Skip to content

chore(deps): update custom docker images (loose) to v20260416101041#14060

Merged
renovate[bot] merged 1 commit intomainfrom
renovate/custom-docker-images-(loose)-to-v20260416101041
Apr 16, 2026
Merged

chore(deps): update custom docker images (loose) to v20260416101041#14060
renovate[bot] merged 1 commit intomainfrom
renovate/custom-docker-images-(loose)-to-v20260416101041

Conversation

@renovate
Copy link
Copy Markdown
Contributor

@renovate renovate bot commented Apr 16, 2026

This PR contains the following updates:

Package Update Change
europe-docker.pkg.dev/kyma-project/prod/test-infra/rotate-service-account major v20260414004024v20260416101041
europe-docker.pkg.dev/kyma-project/prod/test-infra/service-account-keys-cleaner major v20260414004024v20260416101041

Configuration

📅 Schedule: (UTC)

  • Branch creation
    • At any time (no schedule defined)
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Enabled.

Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about these updates again.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@renovate renovate bot requested a review from a team as a code owner April 16, 2026 15:08
@renovate renovate bot enabled auto-merge April 16, 2026 15:08
Copy link
Copy Markdown

@neighbors-bot neighbors-bot left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Auto approval of PR generated by Renovate Bot

Copy link
Copy Markdown

@neighbors-bot neighbors-bot left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Auto approval of PR generated by Renovate Bot

@neighbors-bot neighbors-bot added the auto-approved Denotes a PR that was approved by automation. label Apr 16, 2026
@kyma-bot
Copy link
Copy Markdown
Contributor

Plan Result

CI link

Plan: 0 to add, 2 to change, 0 to destroy.
  • Update
    • module.service_account_keys_cleaner.google_cloud_run_service.service_account_keys_cleaner
    • module.service_account_keys_rotator.google_cloud_run_service.service_account_keys_rotator
Change Result (Click me)
  # module.service_account_keys_cleaner.google_cloud_run_service.service_account_keys_cleaner will be updated in-place
  ~ resource "google_cloud_run_service" "service_account_keys_cleaner" {
        id                         = "locations/europe-west4/namespaces/sap-kyma-prow/services/service-account-keys-cleaner"
        name                       = "service-account-keys-cleaner"
        # (4 unchanged attributes hidden)

      ~ template {
          ~ spec {
                # (4 unchanged attributes hidden)

              ~ containers {
                  ~ image   = "europe-docker.pkg.dev/kyma-project/prod/test-infra/service-account-keys-cleaner:v20260414004024" -> "europe-docker.pkg.dev/kyma-project/prod/test-infra/service-account-keys-cleaner:v20260416101041"
                    # (2 unchanged attributes hidden)

                    # (6 unchanged blocks hidden)
                }
            }

            # (1 unchanged block hidden)
        }

        # (2 unchanged blocks hidden)
    }

  # module.service_account_keys_rotator.google_cloud_run_service.service_account_keys_rotator will be updated in-place
  ~ resource "google_cloud_run_service" "service_account_keys_rotator" {
        id                         = "locations/europe-west4/namespaces/sap-kyma-prow/services/service-account-keys-rotator"
        name                       = "service-account-keys-rotator"
        # (4 unchanged attributes hidden)

      ~ template {
          ~ spec {
                # (4 unchanged attributes hidden)

              ~ containers {
                  ~ image   = "europe-docker.pkg.dev/kyma-project/prod/test-infra/rotate-service-account:v20260414004024" -> "europe-docker.pkg.dev/kyma-project/prod/test-infra/rotate-service-account:v20260416101041"
                    name    = "rotate-service-account-1"
                    # (2 unchanged attributes hidden)

                    # (6 unchanged blocks hidden)
                }
            }

            # (1 unchanged block hidden)
        }

        # (2 unchanged blocks hidden)
    }

Plan: 0 to add, 2 to change, 0 to destroy.

Changes to Outputs:
  ~ service_account_keys_cleaner                   = {
      ~ service_account_keys_cleaner_cloud_run_service = {
            id                         = "locations/europe-west4/namespaces/sap-kyma-prow/services/service-account-keys-cleaner"
            name                       = "service-account-keys-cleaner"
          ~ template                   = [
              ~ {
                  ~ spec     = [
                      ~ {
                          ~ containers            = [
                              ~ {
                                  ~ image           = "europe-docker.pkg.dev/kyma-project/prod/test-infra/service-account-keys-cleaner:v20260414004024" -> "europe-docker.pkg.dev/kyma-project/prod/test-infra/service-account-keys-cleaner:v20260416101041"
                                    name            = ""
                                    # (11 unchanged attributes hidden)
                                },
                            ]
                            # (6 unchanged attributes hidden)
                        },
                    ]
                    # (1 unchanged attribute hidden)
                },
            ]
            # (7 unchanged attributes hidden)
        }
        # (2 unchanged attributes hidden)
    }
  ~ service_account_keys_rotator                   = {
      ~ service_account_keys_rotator_cloud_run_service   = {
            id                         = "locations/europe-west4/namespaces/sap-kyma-prow/services/service-account-keys-rotator"
            name                       = "service-account-keys-rotator"
          ~ template                   = [
              ~ {
                  ~ spec     = [
                      ~ {
                          ~ containers            = [
                              ~ {
                                  ~ image           = "europe-docker.pkg.dev/kyma-project/prod/test-infra/rotate-service-account:v20260414004024" -> "europe-docker.pkg.dev/kyma-project/prod/test-infra/rotate-service-account:v20260416101041"
                                    name            = "rotate-service-account-1"
                                    # (11 unchanged attributes hidden)
                                },
                            ]
                            # (6 unchanged attributes hidden)
                        },
                    ]
                    # (1 unchanged attribute hidden)
                },
            ]
            # (7 unchanged attributes hidden)
        }
        # (3 unchanged attributes hidden)
    }
ℹ️ Objects have changed outside of Terraform

This feature was introduced from Terraform v0.15.4.

