Skip to content

Commit

Permalink
GCP IAM Updates Detected
Browse files Browse the repository at this point in the history
  • Loading branch information
jdyke committed Nov 17, 2024
1 parent b99a49d commit 46d2e2c
Show file tree
Hide file tree
Showing 67 changed files with 518 additions and 11 deletions.
25 changes: 25 additions & 0 deletions roles/aiplatform.onlinePredictionServiceAgent
Original file line number Diff line number Diff line change
@@ -0,0 +1,25 @@
{
"description": "Gives Vertex AI Online Prediction the permissions it needs to function.",
"etag": "AA==",
"includedPermissions": [
"gkehub.features.get",
"gkehub.features.getIamPolicy",
"gkehub.features.list",
"gkehub.fleet.get",
"gkehub.gateway.delete",
"gkehub.gateway.generateCredentials",
"gkehub.gateway.get",
"gkehub.gateway.patch",
"gkehub.gateway.post",
"gkehub.gateway.put",
"gkehub.locations.get",
"gkehub.locations.list",
"gkehub.memberships.get",
"gkehub.memberships.getIamPolicy",
"gkehub.memberships.list",
"serviceusage.services.get"
],
"name": "roles/aiplatform.onlinePredictionServiceAgent",
"stage": "GA",
"title": "Vertex AI Online Prediction Service Agent"
}
5 changes: 4 additions & 1 deletion roles/aiplatform.ragServiceAgent
Original file line number Diff line number Diff line change
@@ -1,5 +1,5 @@
{
"description": "Vertex AI Service Agent used by Vertex RAG to access user imported data and Vertex AI in the project",
"description": "Vertex AI Service Agent used by Vertex RAG to access user imported data, Vertex AI, Document AI processors in the project",
"etag": "AA==",
"includedPermissions": [
"aiplatform.endpoints.get",
Expand Down Expand Up @@ -37,6 +37,9 @@
"bigquery.tables.restoreSnapshot",
"bigquery.tables.update",
"bigquery.tables.updateData",
"documentai.processorVersions.processOnline",
"documentai.processors.get",
"documentai.processors.processOnline",
"logging.logEntries.create",
"logging.logEntries.route",
"storage.buckets.get",
Expand Down
3 changes: 3 additions & 0 deletions roles/batch.serviceAgent
Original file line number Diff line number Diff line change
Expand Up @@ -253,6 +253,8 @@
"compute.networkEndpointGroups.listEffectiveTags",
"compute.networkEndpointGroups.listTagBindings",
"compute.networkEndpointGroups.use",
"compute.networkProfiles.get",
"compute.networkProfiles.list",
"compute.networks.get",
"compute.networks.list",
"compute.networks.listEffectiveTags",
Expand Down Expand Up @@ -349,6 +351,7 @@
"compute.snapshots.listTagBindings",
"compute.snapshots.setLabels",
"compute.snapshots.useReadOnly",
"compute.spotAssistants.get",
"compute.sslCertificates.get",
"compute.sslCertificates.list",
"compute.sslCertificates.listEffectiveTags",
Expand Down
5 changes: 4 additions & 1 deletion roles/chronicle.admin
Original file line number Diff line number Diff line change
Expand Up @@ -81,6 +81,10 @@
"chronicle.dataTaps.get",
"chronicle.dataTaps.list",
"chronicle.dataTaps.update",
"chronicle.enrichmentControls.create",
"chronicle.enrichmentControls.delete",
"chronicle.enrichmentControls.get",
"chronicle.enrichmentControls.list",
"chronicle.entities.batchCreate",
"chronicle.entities.batchDelete",
"chronicle.entities.batchValidate",
Expand Down Expand Up @@ -175,7 +179,6 @@
"chronicle.legacies.legacyGetRuleCounts",
"chronicle.legacies.legacyGetRulesTrends",
"chronicle.legacies.legacyRunTestRule",
"chronicle.legacies.legacySearchAlerts",
"chronicle.legacies.legacySearchArtifactEvents",
