Step 3 - Nais terraforming the tenant¶
Here we describe the steps required to run through the terraform as this is not necessarily a straight forward process.
Nais-terraform-modules repository¶
- Copy an existing tenant folder to get have naas.tf and main.tf as templates.
- Update the naas.tf and main.tf files to represent desired reality.
- Add the new tenant to atlantis.yaml
console.cloud.gooogle.com -> nais-io project¶
- go to secret manager and create two empty secrets named:
-management-iap-client-id -management-iap-client-secret - location europe-north1, labels: "provisioned: manually"
- add dummy content to make sure we have a latest version
- grant the nais-tf-
@nais-io.iam.gserviceaccount.com the role roles/secretmanager.secretAccessor
on the secrets - add nais-tf-
@nais-io.iam.gserviceaccount.com to the domain https://search.google.com/search-console?resource_id=sc-domain%3Adoc. .cloud.nais.io