OpenTofu detected the following changes made outside of OpenTofu since the
last "tofu apply" which may have affected this plan:

  # module.chainguard_cache.google_artifact_registry_repository.protected_repository[0] has changed
  ~ resource "google_artifact_registry_repository" "protected_repository" {
        id                     = "projects/kyma-project/locations/europe/repositories/chainguard-cache"
        name                   = "chainguard-cache"
      ~ update_time            = "2026-04-16T10:10:52.431666Z" -> "2026-04-16T14:57:46.544381Z"
        # (12 unchanged attributes hidden)

        # (2 unchanged blocks hidden)
    }

  # module.dev_docker_repository.google_artifact_registry_repository.protected_repository[0] has changed
  ~ resource "google_artifact_registry_repository" "protected_repository" {
        id                     = "projects/kyma-project/locations/europe/repositories/dev"
        name                   = "dev"
      ~ update_time            = "2026-04-16T10:37:03.409870Z" -> "2026-04-16T15:01:28.341049Z"
        # (12 unchanged attributes hidden)

        # (4 unchanged blocks hidden)
    }

  # module.docker_cache.google_artifact_registry_repository.unprotected_repository[0] has changed
  ~ resource "google_artifact_registry_repository" "unprotected_repository" {
        id                     = "projects/kyma-project/locations/europe/repositories/cache"
        name                   = "cache"
      ~ update_time            = "2026-04-16T10:37:17.724562Z" -> "2026-04-16T15:03:14.744568Z"
        # (12 unchanged attributes hidden)

        # (4 unchanged blocks hidden)
    }

  # module.dockerhub_mirror.google_artifact_registry_repository.unprotected_repository[0] has changed
  ~ resource "google_artifact_registry_repository" "unprotected_repository" {
        id                     = "projects/kyma-project/locations/europe/repositories/dockerhub-mirror"
        name                   = "dockerhub-mirror"
      ~ update_time            = "2026-04-16T10:02:11.425083Z" -> "2026-04-16T14:05:20.542370Z"
        # (12 unchanged attributes hidden)

        # (2 unchanged blocks hidden)
    }

  # module.kyma_restricted_images_dev.google_artifact_registry_repository.protected_repository[0] has changed
  ~ resource "google_artifact_registry_repository" "protected_repository" {
        id                     = "projects/kyma-project/locations/europe/repositories/kyma-restricted-images-dev"
        name                   = "kyma-restricted-images-dev"
      ~ update_time            = "2026-04-16T10:36:45.562010Z" -> "2026-04-16T14:52:04.928135Z"
        # (12 unchanged attributes hidden)

        # (4 unchanged blocks hidden)
    }

  # module.kyma_restricted_images_prod.google_artifact_registry_repository.protected_repository[0] has changed
  ~ resource "google_artifact_registry_repository" "protected_repository" {
        id                     = "projects/kyma-project/locations/europe/repositories/kyma-restricted-images-prod"
        name                   = "kyma-restricted-images-prod"
      ~ update_time            = "2026-04-16T10:37:08.395753Z" -> "2026-04-16T14:52:31.284756Z"
        # (12 unchanged attributes hidden)

        # (3 unchanged blocks hidden)
    }

  # module.prod_docker_repository.google_artifact_registry_repository.protected_repository[0] has changed
  ~ resource "google_artifact_registry_repository" "protected_repository" {
        id                     = "projects/kyma-project/locations/europe/repositories/prod"
        name                   = "prod"
      ~ update_time            = "2026-04-16T10:34:51.323028Z" -> "2026-04-16T14:57:43.844774Z"
        # (12 unchanged attributes hidden)

        # (2 unchanged blocks hidden)
    }


Unless you have made equivalent changes to your configuration, or ignored the

@renovate renovate bot added this pull request to the merge queue Apr 16, 2026
Merged via the queue into main with commit 313d73a Apr 16, 2026
48 checks passed
@renovate renovate bot deleted the renovate/custom-docker-images-(loose)-to-v20260416101041 branch April 16, 2026 15:19
@kyma-bot
Copy link
Copy Markdown
Contributor