"chronicle.legacies.legacySearchArtifactIoCDetails",
"chronicle.legacies.legacySearchAssetEvents",
Expand Down
3 changes: 2 additions & 1 deletion roles/chronicle.editor
Original file line number Diff line number Diff line change
Expand Up @@ -67,6 +67,8 @@
"chronicle.dataTaps.get",
"chronicle.dataTaps.list",
"chronicle.dataTaps.update",
"chronicle.enrichmentControls.get",
"chronicle.enrichmentControls.list",
"chronicle.entities.batchCreate",
"chronicle.entities.batchDelete",
"chronicle.entities.batchValidate",
Expand Down Expand Up @@ -142,7 +144,6 @@
"chronicle.legacies.legacyGetRuleCounts",
"chronicle.legacies.legacyGetRulesTrends",
"chronicle.legacies.legacyRunTestRule",
"chronicle.legacies.legacySearchAlerts",
"chronicle.legacies.legacySearchArtifactEvents",
"chronicle.legacies.legacySearchArtifactIoCDetails",
"chronicle.legacies.legacySearchAssetEvents",
Expand Down
1 change: 0 additions & 1 deletion roles/chronicle.limitedViewer
Original file line number Diff line number Diff line change
Expand Up @@ -58,7 +58,6 @@
"chronicle.legacies.legacyFindUdmEvents",
"chronicle.legacies.legacyGetAlert",
"chronicle.legacies.legacyGetFinding",
"chronicle.legacies.legacySearchAlerts",
"chronicle.legacies.legacySearchArtifactEvents",
"chronicle.legacies.legacySearchArtifactIoCDetails",
"chronicle.legacies.legacySearchAssetEvents",
Expand Down
7 changes: 7 additions & 0 deletions roles/chronicle.restrictedDataAccessViewer
Original file line number Diff line number Diff line change
Expand Up @@ -68,6 +68,8 @@
"chronicle.operations.list",
"chronicle.operations.streamSearch",
"chronicle.operations.wait",
"chronicle.preferenceSets.get",
"chronicle.preferenceSets.update",
"chronicle.referenceLists.get",
"chronicle.referenceLists.list",
"chronicle.referenceLists.verifyReferenceList",
Expand All @@ -80,6 +82,11 @@
"chronicle.rules.list",
"chronicle.rules.listRevisions",
"chronicle.rules.verifyRuleText",
"chronicle.searchQueries.create",
"chronicle.searchQueries.delete",
"chronicle.searchQueries.get",
"chronicle.searchQueries.list",
"chronicle.searchQueries.update",
"resourcemanager.projects.get",
"resourcemanager.projects.list"
],
Expand Down
3 changes: 2 additions & 1 deletion roles/chronicle.viewer
Original file line number Diff line number Diff line change
Expand Up @@ -40,6 +40,8 @@
"chronicle.dataTables.list",
"chronicle.dataTaps.get",
"chronicle.dataTaps.list",
"chronicle.enrichmentControls.get",
"chronicle.enrichmentControls.list",
"chronicle.entities.find",
"chronicle.entities.findRelatedEntities",
"chronicle.entities.get",
Expand Down Expand Up @@ -103,7 +105,6 @@
"chronicle.legacies.legacyGetRuleCounts",
"chronicle.legacies.legacyGetRulesTrends",
"chronicle.legacies.legacyRunTestRule",
"chronicle.legacies.legacySearchAlerts",
"chronicle.legacies.legacySearchArtifactEvents",
"chronicle.legacies.legacySearchArtifactIoCDetails",
"chronicle.legacies.legacySearchAssetEvents",
Expand Down
1 change: 1 addition & 0 deletions roles/chroniclesm.viewer
Original file line number Diff line number Diff line change
Expand Up @@ -3,6 +3,7 @@
"etag": "AA==",
"includedPermissions": [
"chroniclesm.gcpAssociations.get",
"chroniclesm.gcpAssociations.list",
"chroniclesm.gcpLogFlowFilters.get",
"chroniclesm.gcpSettings.get"
],
Expand Down
4 changes: 2 additions & 2 deletions roles/cloudaicompanion.serviceAgent
Original file line number Diff line number Diff line change
@@ -1,5 +1,5 @@
{
"description": "Gives Cloud AI Companion components the proper permissions to function.",
