chore(cluster capacity): add group to registries.tf#8550
chore(cluster capacity): add group to registries.tf#8550k8s-ci-robot merged 1 commit intokubernetes:mainfrom
Conversation
|
atlantis plan |
|
Ran Plan for dir: Plan Failed: This project is currently locked by an unapplied plan from pull #8531. To continue, delete the lock from #8531 or apply that plan and merge the pull request. Once the lock is released, comment |
|
atlantis plan |
|
Ran Plan for dir: Show OutputNote: Objects have changed outside of Terraform
Terraform detected the following changes made outside of Terraform since the
last "terraform apply" which may have affected this plan:
# module.artifact_registry["charts"].google_artifact_registry_repository.repo has changed
~ resource "google_artifact_registry_repository" "repo" {
id = "projects/k8s-staging-images/locations/us-central1/repositories/charts"
name = "charts"
~ update_time = "2025-07-14T07:55:00.537673Z" -> "2025-09-11T13:37:24.624551Z"
# (12 unchanged attributes hidden)
# (1 unchanged block hidden)
}
# module.artifact_registry["cloud-provider-kind"].google_artifact_registry_repository.repo has changed
~ resource "google_artifact_registry_repository" "repo" {
id = "projects/k8s-staging-images/locations/us-central1/repositories/cloud-provider-kind"
name = "cloud-provider-kind"
~ update_time = "2025-08-21T13:41:55.219126Z" -> "2025-09-23T07:32:55.457597Z"
# (12 unchanged attributes hidden)
# (1 unchanged block hidden)
}
# module.artifact_registry["csi-vsphere"].google_artifact_registry_repository.repo has changed
~ resource "google_artifact_registry_repository" "repo" {
id = "projects/k8s-staging-images/locations/us-central1/repositories/csi-vsphere"
name = "csi-vsphere"
~ update_time = "2025-08-27T07:41:28.544978Z" -> "2025-09-23T15:41:25.834005Z"
# (12 unchanged attributes hidden)
# (1 unchanged block hidden)
}
# module.artifact_registry["dra-driver-cpu"].google_artifact_registry_repository.repo has changed
~ resource "google_artifact_registry_repository" "repo" {
id = "projects/k8s-staging-images/locations/us-central1/repositories/dra-driver-cpu"
name = "dra-driver-cpu"
~ update_time = "2025-08-05T18:10:48.010534Z" -> "2025-09-16T18:10:46.341991Z"
# (12 unchanged attributes hidden)
# (1 unchanged block hidden)
}
# module.artifact_registry["dra-example-driver"].google_artifact_registry_repository.repo has changed
~ resource "google_artifact_registry_repository" "repo" {
id = "projects/k8s-staging-images/locations/us-central1/repositories/dra-example-driver"
name = "dra-example-driver"
~ update_time = "2025-08-20T13:42:45.584767Z" -> "2025-09-11T19:15:57.105907Z"
# (12 unchanged attributes hidden)
# (1 unchanged block hidden)
}
# module.artifact_registry["etcd-manager"].google_artifact_registry_repository.repo has changed
~ resource "google_artifact_registry_repository" "repo" {
id = "projects/k8s-staging-images/locations/us-central1/repositories/etcd-manager"
name = "etcd-manager"
~ update_time = "2025-08-03T14:48:32.434494Z" -> "2025-09-22T19:50:13.594490Z"
# (12 unchanged attributes hidden)
# (1 unchanged block hidden)
}
# module.artifact_registry["gateway-api-inference-extension"].google_artifact_registry_repository.repo has changed
~ resource "google_artifact_registry_repository" "repo" {
id = "projects/k8s-staging-images/locations/us-central1/repositories/gateway-api-inference-extension"
name = "gateway-api-inference-extension"
~ update_time = "2025-08-27T12:22:29.597791Z" -> "2025-09-23T13:49:14.320435Z"
# (12 unchanged attributes hidden)
# (1 unchanged block hidden)
}
# module.artifact_registry["ingress-nginx"].google_artifact_registry_repository.repo has changed
~ resource "google_artifact_registry_repository" "repo" {
id = "projects/k8s-staging-images/locations/us-central1/repositories/ingress-nginx"
name = "ingress-nginx"
~ update_time = "2025-08-27T01:33:39.777208Z" -> "2025-09-21T13:54:16.191643Z"
# (12 unchanged attributes hidden)
# (1 unchanged block hidden)
}
# module.artifact_registry["jobset"].google_artifact_registry_repository.repo has changed
~ resource "google_artifact_registry_repository" "repo" {
id = "projects/k8s-staging-images/locations/us-central1/repositories/jobset"
name = "jobset"
~ update_time = "2025-08-27T00:44:54.946875Z" -> "2025-09-22T20:50:53.155451Z"
# (12 unchanged attributes hidden)
# (1 unchanged block hidden)
}
# module.artifact_registry["kueue"].google_artifact_registry_repository.repo has changed
~ resource "google_artifact_registry_repository" "repo" {
id = "projects/k8s-staging-images/locations/us-central1/repositories/kueue"
name = "kueue"
~ update_time = "2025-08-27T15:51:54.396464Z" -> "2025-09-23T15:16:35.733630Z"
# (12 unchanged attributes hidden)
# (1 unchanged block hidden)
}
# module.artifact_registry["lws"].google_artifact_registry_repository.repo has changed
~ resource "google_artifact_registry_repository" "repo" {
id = "projects/k8s-staging-images/locations/us-central1/repositories/lws"
name = "lws"
~ update_time = "2025-08-27T03:21:00.247862Z" -> "2025-09-23T16:03:40.603481Z"
# (12 unchanged attributes hidden)
# (1 unchanged block hidden)
}
Unless you have made equivalent changes to your configuration, or ignored the
relevant attributes using ignore_changes, the following plan may include
actions to undo or respond to these changes.