✅ Apply Result

CI link

Apply complete! Resources: 0 added, 2 changed, 0 destroyed.
Details (Click me)
Acquiring state lock. This may take a few moments...
data.github_organization.kyma_project: Reading...
data.github_repository.gitleaks_repository["test-infra"]: Reading...
data.github_repository.test_infra: Reading...
github_actions_organization_variable.gcp_kyma_project_project_id: Refreshing state... [id=GCP_KYMA_PROJECT_PROJECT_ID]
github_actions_variable.github_terraform_planner_secret_name: Refreshing state... [id=test-infra:GH_TERRAFORM_PLANNER_SECRET_NAME]
github_actions_variable.github_terraform_executor_secret_name: Refreshing state... [id=test-infra:GH_TERRAFORM_EXECUTOR_SECRET_NAME]
github_actions_organization_variable.image_builder_ado_pat_gcp_secret_name: Refreshing state... [id=IMAGE_BUILDER_ADO_PAT_GCP_SECRET_NAME]
google_service_account.sa-secret-update: Refreshing state... [id=projects/sap-kyma-prow/serviceAccounts/sa-secret-update@sap-kyma-prow.iam.gserviceaccount.com]
google_secret_manager_secret.modg_github_app_client_secret_staging: Refreshing state... [id=projects/sap-kyma-prow/secrets/security-scanner_staging-modg_github-app-client-secret-staging]
google_service_account.terraform_executor: Refreshing state... [id=projects/sap-kyma-prow/serviceAccounts/terraform-executor@sap-kyma-prow.iam.gserviceaccount.com]
module.signify_secret_rotator.data.google_monitoring_notification_channel.kyma_tooling: Reading...
google_service_account.secrets-rotator: Refreshing state... [id=projects/sap-kyma-prow/serviceAccounts/secrets-rotator@sap-kyma-prow.iam.gserviceaccount.com]
google_secret_manager_secret.doc_collector_internal_github_token: Refreshing state... [id=projects/sap-kyma-prow/secrets/technical-writers-docsync-workflow-gh-tools-neighbors-token]
google_service_account.terraform-planner: Refreshing state... [id=projects/sap-kyma-prow/serviceAccounts/terraform-planner@sap-kyma-prow.iam.gserviceaccount.com]
google_service_account.sa-dev-kyma-project: Refreshing state... [id=projects/sap-kyma-prow/serviceAccounts/sa-dev-kyma-project@sap-kyma-prow.iam.gserviceaccount.com]
google_service_account.busola_staging_ocm_builder: Refreshing state... [id=projects/sap-kyma-prow/serviceAccounts/busola-staging-ocm-builder@sap-kyma-prow.iam.gserviceaccount.com]
google_service_account.sec-scanner-cfg-processor: Refreshing state... [id=projects/sap-kyma-prow/serviceAccounts/sec-scanner-cfg-processor@sap-kyma-prow.iam.gserviceaccount.com]
module.signify_secret_rotator.data.google_monitoring_notification_channel.kyma_tooling: Read complete after 0s [id=projects/sap-kyma-prow/notificationChannels/5909844679104799956]
google_service_account.kyma-security-scanners: Refreshing state... [id=projects/sap-kyma-prow/serviceAccounts/kyma-security-scanners@sap-kyma-prow.iam.gserviceaccount.com]
google_dns_managed_zone.build_kyma: Refreshing state... [id=projects/sap-kyma-prow/managedZones/build-kyma]
google_service_account.image_syncer_reader: Refreshing state... [id=projects/sap-kyma-prow/serviceAccounts/image-syncer-reader@sap-kyma-prow.iam.gserviceaccount.com]
google_secret_manager_secret.modg_bdba_bot_api_key_staging: Refreshing state... [id=projects/sap-kyma-prow/secrets/security-scanner_staging-modg_bdba-bot-api-key-staging]
module.service_account_keys_rotator.data.google_project.project: Reading...
google_service_account.gitleaks_secret_accesor: Refreshing state... [id=projects/sap-kyma-prow/serviceAccounts/gitleaks-secret-accesor@sap-kyma-prow.iam.gserviceaccount.com]
module.github_webhook_gateway.data.google_secret_manager_secret.gh_tools_kyma_bot_token: Reading...
data.google_secret_manager_secret_version.dockerhub_oat_secret[0]: Reading...
google_service_account.gitleaks-secret-accesor: Refreshing state... [id=projects/sap-kyma-prow/serviceAccounts/gitleaks-secret-accesor@sap-kyma-prow.iam.gserviceaccount.com]
module.github_webhook_gateway.data.google_secret_manager_secret.gh_tools_kyma_bot_token: Read complete after 0s [id=projects/sap-kyma-prow/secrets/trusted_default_kyma-bot-github-sap-token]
google_secret_manager_secret.chainguard_pull_token: Refreshing state... [id=projects/sap-kyma-prow/secrets/chainguard_auth_token]
google_project_iam_member.kyma_developer_admin_editor: Refreshing state... [id=kyma-project/roles/editor/group:kyma_developer_admin@sap.com]
google_cloud_identity_group_membership.image_builder_group_to_dev_read: Refreshing state... [id=groups/0184mhaj2tdduaw/memberships/01fob9te0l19xwg]
data.google_secret_manager_secret_version.dockerhub_oat_secret[0]: Read complete after 0s [id=projects/351981214969/secrets/docker_sap_org_service_auth_token/versions/1]
module.prod_docker_repository.google_artifact_registry_repository.protected_repository[0]: Refreshing state... [id=projects/kyma-project/locations/europe/repositories/prod]
module.service_account_keys_rotator.data.google_project.project: Read complete after 0s [id=projects/sap-kyma-prow]
module.kyma_restricted_images_prod.google_artifact_registry_repository.protected_repository[0]: Refreshing state... [id=projects/kyma-project/locations/europe/repositories/kyma-restricted-images-prod]
google_service_account.sa-security-dashboard-oauth: Refreshing state... [id=projects/sap-kyma-prow/serviceAccounts/sa-security-dashboard-oauth@sap-kyma-prow.iam.gserviceaccount.com]
google_secret_manager_secret.internal_github_terraform_executor: Refreshing state... [id=projects/sap-kyma-prow/secrets/iac-bot-gh-tools-sap-terraform-executor-token]
data.google_client_config.gcp: Reading...
data.google_client_config.gcp: Read complete after 0s [id=projects/sap-kyma-prow/regions/europe-west4/zones/]
google_cloud_identity_group_membership.developers_group_to_prod_read: Refreshing state... [id=groups/00xvir7l1dtv8ew/memberships/02koq65619rujz4]
module.dev_docker_repository.google_artifact_registry_repository.protected_repository[0]: Refreshing state... [id=projects/kyma-project/locations/europe/repositories/dev]
module.dev_kyma_modules.google_artifact_registry_repository.unprotected_repository[0]: Refreshing state... [id=projects/kyma-project/locations/europe/repositories/dev-kyma-modules]
google_service_account.restricted-markets-artifactregistry-reader: Refreshing state... [id=projects/sap-kyma-prow/serviceAccounts/restricted-markets-reg-reader@sap-kyma-prow.iam.gserviceaccount.com]
google_secret_manager_secret.image_builder_sa_key_restricted_markets: Refreshing state... [id=projects/sap-kyma-prow/secrets/image-builder-sa-key-restricted-markets]
google_cloud_identity_group_membership.security_scanners_group_to_dev_read: Refreshing state... [id=groups/0184mhaj2tdduaw/memberships/00meukdy10z0qky]