"description": "Gives Gemini for Google Cloud components the proper permissions to function.",
"etag": "AA==",
"includedPermissions": [
"cloudaicompanion.codeRepositoryIndexes.get",
Expand Down Expand Up @@ -29,5 +29,5 @@
],
"name": "roles/cloudaicompanion.serviceAgent",
"stage": "GA",
"title": "Cloud AI Companion Service Agent"
"title": "Gemini for Google Cloud Service Agent"
}
1 change: 1 addition & 0 deletions roles/cloudaicompanion.user
Original file line number Diff line number Diff line change
Expand Up @@ -9,6 +9,7 @@
"cloudaicompanion.instances.completeTask",
"cloudaicompanion.instances.generateCode",
"cloudaicompanion.instances.generateText",
"cloudaicompanion.licenses.selfAssign",
"resourcemanager.projects.get",
"resourcemanager.projects.list"
],
Expand Down
4 changes: 4 additions & 0 deletions roles/cloudtpu.serviceAgent
Original file line number Diff line number Diff line change
Expand Up @@ -381,6 +381,8 @@
"compute.networkEndpointGroups.listEffectiveTags",
"compute.networkEndpointGroups.listTagBindings",
"compute.networkEndpointGroups.use",
"compute.networkProfiles.get",
"compute.networkProfiles.list",
"compute.networks.access",
"compute.networks.addPeering",
"compute.networks.create",
Expand Down Expand Up @@ -598,6 +600,7 @@
"compute.snapshots.setIamPolicy",
"compute.snapshots.setLabels",
"compute.snapshots.useReadOnly",
"compute.spotAssistants.get",
"compute.sslCertificates.get",
"compute.sslCertificates.list",
"compute.sslCertificates.listEffectiveTags",
Expand Down Expand Up @@ -632,6 +635,7 @@
"compute.subnetworks.update",
"compute.subnetworks.use",
"compute.subnetworks.useExternalIp",
"compute.subnetworks.usePeerMigration",
"compute.targetGrpcProxies.create",
"compute.targetGrpcProxies.createTagBinding",
"compute.targetGrpcProxies.delete",
Expand Down
4 changes: 4 additions & 0 deletions roles/composer.serviceAgent
Original file line number Diff line number Diff line change
Expand Up @@ -464,6 +464,8 @@
"compute.networkEndpointGroups.listEffectiveTags",
"compute.networkEndpointGroups.listTagBindings",
"compute.networkEndpointGroups.use",
"compute.networkProfiles.get",
"compute.networkProfiles.list",
"compute.networks.access",
"compute.networks.addPeering",
"compute.networks.create",
Expand Down Expand Up @@ -681,6 +683,7 @@
"compute.snapshots.setIamPolicy",
"compute.snapshots.setLabels",
"compute.snapshots.useReadOnly",
"compute.spotAssistants.get",
"compute.sslCertificates.get",
"compute.sslCertificates.list",
"compute.sslCertificates.listEffectiveTags",
Expand Down Expand Up @@ -715,6 +718,7 @@
"compute.subnetworks.update",
"compute.subnetworks.use",
"compute.subnetworks.useExternalIp",
"compute.subnetworks.usePeerMigration",
"compute.targetGrpcProxies.create",
"compute.targetGrpcProxies.createTagBinding",
"compute.targetGrpcProxies.delete",
Expand Down
4 changes: 4 additions & 0 deletions roles/compute.admin
Original file line number Diff line number Diff line change
Expand Up @@ -419,6 +419,8 @@
"compute.networkEndpointGroups.listEffectiveTags",
"compute.networkEndpointGroups.listTagBindings",
"compute.networkEndpointGroups.use",
"compute.networkProfiles.get",
"compute.networkProfiles.list",
"compute.networks.access",
"compute.networks.addPeering",
"compute.networks.create",
Expand Down Expand Up @@ -720,6 +722,7 @@
"compute.snapshots.setIamPolicy",
"compute.snapshots.setLabels",
"compute.snapshots.useReadOnly",
"compute.spotAssistants.get",
