Skip to content

Commit

Permalink
GCP IAM Updates Detected
Browse files Browse the repository at this point in the history
  • Loading branch information
jdyke committed Oct 24, 2024
1 parent 09499db commit 72549f2
Show file tree
Hide file tree
Showing 9 changed files with 38 additions and 20 deletions.
8 changes: 4 additions & 4 deletions roles/backupdr.admin
Original file line number Diff line number Diff line change
Expand Up @@ -2,16 +2,16 @@
"description": "Provides full access to all Backup and DR resources. ",
"etag": "AA==",
"includedPermissions": [
"backupdr.backupPlanAssociations.createForComputeInstance",
"backupdr.backupPlanAssociations.deleteForComputeInstance",
"backupdr.backupPlanAssociations.create",
"backupdr.backupPlanAssociations.delete",
"backupdr.backupPlanAssociations.get",
"backupdr.backupPlanAssociations.list",
"backupdr.backupPlanAssociations.triggerBackupForComputeInstance",
"backupdr.backupPlanAssociations.triggerBackup",
"backupdr.backupPlans.create",
"backupdr.backupPlans.delete",
"backupdr.backupPlans.get",
"backupdr.backupPlans.list",
"backupdr.backupPlans.useForComputeInstance",
"backupdr.backupPlans.useComputeInstanceOnly",
"backupdr.backupVaults.associate",
"backupdr.backupVaults.create",
"backupdr.backupVaults.delete",
Expand Down
8 changes: 4 additions & 4 deletions roles/backupdr.userv2
Original file line number Diff line number Diff line change
Expand Up @@ -2,16 +2,16 @@
"description": "Provides full access to Backup and DR resources except deploying and managing backup infrastructure, expiring backups, changing data sensitivity and configuring on-premises billing.",
"etag": "AA==",
"includedPermissions": [
"backupdr.backupPlanAssociations.createForComputeInstance",
"backupdr.backupPlanAssociations.deleteForComputeInstance",
"backupdr.backupPlanAssociations.create",
"backupdr.backupPlanAssociations.delete",
"backupdr.backupPlanAssociations.get",
"backupdr.backupPlanAssociations.list",
"backupdr.backupPlanAssociations.triggerBackupForComputeInstance",
"backupdr.backupPlanAssociations.triggerBackup",
"backupdr.backupPlans.create",
"backupdr.backupPlans.delete",
"backupdr.backupPlans.get",
"backupdr.backupPlans.list",
"backupdr.backupPlans.useForComputeInstance",
"backupdr.backupPlans.useComputeInstanceOnly",
"backupdr.backupVaults.associate",
"backupdr.backupVaults.get",
"backupdr.backupVaults.list",
Expand Down
4 changes: 4 additions & 0 deletions roles/cloudsql.viewer
Original file line number Diff line number Diff line change
Expand Up @@ -5,6 +5,8 @@
"cloudaicompanion.entitlements.get",
"cloudsql.backupRuns.get",
"cloudsql.backupRuns.list",
"cloudsql.backups.get",
"cloudsql.backups.list",
"cloudsql.databases.get",
"cloudsql.databases.list",
"cloudsql.instances.export",
Expand All @@ -15,6 +17,8 @@
"cloudsql.instances.listServerCas",
"cloudsql.instances.listServerCertificates",
"cloudsql.instances.listTagBindings",
"cloudsql.operations.get",
"cloudsql.operations.list",
"cloudsql.sslCerts.get",
"cloudsql.sslCerts.list",
"cloudsql.users.get",
Expand Down
5 changes: 0 additions & 5 deletions roles/compute.instanceAdmin.v1
Original file line number Diff line number Diff line change
Expand Up @@ -2,11 +2,6 @@
"description": "Full control of Compute Engine instances, instance groups, disks, snapshots, and images. Read access to all Compute Engine networking resources.",
"etag": "AA==",
"includedPermissions": [
"backupdr.backupPlanAssociations.createForComputeInstance",
"backupdr.backupPlanAssociations.deleteForComputeInstance",
"backupdr.backupPlanAssociations.list",
"backupdr.backupPlanAssociations.triggerBackupForComputeInstance",
"backupdr.backupPlans.useForComputeInstance",
"compute.acceleratorTypes.get",
"compute.acceleratorTypes.list",
"compute.addresses.createInternal",
Expand Down
1 change: 0 additions & 1 deletion roles/contactcenterinsights.editor
Original file line number Diff line number Diff line change
Expand Up @@ -67,7 +67,6 @@
"contactcenterinsights.qaScorecardRevisions.get",
"contactcenterinsights.qaScorecardRevisions.list",
"contactcenterinsights.qaScorecardRevisions.tune",
"contactcenterinsights.qaScorecardRevisions.undeploy",
"contactcenterinsights.qaScorecards.create",
"contactcenterinsights.qaScorecards.delete",
"contactcenterinsights.qaScorecards.get",
Expand Down
24 changes: 24 additions & 0 deletions roles/designcenter.serviceAgent
Original file line number Diff line number Diff line change
@@ -0,0 +1,24 @@
{
"description": "Gives the DesignCenter API Service Account access to necessary GCP resources.",
"etag": "AA==",
"includedPermissions": [
"storage.buckets.create",
"storage.buckets.delete",
"storage.buckets.get",
"storage.buckets.list",
"storage.buckets.update",
"storage.managedFolders.create",
"storage.managedFolders.delete",
"storage.managedFolders.get",
"storage.managedFolders.getIamPolicy",
"storage.managedFolders.list",
"storage.objects.create",
"storage.objects.delete",
"storage.objects.get",
"storage.objects.list",
"storage.objects.update"
],
"name": "roles/designcenter.serviceAgent",
"stage": "ALPHA",
"title": "DesignCenter Service Agent"
}
1 change: 0 additions & 1 deletion roles/dspm.serviceAgent
Original file line number Diff line number Diff line change
Expand Up @@ -43,7 +43,6 @@
"securitycentermanagement.securityHealthAnalyticsCustomModules.get",
"securityposture.operations.get",
"securityposture.postureDeployments.create",
"securityposture.postureDeployments.delete",
"securityposture.postures.create",
"securityposture.postures.get",
"storage.buckets.createTagBinding",
Expand Down
5 changes: 0 additions & 5 deletions roles/genomics.serviceAgent
Original file line number Diff line number Diff line change
Expand Up @@ -2,11 +2,6 @@
"description": "Gives Genomics Service Account access to compute resources. Includes access to service accounts.",
"etag": "AA==",
"includedPermissions": [
"backupdr.backupPlanAssociations.createForComputeInstance",
"backupdr.backupPlanAssociations.deleteForComputeInstance",
"backupdr.backupPlanAssociations.list",
"backupdr.backupPlanAssociations.triggerBackupForComputeInstance",
"backupdr.backupPlans.useForComputeInstance",
"compute.acceleratorTypes.get",
"compute.acceleratorTypes.list",
"compute.addresses.createInternal",
Expand Down
2 changes: 2 additions & 0 deletions roles/iam.securityReviewer
Original file line number Diff line number Diff line change
Expand Up @@ -482,8 +482,10 @@
"cloudsecurityscanner.scanruns.list",
"cloudsecurityscanner.scans.list",
"cloudsql.backupRuns.list",
"cloudsql.backups.list",
"cloudsql.databases.list",
"cloudsql.instances.list",
"cloudsql.operations.list",
"cloudsql.sslCerts.list",
"cloudsql.users.list",
"cloudsupport.accounts.getIamPolicy",
Expand Down

0 comments on commit 72549f2

Please sign in to comment.