google_service_account.kyma-oci-image-builder: Refreshing state... [id=projects/sap-kyma-prow/serviceAccounts/kyma-oci-image-builder@sap-kyma-prow.iam.gserviceaccount.com]
module.security_dashboard_token.google_cloud_run_service.security_dashboard_token: Refreshing state... [id=locations/europe-west1/namespaces/sap-kyma-prow/services/security-dashboard-token]
google_secret_manager_secret.internal_github_terraform_planner: Refreshing state... [id=projects/sap-kyma-prow/secrets/iac-bot-gh-tools-sap-terraform-planner-token]
module.github_webhook_gateway.data.google_secret_manager_secret.webhook_token: Reading...
module.signify_secret_rotator.data.google_project.project: Reading...
module.github_webhook_gateway.data.google_secret_manager_secret.webhook_token: Read complete after 0s [id=projects/sap-kyma-prow/secrets/sap-tools-github-backlog-webhook-secret]
google_secret_manager_secret.dora_integration_internal_github_token: Refreshing state... [id=projects/sap-kyma-prow/secrets/dora-integration-gh-tools-serviceuser-token]
module.github_webhook_gateway.data.google_iam_policy.noauth: Reading...
module.github_webhook_gateway.data.google_iam_policy.noauth: Read complete after 0s [id=3450855414]
module.service_account_keys_cleaner.data.google_project.project: Reading...
google_secret_manager_secret.sec-scanner-cfg-processor-gcp-sa-key: Refreshing state... [id=projects/sap-kyma-prow/secrets/sec-scanner-cfg-gcp-sa-key]
module.github_webhook_gateway.google_service_account.github_webhook_gateway: Refreshing state... [id=projects/sap-kyma-prow/serviceAccounts/github-webhook-gateway@sap-kyma-prow.iam.gserviceaccount.com]
module.security_dashboard_token.data.google_iam_policy.noauth: Reading...
module.security_dashboard_token.data.google_iam_policy.noauth: Read complete after 0s [id=3450855414]
module.service_account_keys_cleaner.google_service_account.service_account_keys_cleaner: Refreshing state... [id=projects/sap-kyma-prow/serviceAccounts/sa-keys-cleaner@sap-kyma-prow.iam.gserviceaccount.com]
module.slack_message_sender.data.google_secret_manager_secret.common_slack_bot_token: Reading...
module.signify_secret_rotator.data.google_project.project: Read complete after 0s [id=projects/sap-kyma-prow]
google_cloud_identity_group_membership.image_builder_group_to_dev_write: Refreshing state... [id=groups/023ckvvd0rmgw6a/memberships/01fob9te0l19xwg]
data.google_monitoring_notification_channel.kyma_tooling: Reading...
module.dev_docker_repository.data.google_client_config.this: Reading...
module.dev_docker_repository.data.google_client_config.this: Read complete after 0s [id=projects/kyma-project/regions/europe-west4/zones/]
module.chainguard_cache.data.google_client_config.this: Reading...
module.chainguard_cache.data.google_client_config.this: Read complete after 0s [id=projects/kyma-project/regions/europe-west4/zones/]
module.prod_docker_repository.data.google_client_config.this: Reading...
module.prod_docker_repository.data.google_client_config.this: Read complete after 0s [id=projects/kyma-project/regions/europe-west4/zones/]
google_service_account.kyma_project_image_builder: Refreshing state... [id=projects/kyma-project/serviceAccounts/azure-pipeline-image-builder@kyma-project.iam.gserviceaccount.com]
google_project_iam_member.kyma_developer_admin_logging_viewer: Refreshing state... [id=kyma-project/roles/logging.viewer/group:kyma_developer_admin@sap.com]
module.slack_message_sender.data.google_secret_manager_secret.common_slack_bot_token: Read complete after 0s [id=projects/sap-kyma-prow/secrets/common-slack-bot-token]
data.google_project.kyma_project: Reading...
module.service_account_keys_cleaner.data.google_project.project: Read complete after 0s [id=projects/sap-kyma-prow]
module.dockerhub_mirror.data.google_client_config.this: Reading...
module.dockerhub_mirror.data.google_client_config.this: Read complete after 0s [id=projects/kyma-project/regions/europe-west4/zones/]
google_project_iam_member.kyma_developer_admin_private_logging_viewer: Refreshing state... [id=kyma-project/roles/logging.privateLogViewer/group:kyma_developer_admin@sap.com]
module.kyma_restricted_images_dev.data.google_client_config.this: Reading...
module.kyma_restricted_images_dev.data.google_client_config.this: Read complete after 0s [id=projects/kyma-project/regions/europe-west4/zones/]
module.kyma_restricted_images_prod.data.google_client_config.this: Reading...
module.kyma_restricted_images_prod.data.google_client_config.this: Read complete after 0s [id=projects/kyma-project/regions/europe-west4/zones/]
module.signify_secret_rotator.google_service_account.signify_secret_rotator: Refreshing state... [id=projects/sap-kyma-prow/serviceAccounts/signify-rotator@sap-kyma-prow.iam.gserviceaccount.com]
module.github_webhook_gateway.google_pubsub_topic.issue_labeled: Refreshing state... [id=projects/sap-kyma-prow/topics/issue-labeled]
google_storage_bucket.secret-rotator-dead-letters-bucket: Refreshing state... [id=secrets-rotator-dead-letters]
data.google_monitoring_notification_channel.kyma_tooling: Read complete after 0s [id=projects/sap-kyma-prow/notificationChannels/5909844679104799956]
google_pubsub_topic.secrets_rotator_dead_letter: Refreshing state... [id=projects/sap-kyma-prow/topics/secrets-rotator-dead-letter]
data.google_project.kyma_project: Read complete after 0s [id=projects/kyma-project]
google_cloud_identity_group_membership.markets_delivery_group_to_prod_read: Refreshing state... [id=groups/00xvir7l1dtv8ew/memberships/03fwokq04jj0scm]
module.kyma_restricted_images_dev.google_artifact_registry_repository.protected_repository[0]: Refreshing state... [id=projects/kyma-project/locations/europe/repositories/kyma-restricted-images-dev]
data.google_project.current: Reading...
google_service_account.kyma-submission-pipeline: Refreshing state... [id=projects/sap-kyma-prow/serviceAccounts/kyma-submission-pipeline@sap-kyma-prow.iam.gserviceaccount.com]
data.google_pubsub_topic.secret-manager-notifications-topic: Reading...
google_cloud_identity_group_membership.developers_group_to_dev_write: Refreshing state... [id=groups/023ckvvd0rmgw6a/memberships/02koq65619rujz4]
google_cloud_identity_group_membership.image_signer_group_to_prod_read: Refreshing state... [id=groups/00xvir7l1dtv8ew/memberships/01yyy98l2u8q924]
google_service_account.terraform-executor: Refreshing state... [id=projects/sap-kyma-prow/serviceAccounts/terraform-executor@sap-kyma-prow.iam.gserviceaccount.com]
data.google_pubsub_topic.secret-manager-notifications-topic: Read complete after 0s [id=projects/sap-kyma-prow/topics/secret-manager-notifications]
google_service_account.terraform_planner: Refreshing state... [id=projects/sap-kyma-prow/serviceAccounts/terraform-planner@sap-kyma-prow.iam.gserviceaccount.com]