"compute.sslCertificates.create",
"compute.sslCertificates.createTagBinding",
"compute.sslCertificates.delete",
Expand Down Expand Up @@ -763,6 +766,7 @@
"compute.subnetworks.update",
"compute.subnetworks.use",
"compute.subnetworks.useExternalIp",
"compute.subnetworks.usePeerMigration",
"compute.targetGrpcProxies.create",
"compute.targetGrpcProxies.createTagBinding",
"compute.targetGrpcProxies.delete",
Expand Down
3 changes: 3 additions & 0 deletions roles/compute.instanceAdmin.v1
Original file line number Diff line number Diff line change
Expand Up @@ -261,6 +261,8 @@
"compute.networkEndpointGroups.listEffectiveTags",
"compute.networkEndpointGroups.listTagBindings",
"compute.networkEndpointGroups.use",
"compute.networkProfiles.get",
"compute.networkProfiles.list",
"compute.networks.get",
"compute.networks.list",
"compute.networks.listEffectiveTags",
Expand Down Expand Up @@ -359,6 +361,7 @@
"compute.snapshots.setIamPolicy",
"compute.snapshots.setLabels",
"compute.snapshots.useReadOnly",
"compute.spotAssistants.get",
"compute.sslCertificates.get",
"compute.sslCertificates.list",
"compute.sslCertificates.listEffectiveTags",
Expand Down
3 changes: 3 additions & 0 deletions roles/compute.networkAdmin
Original file line number Diff line number Diff line change
Expand Up @@ -231,6 +231,8 @@
"compute.networkEndpointGroups.listEffectiveTags",
"compute.networkEndpointGroups.listTagBindings",
"compute.networkEndpointGroups.use",
"compute.networkProfiles.get",
"compute.networkProfiles.list",
"compute.networks.access",
"compute.networks.addPeering",
"compute.networks.create",
Expand Down Expand Up @@ -451,6 +453,7 @@
"compute.subnetworks.update",
"compute.subnetworks.use",
"compute.subnetworks.useExternalIp",
"compute.subnetworks.usePeerMigration",
"compute.targetGrpcProxies.create",
"compute.targetGrpcProxies.createTagBinding",
"compute.targetGrpcProxies.delete",
Expand Down
2 changes: 2 additions & 0 deletions roles/compute.networkUser
Original file line number Diff line number Diff line change
Expand Up @@ -36,6 +36,8 @@
"compute.networkAttachments.list",
"compute.networkAttachments.listEffectiveTags",
"compute.networkAttachments.listTagBindings",
"compute.networkProfiles.get",
"compute.networkProfiles.list",
"compute.networks.access",
"compute.networks.get",
"compute.networks.getEffectiveFirewalls",
Expand Down
2 changes: 2 additions & 0 deletions roles/compute.networkViewer
Original file line number Diff line number Diff line change
Expand Up @@ -90,6 +90,8 @@
"compute.networkAttachments.list",
"compute.networkAttachments.listEffectiveTags",
"compute.networkAttachments.listTagBindings",
"compute.networkProfiles.get",
"compute.networkProfiles.list",
"compute.networks.get",
"compute.networks.getEffectiveFirewalls",
"compute.networks.getRegionEffectiveFirewalls",
Expand Down
3 changes: 3 additions & 0 deletions roles/compute.viewer
Original file line number Diff line number Diff line change
Expand Up @@ -150,6 +150,8 @@
"compute.networkEndpointGroups.list",
"compute.networkEndpointGroups.listEffectiveTags",
"compute.networkEndpointGroups.listTagBindings",
"compute.networkProfiles.get",
"compute.networkProfiles.list",
"compute.networks.get",
"compute.networks.getEffectiveFirewalls",
"compute.networks.getRegionEffectiveFirewalls",
Expand Down Expand Up @@ -265,6 +267,7 @@
"compute.snapshots.list",
"compute.snapshots.listEffectiveTags",
"compute.snapshots.listTagBindings",
"compute.spotAssistants.get",
