variables.tf | 5 +++++ 2 files changed, 7 insertions(+) diff --git a/terraform/gcp/modules/sigstore/sigstore.tf b/terraform/gcp/modules/sigstore/sigstore.tf index 44f17226d..36f7ac69a 100644 --- a/terraform/gcp/modules/sigstore/sigstore.tf +++ b/terraform/gcp/modules/sigstore/sigstore.tf @@ -218,6 +218,8 @@ module "rekor" { dns_zone_name = var.dns_zone_name dns_domain_name = var.dns_domain_name + new_entry_pubsub_consumers = var.rekor_new_entry_pubsub_consumers + redis_cluster_memory_size_gb = var.redis_cluster_memory_size_gb depends_on = [ diff --git a/terraform/gcp/modules/sigstore/variables.tf b/terraform/gcp/modules/sigstore/variables.tf index 6dee23e06..8cf23c2e3 100644 --- a/terraform/gcp/modules/sigstore/variables.tf +++ b/terraform/gcp/modules/sigstore/variables.tf @@ -260,6 +260,11 @@ variable "rekor_key_name" { default = "rekor-key" } +variable "rekor_new_entry_pubsub_consumers" { + type = list(string) + description = "List of IAM principals that can subscribe to events about new entries in the log" +} + variable "timestamp" { type = object({ enabled = bool