google_secret_manager_secret.modg_github_app_private_key_staging: Refreshing state... [id=projects/sap-kyma-prow/secrets/security-scanner_staging-modg_github-app-private-key-staging]
google_service_account.image_syncer_writer: Refreshing state... [id=projects/sap-kyma-prow/serviceAccounts/image-syncer-writer@sap-kyma-prow.iam.gserviceaccount.com]
data.google_project.current: Read complete after 1s [id=projects/sap-kyma-prow]
module.slack_message_sender.google_monitoring_alert_policy.slack_message_sender: Refreshing state... [id=projects/sap-kyma-prow/alertPolicies/17360148176148949136]
google_service_account.kyma_project_image_builder_restricted_markets: Refreshing state... [id=projects/kyma-project/serviceAccounts/img-builder-restricted-markets@kyma-project.iam.gserviceaccount.com]
module.slack_message_sender.google_service_account.slack_message_sender: Refreshing state... [id=projects/sap-kyma-prow/serviceAccounts/slack-message-sender@sap-kyma-prow.iam.gserviceaccount.com]
google_secret_manager_secret.kyma_modules_runtime_internal_github_token: Refreshing state... [id=projects/sap-kyma-prow/secrets/kyma-prow-serviceuser-internal-github-token]
google_service_account.kyma_modules_reader_staging_modg: Refreshing state... [id=projects/sap-kyma-prow/serviceAccounts/staging-modg-registry-reader@sap-kyma-prow.iam.gserviceaccount.com]
google_service_account.sa-kyma-project: Refreshing state... [id=projects/sap-kyma-prow/serviceAccounts/sa-kyma-project@sap-kyma-prow.iam.gserviceaccount.com]
google_cloud_identity_group_membership.image_builder_group_to_prod_read: Refreshing state... [id=groups/00xvir7l1dtv8ew/memberships/01fob9te0l19xwg]
google_service_account.kyma-modules-reader-modg: Refreshing state... [id=projects/sap-kyma-prow/serviceAccounts/modg-vuln-mgmt-reg-reader@sap-kyma-prow.iam.gserviceaccount.com]
module.service_account_keys_rotator.data.google_monitoring_notification_channel.kyma_tooling: Reading...
google_cloud_identity_group_membership.security_scanners_group_to_prod_read: Refreshing state... [id=groups/00xvir7l1dtv8ew/memberships/00meukdy10z0qky]
google_cloud_identity_group_membership.image_builder_group_to_prod_write: Refreshing state... [id=groups/01egqt2p1a2johw/memberships/01fob9te0l19xwg]
data.github_repository.test_infra: Read complete after 3s [id=test-infra]
google_cloud_identity_group_membership.developers_group_to_dev_read: Refreshing state... [id=groups/0184mhaj2tdduaw/memberships/02koq65619rujz4]
module.docker_cache.data.google_client_config.this: Reading...
module.docker_cache.data.google_client_config.this: Read complete after 0s [id=projects/kyma-project/regions/europe-west4/zones/]
google_secret_manager_secret.kyma_bot_public_github_token: Refreshing state... [id=projects/sap-kyma-prow/secrets/kyma-bot-github-public-repo-token]
module.dev_kyma_modules.data.google_client_config.this: Reading...
module.dev_kyma_modules.data.google_client_config.this: Read complete after 0s [id=projects/kyma-project/regions/europe-west4/zones/]
module.docker_cache.google_artifact_registry_repository.unprotected_repository[0]: Refreshing state... [id=projects/kyma-project/locations/europe/repositories/cache]
google_service_account.kyma_modules_reader: Refreshing state... [id=projects/kyma-project/serviceAccounts/kyma-modules-reader@kyma-project.iam.gserviceaccount.com]
module.service_account_keys_rotator.data.google_monitoring_notification_channel.kyma_tooling: Read complete after 0s [id=projects/sap-kyma-prow/notificationChannels/5909844679104799956]
google_service_account.neighbors-conduit-cli-builder: Refreshing state... [id=projects/sap-kyma-prow/serviceAccounts/neighbors-conduit-cli-builder@sap-kyma-prow.iam.gserviceaccount.com]
data.github_repository.gitleaks_repository["test-infra"]: Read complete after 3s [id=test-infra]
module.kyma_modules.data.google_client_config.this: Reading...
module.kyma_modules.data.google_client_config.this: Read complete after 0s [id=projects/kyma-project/regions/europe-west4/zones/]
module.service_account_keys_rotator.google_service_account.service_account_keys_rotator: Refreshing state... [id=projects/sap-kyma-prow/serviceAccounts/sa-keys-rotator@sap-kyma-prow.iam.gserviceaccount.com]
module.kyma_modules.google_artifact_registry_repository.protected_repository[0]: Refreshing state... [id=projects/kyma-project/locations/europe/repositories/kyma-modules]
module.service_account_keys_rotator.google_project_service_identity.pubsub_identity_agent: Refreshing state... [id=projects/sap-kyma-prow/services/pubsub.googleapis.com]
google_project_iam_member.terraform_executor_prow_project_owner: Refreshing state... [id=sap-kyma-prow/roles/owner/serviceAccount:terraform-executor@sap-kyma-prow.iam.gserviceaccount.com]
github_actions_variable.gcp_terraform_executor_service_account_email: Refreshing state... [id=test-infra:GCP_TERRAFORM_EXECUTOR_SERVICE_ACCOUNT_EMAIL]
module.signify_secret_rotator.google_monitoring_alert_policy.signify_secret_rotator_error_alert: Refreshing state... [id=projects/sap-kyma-prow/alertPolicies/5685251492968365145]
google_cloud_identity_group_membership.security_scanners_sa_to_hierarchical_group: Refreshing state... [id=groups/00meukdy10z0qky/memberships/116026471765855676444]
github_actions_organization_variable.image_syncer_reader_service_account_email_public_github: Refreshing state... [id=IMAGE_SYNCER_READER_SERVICE_ACCOUNT_EMAIL]
google_secret_manager_secret_iam_member.chainguard_token_terraform_planner_access: Refreshing state... [id=projects/sap-kyma-prow/secrets/chainguard_auth_token/roles/secretmanager.secretAccessor/serviceAccount:terraform-planner@sap-kyma-prow.iam.gserviceaccount.com]
data.google_secret_manager_secret_version.chainguard_pull_token_password: Reading...
github_actions_variable.internal_github_terraform_executor_secret_name: Refreshing state... [id=test-infra:INTERNAL_GITHUB_TERRAFORM_EXECUTOR_SECRET_NAME]
google_service_account_iam_member.restricted_markets_artifactregistry_reader_impersonation: Refreshing state... [id=projects/sap-kyma-prow/serviceAccounts/restricted-markets-reg-reader@sap-kyma-prow.iam.gserviceaccount.com/roles/iam.serviceAccountTokenCreator/serviceAccount:gcr-writer@sap-ti-dx-kyma-mps-dev.iam.gserviceaccount.com]
google_cloud_identity_group_membership.markets_delivery_sa_to_hierarchical_group: Refreshing state... [id=groups/03fwokq04jj0scm/memberships/116475765156525953628]
data.google_secret_manager_secret_version.chainguard_pull_token_password: Read complete after 0s [id=projects/351981214969/secrets/chainguard_auth_token/versions/1]
github_actions_variable.internal_github_terraform_planner_secret_name: Refreshing state... [id=test-infra:INTERNAL

