I am trying to set-up my terraform's main.tf by using service accounts that get impersonated by authorized users... I followed this guide to set this up, and it works, I can create a bucket within my project and within my organization.
Now in order to do more specific stuff, like declare these blocks
data "google_organization" "org" {
organization = var.organization.id
}
data "google_billing_account" "acct" {
billing_account = var.billing_account.id
open = var.billing_account.active
}
I figured (but I may be wrong) that I need to include more elements in the scope of my provider, like this :
provider "google" {
alias = "super_admin_impersonation"
scopes = [
"https://www.googleapis.com/auth/cloud-platform",
"https://www.googleapis.com/auth/userinfo.email",
"https://www.googleapis.com/auth/admin.directory.orgunit", # I added this
"https://www.googleapis.com/auth/cloud-billing" # And this
]
}
and so, also add them to the google_service_account_access_token block
data "google_service_account_access_token" "super_admin" {
provider = google.super_admin_impersonation
target_service_account = "${var.service_acc_terraform_super_admin.name}@${var.project_infra_genesis.id}.${var.service_acc_terraform_super_admin.suffix}"
scopes = ["cloud-platform", "userinfo-email", "admin.directory.orgunit", "cloud-billing"]
lifetime = "1200s"
}
The problem, is that when I add "admin.directory.orgunit", "cloud-billing" to this block's scope, I get this error :
╷
│ Error: googleapi: Error 400: Request contains an invalid argument., badRequest
│
│ with data.google_service_account_access_token.super_admin,
│ on main.tf line 22, in data "google_service_account_access_token" "super_admin":
│ 22: data "google_service_account_access_token" "super_admin" {
│
╵
Google's official Oauth2 scopes for their APIs is where I determine the names of scopes...
My question is: how do you know which scopes can be used in google_service_account_access_token? Is there a complete list I can refer to in order to include more in this block?