googleapi: Error 403: Permission '' denied on resource

211 views Asked by At

I'm trying to make a cloud run service publicly accessible using terraform. I can successfully create the service with terraform but when trying to set IAM permissions I get a 403 error.

The terraform service account associated with var.credentials_file has the owner role (just for checking).

My terreform setup below:

terraform {
  required_providers {
    google = {
      source  = "hashicorp/google"
      version = "4.51.0"

provider "google" {
  credentials = file(var.credentials_file)
  project = var.project
  region  = var.region

resource "google_cloud_run_v2_service" "terra_demo" {
  name     = "cloudrun-service-demo"
  location = var.region
  ingress  = "INGRESS_TRAFFIC_ALL"

  template {
    containers {
      image = "${var.project}/${var.container_repository}/${var.container_name}"
  depends_on = []

resource "google_cloud_run_service_iam_binding" "default" {
  location = google_cloud_run_v2_service.terra_demo.location
  service  =
  role     = "roles/run.invoker"
  members = [


There are 1 answers

sam On

This turned out to be a misunderstanding of IAM roles.

If terraform user set to owner here: it works ok.

Instead of from which doesn't work