# ...
# ... The maximum length of GitHub Comment is 65536, so the content is omitted by tfcmt.
# ...

        "asia-northeast3",
        "asia-south1",
        "asia-south2",
        "asia-southeast1",
        "asia-southeast2",
        "australia-southeast1",
        "australia-southeast2",
        "europe-central2",
        "europe-north1",
        "europe-southwest1",
        "europe-west1",
        "europe-west10",
        "europe-west12",
        "europe-west2",
        "europe-west3",
        "europe-west4",
        "europe-west6",
        "europe-west8",
        "europe-west9",
        "me-central1",
        "me-central2",
        "me-west1",
        "northamerica-northeast1",
        "northamerica-northeast2",
        "southamerica-east1",
        "southamerica-west1",
        "us-central1",
        "us-central2",
        "us-east1",
        "us-east4",
        "us-east5",
        "us-east7",
        "us-south1",
        "us-west1",
        "us-west2",
        "us-west3",
        "us-west4",
        "us-west8",
      ])
      "enforce_in_transit" = false
    },
  ])
  "message_transforms" = tolist([])
  "name" = "secrets-rotator-dead-letter"
  "project" = "sap-kyma-prow"
  "schema_settings" = tolist([])
  "tags" = tomap(null) /* of string */
  "terraform_labels" = tomap({
    "application" = "secrets-rotator"
  })
  "timeouts" = null /* object */
}
service_account_keys_cleaner = {
  "service_account_keys_cleaner_cloud_run_service" = {
    "autogenerate_revision_name" = false
    "id" = "locations/europe-west4/namespaces/sap-kyma-prow/services/service-account-keys-cleaner"
    "location" = "europe-west4"
    "metadata" = tolist([
      {
        "annotations" = tomap({})
        "effective_annotations" = tomap({
          "run.googleapis.com/ingress" = "all"
          "run.googleapis.com/ingress-status" = "all"
          "run.googleapis.com/operation-id" = "b8f7e760-423d-4b85-98d0-b0b321725593"
          "run.googleapis.com/urls" = "[\"https://service-account-keys-cleaner-351981214969.europe-west4.run.app\",\"https://service-account-keys-cleaner-q25ja7ch3q-ez.a.run.app\"]"
          "serving.knative.dev/creator" = "kacper.malachowski@sap.com"
          "serving.knative.dev/lastModifier" = "terraform-executor@sap-kyma-prow.iam.gserviceaccount.com"
        })
        "effective_labels" = tomap({
          "cloud.googleapis.com/location" = "europe-west4"
        })
        "generation" = 335
        "labels" = tomap({})
        "namespace" = "sap-kyma-prow"
        "resource_version" = "AAZPZoE/gBw"
        "self_link" = "/apis/serving.knative.dev/v1/namespaces/351981214969/services/service-account-keys-cleaner"
        "terraform_labels" = tomap({})
        "uid" = "b294b2a5-1c7d-4ab2-a8e3-ad27bbb0b00c"
      },
    ])
    "name" = "service-account-keys-cleaner"
    "project" = "sap-kyma-prow"
    "status" = tolist([
      {
        "conditions" = tolist([
          {
            "message" = ""
            "reason" = ""
            "status" = "True"
            "type" = "Ready"
          },
          {
            "message" = ""
            "reason" = ""
            "status" = "True"
            "type" = "ConfigurationsReady"
          },
          {
            "message" = ""
            "reason" = ""
            "status" = "True"
            "type" = "RoutesReady"
          },
        ])
        "latest_created_revision_name" = "service-account-keys-cleaner-00335-9nr"
        "latest_ready_revision_name" = "service-account-keys-cleaner-00335-9nr"
        "observed_generation" = 335
        "traffic" = tolist([
          {
            "latest_revision" = true
            "percent" = 100
            "revision_name" = "service-account-keys-cleaner-00335-9nr"
            "tag" = ""
            "url" = ""
          },
        ])
        "url" = "https://service-account-keys-cleaner-q25ja7ch3q-ez.a.run.app"
      },
    ])
    "template" = tolist([
      {
        "metadata" = tolist([
          {
            "annotations" = tomap({
              "autoscaling.knative.dev/maxScale" = "100"
            })
            "generation" = 0
            "labels" = tomap({
              "run.googleapis.com/startupProbeType" = "Default"
            })
            "name" = ""
            "namespace" = ""
            "resource_version" = ""
            "self_link" = ""
            "uid" = ""
          },
        ])
        "spec" = tolist([
          {
            "container_concurrency" = 80
            "containers" = tolist([
              {
                "args" = tolist([])
                "command" = tolist([])
                "env" = toset([
                  {
                    "name" = "APPLICATION_NAME"
                    "value" = "secrets-rotator"
                    "value_from" = tolist([])
                  },
                  {
                    "name" = "COMPONENT_NAME"
                    "value" = "service-account-keys-cleaner"
                    "value_from" = tolist([])
                  },
                  {
                    "name" = "LISTEN_PORT"
                    "value" = "8080"
                    "value_from" = tolist([])
                  },
                ])
                "env_from" = tolist([])
                "image" = "europe-docker.pkg.dev/kyma-project/prod/test-infra/service-account-keys-cleaner:v20260416101041"
                "liveness_probe" = tolist([])
                "name" = ""
                "ports" = tolist([
                  {
                    "container_port" = 8080
                    "name" = "http1"
                    "protocol" = ""
                  },
                ])
                "readiness_probe" = tolist([])
                "resources" = tolist([
                  {
                    "limits" = tomap({
                      "cpu" = "1000m"
                      "memory" = "512Mi"
                    })
                    "requests" = tomap({})
                  },
                ])
                "startup_probe" = tolist([
                  {
                    "failure_threshold" = 1
                    "grpc" = tolist([])
                    "http_get" = tolist([])
                    "initial_delay_seconds" = 0
                    "period_seconds" = 240
                    "tcp_socket" = tolist([
                      {
                        "port" = 8080
                      },
                    ])
                    "timeout_seconds" = 240
                  },
                ])
                "volume_mounts" = tolist([])
                "working_dir" = ""
              },
            ])
            "node_selector" = tomap({})
            "service_account_name" = "sa-keys-cleaner@sap-kyma-prow.iam.gserviceaccount.com"
            "serving_state" = ""