─────────────────────────────────────────────────────────────────────────────
Terraform used the selected providers to generate the following execution
plan. Resource actions are indicated with the following symbols:
+ create
~ update in-place
Terraform will perform the following actions:
# module.artifact_registry["cluster-capacity"].google_artifact_registry_repository.repo will be created
+ resource "google_artifact_registry_repository" "repo" {
+ cleanup_policy_dry_run = false
+ create_time = (known after apply)
+ effective_labels = {
+ "goog-terraform-provisioned" = "true"
}
+ format = "DOCKER"
+ id = (known after apply)
+ location = "us-central1"
+ mode = "STANDARD_REPOSITORY"
+ name = (known after apply)
+ project = "k8s-staging-images"
+ repository_id = "cluster-capacity"
+ terraform_labels = {
+ "goog-terraform-provisioned" = "true"
}
+ update_time = (known after apply)
+ cleanup_policies {
+ action = "DELETE"
+ id = "delete-images-older-than-90-days"
+ condition {
+ older_than = "7776000s"
+ package_name_prefixes = []
+ tag_prefixes = []
+ tag_state = "ANY"
+ version_name_prefixes = []
# (1 unchanged attribute hidden)
}
}
}
# module.artifact_registry["cluster-capacity"].google_artifact_registry_repository_iam_member.readers["allUsers"] will be created
+ resource "google_artifact_registry_repository_iam_member" "readers" {
+ etag = (known after apply)
+ id = (known after apply)
+ location = "us-central1"
+ member = "allUsers"
+ project = "k8s-staging-images"
+ repository = (known after apply)
+ role = "roles/artifactregistry.reader"
}
# module.artifact_registry["cluster-capacity"].google_artifact_registry_repository_iam_member.writers["group:k8s-infra-staging-cluster-capacity@kubernetes.io"] will be created
+ resource "google_artifact_registry_repository_iam_member" "writers" {
+ etag = (known after apply)
+ id = (known after apply)
+ location = "us-central1"
+ member = "group:k8s-infra-staging-cluster-capacity@kubernetes.io"
+ project = "k8s-staging-images"
+ repository = (known after apply)
+ role = "roles/artifactregistry.writer"
}
# module.iam.google_project_iam_binding.project_iam_authoritative["default--roles/viewer"] will be updated in-place
~ resource "google_project_iam_binding" "project_iam_authoritative" {
id = "k8s-staging-images/roles/viewer"
~ members = [
+ "group:k8s-infra-staging-cluster-capacity@kubernetes.io",
# (21 unchanged elements hidden)
]
# (3 unchanged attributes hidden)
}
Plan: 3 to add, 1 to change, 0 to destroy.
Note: Objects have changed outside of Terraform
|
|
[APPROVALNOTIFIER] This PR is APPROVED This pull-request has been approved by: ingvagabund, upodroid The full list of commands accepted by this bot can be found here. The pull request process is described here DetailsNeeds approval from an approver in each of these files:
Approvers can indicate their approval by writing |
|
atlantis apply |
|
Ran Apply for dir: module.artifact_registry["cluster-capacity"].google_artifact_registry_repository.repo: Creating...
module.iam.google_project_iam_binding.project_iam_authoritative["default--roles/viewer"]: Modifying... [id=k8s-staging-images/roles/viewer]
module.iam.google_project_iam_binding.project_iam_authoritative["default--roles/viewer"]: Modifications complete after 7s [id=k8s-staging-images/roles/viewer]
module.artifact_registry["cluster-capacity"].google_artifact_registry_repository.repo: Still creating... [10s elapsed]
module.artifact_registry["cluster-capacity"].google_artifact_registry_repository.repo: Creation complete after 11s [id=projects/k8s-staging-images/locations/us-central1/repositories/cluster-capacity]
module.artifact_registry["cluster-capacity"].google_artifact_registry_repository_iam_member.readers["allUsers"]: Creating...
module.artifact_registry["cluster-capacity"].google_artifact_registry_repository_iam_member.writers["group:k8s-infra-staging-cluster-capacity@kubernetes.io"]: Creating...
module.artifact_registry["cluster-capacity"].google_artifact_registry_repository_iam_member.writers["group:k8s-infra-staging-cluster-capacity@kubernetes.io"]: Creation complete after 7s [id=projects/k8s-staging-images/locations/us-central1/repositories/cluster-capacity/roles/artifactregistry.writer/group:k8s-infra-staging-cluster-capacity@kubernetes.io]
module.artifact_registry["cluster-capacity"].google_artifact_registry_repository_iam_member.readers["allUsers"]: Creation complete after 7s [id=projects/k8s-staging-images/locations/us-central1/repositories/cluster-capacity/roles/artifactregistry.reader/allUsers]
Apply complete! Resources: 3 added, 1 changed, 0 destroyed. |
|
Locks and plans deleted for the projects and workspaces modified in this pull request:
|
Follow up for #7030