"compute.sslCertificates.get",
"compute.sslCertificates.list",
"compute.sslCertificates.listEffectiveTags",
Expand Down
4 changes: 4 additions & 0 deletions roles/container.serviceAgent
Original file line number Diff line number Diff line change
Expand Up @@ -426,6 +426,8 @@
"compute.networkEndpointGroups.listEffectiveTags",
"compute.networkEndpointGroups.listTagBindings",
"compute.networkEndpointGroups.use",
"compute.networkProfiles.get",
"compute.networkProfiles.list",
"compute.networks.access",
"compute.networks.addPeering",
"compute.networks.create",
Expand Down Expand Up @@ -676,6 +678,7 @@
"compute.snapshots.setIamPolicy",
"compute.snapshots.setLabels",
"compute.snapshots.useReadOnly",
"compute.spotAssistants.get",
"compute.sslCertificates.create",
"compute.sslCertificates.createTagBinding",
"compute.sslCertificates.delete",
Expand Down Expand Up @@ -719,6 +722,7 @@
"compute.subnetworks.update",
"compute.subnetworks.use",
"compute.subnetworks.useExternalIp",
"compute.subnetworks.usePeerMigration",
"compute.targetGrpcProxies.create",
"compute.targetGrpcProxies.createTagBinding",
"compute.targetGrpcProxies.delete",
Expand Down
3 changes: 3 additions & 0 deletions roles/dataflow.serviceAgent
Original file line number Diff line number Diff line change
Expand Up @@ -493,6 +493,8 @@
"compute.networkEndpointGroups.listEffectiveTags",
"compute.networkEndpointGroups.listTagBindings",
"compute.networkEndpointGroups.use",
"compute.networkProfiles.get",
"compute.networkProfiles.list",
"compute.networks.access",
"compute.networks.addPeering",
"compute.networks.create",
Expand Down Expand Up @@ -748,6 +750,7 @@
"compute.subnetworks.update",
"compute.subnetworks.use",
"compute.subnetworks.useExternalIp",
"compute.subnetworks.usePeerMigration",
"compute.targetGrpcProxies.create",
"compute.targetGrpcProxies.createTagBinding",
"compute.targetGrpcProxies.delete",
Expand Down
2 changes: 2 additions & 0 deletions roles/datafusion.serviceAgent
Original file line number Diff line number Diff line change
Expand Up @@ -221,6 +221,8 @@
"compute.networkAttachments.listEffectiveTags",
"compute.networkAttachments.listTagBindings",
"compute.networkAttachments.update",
"compute.networkProfiles.get",
"compute.networkProfiles.list",
"compute.networks.addPeering",
"compute.networks.get",
"compute.networks.getEffectiveFirewalls",
Expand Down
5 changes: 5 additions & 0 deletions roles/dataplex.admin
Original file line number Diff line number Diff line change
Expand Up @@ -53,6 +53,11 @@
"dataplex.datascans.run",
"dataplex.datascans.setIamPolicy",
"dataplex.datascans.update",
"dataplex.encryptionConfig.create",
"dataplex.encryptionConfig.delete",
"dataplex.encryptionConfig.get",
"dataplex.encryptionConfig.list",
"dataplex.encryptionConfig.update",
"dataplex.entities.create",
"dataplex.entities.delete",
"dataplex.entities.get",
Expand Down
14 changes: 14 additions & 0 deletions roles/dataplex.encryptionAdmin
Original file line number Diff line number Diff line change
@@ -0,0 +1,14 @@
{
"description": "Gives user permissions to manage encryption config.",
"etag": "AA==",
"includedPermissions": [
"dataplex.encryptionConfig.create",
"dataplex.encryptionConfig.delete",
"dataplex.encryptionConfig.get",
"dataplex.encryptionConfig.list",
"dataplex.encryptionConfig.update"
],
"name": "roles/dataplex.encryptionAdmin",
"stage": "BETA",
"title": "Dataplex Encryption Admin"
}
Loading

0 comments on commit 46d2e2c

Please sign in to comment.