            "timeout_seconds" = 300
            "volumes" = tolist([])
          },
        ])
      },
    ])
    "timeouts" = null /* object */
    "traffic" = tolist([
      {
        "latest_revision" = true
        "percent" = 100
        "revision_name" = ""
        "tag" = ""
        "url" = ""
      },
    ])
  }
  "service_account_keys_cleaner_secheduler" = {
    "app_engine_http_target" = tolist([])
    "attempt_deadline" = "320s"
    "description" = "Call service account keys cleaner service, to remove old versions of secrets"
    "http_target" = tolist([
      {
        "body" = ""
        "headers" = tomap({})
        "http_method" = "GET"
        "oauth_token" = tolist([])
        "oidc_token" = tolist([
          {
            "audience" = "https://service-account-keys-cleaner-q25ja7ch3q-ez.a.run.app"
            "service_account_email" = "secrets-rotator@sap-kyma-prow.iam.gserviceaccount.com"
          },
        ])
        "uri" = "https://service-account-keys-cleaner-q25ja7ch3q-ez.a.run.app/?project=sap-kyma-prow&age=24"
      },
    ])
    "id" = "projects/sap-kyma-prow/locations/europe-west3/jobs/service-account-keys-cleaner"
    "name" = "service-account-keys-cleaner"
    "paused" = false
    "project" = "sap-kyma-prow"
    "pubsub_target" = tolist([])
    "region" = "europe-west3"
    "retry_config" = tolist([])
    "schedule" = "0 0 * * 1-5"
    "state" = "ENABLED"
    "time_zone" = "Etc/UTC"
    "timeouts" = null /* object */
  }
  "service_account_keys_cleaner_service_account" = {
    "account_id" = "sa-keys-cleaner"
    "create_ignore_already_exists" = tobool(null)
    "description" = "Identity of the service account keys rotator service."
    "disabled" = false
    "display_name" = ""
    "email" = "sa-keys-cleaner@sap-kyma-prow.iam.gserviceaccount.com"
    "id" = "projects/sap-kyma-prow/serviceAccounts/sa-keys-cleaner@sap-kyma-prow.iam.gserviceaccount.com"
    "member" = "serviceAccount:sa-keys-cleaner@sap-kyma-prow.iam.gserviceaccount.com"
    "name" = "projects/sap-kyma-prow/serviceAccounts/sa-keys-cleaner@sap-kyma-prow.iam.gserviceaccount.com"
    "project" = "sap-kyma-prow"
    "timeouts" = null /* object */
    "unique_id" = "101317727774651823048"
  }
}
service_account_keys_rotator = {
  "service_account_keys_rotator_cloud_run_service" = {
    "autogenerate_revision_name" = false
    "id" = "locations/europe-west4/namespaces/sap-kyma-prow/services/service-account-keys-rotator"
    "location" = "europe-west4"
    "metadata" = tolist([
      {
        "annotations" = tomap({})
        "effective_annotations" = tomap({
          "run.googleapis.com/client-name" = "cloud-console"
          "run.googleapis.com/ingress" = "all"
          "run.googleapis.com/ingress-status" = "all"
          "run.googleapis.com/operation-id" = "3a662521-355c-44a5-83b7-ae3c0bbbd4c9"
          "run.googleapis.com/urls" = "[\"https://service-account-keys-rotator-351981214969.europe-west4.run.app\",\"https://service-account-keys-rotator-q25ja7ch3q-ez.a.run.app\"]"
          "serving.knative.dev/creator" = "terraform-executor@sap-kyma-prow.iam.gserviceaccount.com"
          "serving.knative.dev/lastModifier" = "terraform-executor@sap-kyma-prow.iam.gserviceaccount.com"
        })
        "effective_labels" = tomap({
          "cloud.googleapis.com/location" = "europe-west4"
        })
        "generation" = 82
        "labels" = tomap({})
        "namespace" = "sap-kyma-prow"
        "resource_version" = "AAZPZoE19oM"
        "self_link" = "/apis/serving.knative.dev/v1/namespaces/351981214969/services/service-account-keys-rotator"
        "terraform_labels" = tomap({})
        "uid" = "da22718b-1d37-4c8f-ae89-25f875a06218"
      },
    ])
    "name" = "service-account-keys-rotator"
    "project" = "sap-kyma-prow"
    "status" = tolist([
      {
        "conditions" = tolist([
          {
            "message" = ""
            "reason" = ""
            "status" = "True"
            "type" = "Ready"
          },
          {
            "message" = ""
            "reason" = ""
            "status" = "True"
            "type" = "ConfigurationsReady"
          },
          {
            "message" = ""
            "reason" = ""
            "status" = "True"
            "type" = "RoutesReady"
          },
        ])
        "latest_created_revision_name" = "service-account-keys-rotator-00082-jbv"
        "latest_ready_revision_name" = "service-account-keys-rotator-00082-jbv"
        "observed_generation" = 82
        "traffic" = tolist([
          {
            "latest_revision" = true
            "percent" = 100
            "revision_name" = "service-account-keys-rotator-00082-jbv"
            "tag" = ""
            "url" = ""
          },
        ])
        "url" = "https://service-account-keys-rotator-q25ja7ch3q-ez.a.run.app"
      },
    ])
    "template" = tolist([
      {
        "metadata" = tolist([
          {
            "annotations" = tomap({
              "autoscaling.knative.dev/maxScale" = "100"
              "run.googleapis.com/client-name" = "cloud-console"
            })
            "generation" = 0
            "labels" = tomap({
              "client.knative.dev/nonce" = "7caecadf-7a51-4ea7-bda5-53e75a23890a"
              "run.googleapis.com/startupProbeType" = "Default"
            })
            "name" = ""
            "namespace" = ""
            "resource_version" = ""
            "self_link" = ""
            "uid" = ""
          },
        ])
        "spec" = tolist([
          {
            "container_concurrency" = 80
            "containers" = tolist([
              {
                "args" = tolist([])
                "command" = tolist([])
                "env" = toset([
                  {
                    "name" = "APPLICATION_NAME"
                    "value" = "secrets-rotator"
                    "value_from" = tolist([])
                  },
                  {
                    "name" = "COMPONENT_NAME"
                    "value" = "service-account-keys-rotator"
                    "value_from" = tolist([])
                  },
                  {
                    "name" = "LISTEN_PORT"
                    "value" = "8080"
                    "value_from" = tolist([])
                  },
                ])
                "env_from" = tolist([])
                "image" = "europe-docker.pkg.dev/kyma-project/prod/test-infra/rotate-service-account:v20260416101041"
                "liveness_probe" = tolist([])
                "name" = "rotate-service-account-1"
                "ports" = tolist([
                  {
                    "container_port" = 8080
                    "name" = "http1"
                    "protocol" = ""
                  },
                ])
                "readiness_probe" = tolist([])
