diff --git a/mmv1/templates/terraform/examples/iam_deny_policy_basic.tf.erb b/mmv1/templates/terraform/examples/iam_deny_policy_basic.tf.erb index fcca132b6cd8..ce12af38140c 100644 --- a/mmv1/templates/terraform/examples/iam_deny_policy_basic.tf.erb +++ b/mmv1/templates/terraform/examples/iam_deny_policy_basic.tf.erb @@ -17,7 +17,7 @@ resource "google_iam_deny_policy" "<%= ctx[:primary_resource_id] %>" { title = "Some expr" expression = "!resource.matchTag('12345678/env', 'test')" } - denied_permissions = ["cloudresourcemanager.googleapis.com/projects.delete"] + denied_permissions = ["cloudresourcemanager.googleapis.com/projects.update"] } } rules { @@ -28,7 +28,7 @@ resource "google_iam_deny_policy" "<%= ctx[:primary_resource_id] %>" { title = "Some expr" expression = "!resource.matchTag('12345678/env', 'test')" } - denied_permissions = ["cloudresourcemanager.googleapis.com/projects.delete"] + denied_permissions = ["cloudresourcemanager.googleapis.com/projects.update"] exception_principals = ["principal://iam.googleapis.com/projects/-/serviceAccounts/${google_service_account.test-account.email}"] } } diff --git a/mmv1/third_party/terraform/services/iam2/resource_iam_deny_policy_test.go.erb b/mmv1/third_party/terraform/services/iam2/resource_iam_deny_policy_test.go.erb index 1e0d4c3c7752..8d18239df3af 100644 --- a/mmv1/third_party/terraform/services/iam2/resource_iam_deny_policy_test.go.erb +++ b/mmv1/third_party/terraform/services/iam2/resource_iam_deny_policy_test.go.erb @@ -111,7 +111,7 @@ resource "google_iam_deny_policy" "example" { title = "Some expr" expression = "!resource.matchTag('12345678/env', 'test')" } - denied_permissions = ["cloudresourcemanager.googleapis.com/projects.delete"] + denied_permissions = ["cloudresourcemanager.googleapis.com/projects.update"] } } rules { @@ -122,7 +122,7 @@ resource "google_iam_deny_policy" "example" { title = "Some expr" expression = "!resource.matchTag('12345678/env', 'test')" } - denied_permissions = ["cloudresourcemanager.googleapis.com/projects.delete"] + denied_permissions = ["cloudresourcemanager.googleapis.com/projects.update"] exception_principals = ["principal://iam.googleapis.com/projects/-/serviceAccounts/${google_service_account.test-account.email}"] } } @@ -159,7 +159,7 @@ resource "google_iam_deny_policy" "example" { location = "/some/file" description = "A denial condition" } - denied_permissions = ["cloudresourcemanager.googleapis.com/projects.delete"] + denied_permissions = ["cloudresourcemanager.googleapis.com/projects.update"] } } }