                "resources" = tolist([
                  {
                    "limits" = tomap({
                      "cpu" = "1000m"
                      "memory" = "512Mi"
                    })
                    "requests" = tomap({})
                  },
                ])
                "startup_probe" = tolist([
                  {
                    "failure_threshold" = 1
                    "grpc" = tolist([])
                    "http_get" = tolist([])
                    "initial_delay_seconds" = 0
                    "period_seconds" = 240
                    "tcp_socket" = tolist([
                      {
                        "port" = 8080
                      },
                    ])
                    "timeout_seconds" = 240
                  },
                ])
                "volume_mounts" = tolist([])
                "working_dir" = ""
              },
            ])
            "node_selector" = tomap({})
            "service_account_name" = "sa-keys-rotator@sap-kyma-prow.iam.gserviceaccount.com"
            "serving_state" = ""
            "timeout_seconds" = 300
            "volumes" = tolist([])
          },
        ])
      },
    ])
    "timeouts" = null /* object */
    "traffic" = tolist([
      {
        "latest_revision" = true
        "percent" = 100
        "revision_name" = ""
        "tag" = ""
        "url" = ""
      },
    ])
  }
  "service_account_keys_rotator_service_account" = {
    "account_id" = "sa-keys-rotator"
    "create_ignore_already_exists" = tobool(null)
    "description" = "Identity of the service account keys rotator service."
    "disabled" = false
    "display_name" = ""
    "email" = "sa-keys-rotator@sap-kyma-prow.iam.gserviceaccount.com"
    "id" = "projects/sap-kyma-prow/serviceAccounts/sa-keys-rotator@sap-kyma-prow.iam.gserviceaccount.com"
    "member" = "serviceAccount:sa-keys-rotator@sap-kyma-prow.iam.gserviceaccount.com"
    "name" = "projects/sap-kyma-prow/serviceAccounts/sa-keys-rotator@sap-kyma-prow.iam.gserviceaccount.com"
    "project" = "sap-kyma-prow"
    "timeouts" = null /* object */
    "unique_id" = "116267434130697196528"
  }
  "service_account_keys_rotator_service_account_iam" = {
    "condition" = tolist([])
    "etag" = "BwZOPMlRDZc="
    "id" = "sap-kyma-prow/roles/iam.serviceAccountKeyAdmin/serviceAccount:sa-keys-rotator@sap-kyma-prow.iam.gserviceaccount.com"
    "member" = "serviceAccount:sa-keys-rotator@sap-kyma-prow.iam.gserviceaccount.com"
    "project" = "sap-kyma-prow"
    "role" = "roles/iam.serviceAccountKeyAdmin"
  }
  "service_account_keys_rotator_subscription" = {
    "ack_deadline_seconds" = 20
    "bigquery_config" = tolist([])
    "cloud_storage_config" = tolist([])
    "dead_letter_policy" = tolist([
      {
        "dead_letter_topic" = "projects/sap-kyma-prow/topics/secrets-rotator-dead-letter"
        "max_delivery_attempts" = 15
      },
    ])
    "effective_labels" = tomap({
      "application_name" = "secrets-rotator"
    })
    "enable_exactly_once_delivery" = false
    "enable_message_ordering" = false
    "expiration_policy" = tolist([
      {
        "ttl" = "31556952s"
      },
    ])
    "filter" = "attributes.eventType = \"SECRET_ROTATE\""
    "id" = "projects/sap-kyma-prow/subscriptions/secrets-rotator-service-account-keys-rotator"
    "labels" = tomap({
      "application_name" = "secrets-rotator"
    })
    "message_retention_duration" = "604800s"
    "message_transforms" = tolist([])
    "name" = "secrets-rotator-service-account-keys-rotator"
    "project" = "sap-kyma-prow"
    "push_config" = tolist([
      {
        "attributes" = tomap({})
        "no_wrapper" = tolist([])
        "oidc_token" = tolist([
          {
            "audience" = ""
            "service_account_email" = "secrets-rotator@sap-kyma-prow.iam.gserviceaccount.com"
          },
        ])
        "push_endpoint" = "https://service-account-keys-rotator-q25ja7ch3q-ez.a.run.app"
      },
    ])
    "retain_acked_messages" = false
    "retry_policy" = tolist([
      {
        "maximum_backoff" = "600s"
        "minimum_backoff" = "300s"
      },
    ])
    "tags" = tomap(null) /* of string */
    "terraform_labels" = tomap({
      "application_name" = "secrets-rotator"
    })
    "timeouts" = null /* object */
    "topic" = "projects/sap-kyma-prow/topics/secret-manager-notifications"
  }
}
terraform_executor_gcp_prow_project_iam_member = {
  "condition" = tolist([])
  "etag" = "BwZOPMlRDZc="
  "id" = "sap-kyma-prow/roles/owner/serviceAccount:terraform-executor@sap-kyma-prow.iam.gserviceaccount.com"
  "member" = "serviceAccount:terraform-executor@sap-kyma-prow.iam.gserviceaccount.com"
  "project" = "sap-kyma-prow"
  "role" = "roles/owner"
}
terraform_executor_gcp_service_account = {
  "account_id" = "terraform-executor"
  "create_ignore_already_exists" = tobool(null)
  "description" = "Identity of terraform executor. It's mapped to k8s service account through workload identity."
  "disabled" = false
  "display_name" = "terraform-executor"
  "email" = "terraform-executor@sap-kyma-prow.iam.gserviceaccount.com"
  "id" = "projects/sap-kyma-prow/serviceAccounts/terraform-executor@sap-kyma-prow.iam.gserviceaccount.com"
  "member" = "serviceAccount:terraform-executor@sap-kyma-prow.iam.gserviceaccount.com"
  "name" = "projects/sap-kyma-prow/serviceAccounts/terraform-executor@sap-kyma-prow.iam.gserviceaccount.com"
  "project" = "sap-kyma-prow"
  "timeouts" = null /* object */
  "unique_id" = "109665069699011807029"
}
terraform_executor_gcp_workload_identity = {
  "condition" = tolist([])
  "etag" = "BwZOc9ZzyOM="
  "id" = "projects/sap-kyma-prow/serviceAccounts/terraform-executor@sap-kyma-prow.iam.gserviceaccount.com/roles/iam.workloadIdentityUser"
  "members" = toset([
    "principal://iam.googleapis.com/projects/351981214969/locations/global/workloadIdentityPools/github.qkg1.top-kyma-project/subject/repository_id:147495537:repository_owner_id:39153523:workflow:Post Apply Prod Terraform",
    "principalSet://iam.googleapis.com/projects/351981214969/locations/global/workloadIdentityPools/github-tools-sap/attribute.deploy_identity/kyma/test-infra/.github/workflows/iac-deploy.yml:main",
    "principalSet://iam.googleapis.com/projects/351981214969/locations/global/workloadIdentityPools/github-tools-sap/attribute.deploy_identity/kyma/tooling-infra/.github/workflows/iac-deploy.yml:vtag",
  ])
  "role" = "roles/iam.workloadIdentityUser"
  "service_account_id" = "projects/sap-kyma-prow/serviceAccounts/terraform-executor@sap-kyma-prow.iam.gserviceaccount.com"
}

`

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

add-or-update auto-approved Denotes a PR that was approved by automation. renovate-dependencies

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants