Skip to content

Commit

Permalink
GCP IAM Updates Detected
Browse files Browse the repository at this point in the history
  • Loading branch information
jdyke committed Oct 11, 2024
1 parent 4538989 commit 96364e2
Show file tree
Hide file tree
Showing 67 changed files with 529 additions and 92 deletions.
2 changes: 1 addition & 1 deletion roles/backupdr.backupvaultAccessor
Original file line number Diff line number Diff line change
Expand Up @@ -23,6 +23,6 @@
"backupdr.operations.list"
],
"name": "roles/backupdr.backupvaultAccessor",
"stage": "BETA",
"stage": "GA",
"title": "Backup and DR Backup Vault Accessor"
}
2 changes: 1 addition & 1 deletion roles/backupdr.backupvaultAdmin
Original file line number Diff line number Diff line change
Expand Up @@ -25,6 +25,6 @@
"backupdr.operations.list"
],
"name": "roles/backupdr.backupvaultAdmin",
"stage": "BETA",
"stage": "GA",
"title": "Backup and DR Backup Vault Admin"
}
2 changes: 1 addition & 1 deletion roles/backupdr.backupvaultLister
Original file line number Diff line number Diff line change
Expand Up @@ -5,6 +5,6 @@
"backupdr.backupVaults.list"
],
"name": "roles/backupdr.backupvaultLister",
"stage": "BETA",
"stage": "GA",
"title": "Backup and DR Backup Vault Lister"
}
2 changes: 1 addition & 1 deletion roles/backupdr.backupvaultViewer
Original file line number Diff line number Diff line change
Expand Up @@ -12,6 +12,6 @@
"backupdr.operations.list"
],
"name": "roles/backupdr.backupvaultViewer",
"stage": "BETA",
"stage": "GA",
"title": "Backup and DR Backup Vault Viewer"
}
2 changes: 0 additions & 2 deletions roles/batch.serviceAgent
Original file line number Diff line number Diff line change
Expand Up @@ -216,7 +216,6 @@
"compute.licenseCodes.getIamPolicy",
"compute.licenseCodes.list",
"compute.licenseCodes.update",
"compute.licenseCodes.use",
"compute.licenses.create",
"compute.licenses.delete",
"compute.licenses.get",
Expand All @@ -241,7 +240,6 @@
"compute.networkEndpointGroups.deleteTagBinding",
"compute.networkEndpointGroups.detachNetworkEndpoints",
"compute.networkEndpointGroups.get",
"compute.networkEndpointGroups.getIamPolicy",
"compute.networkEndpointGroups.list",
"compute.networkEndpointGroups.listEffectiveTags",
"compute.networkEndpointGroups.listTagBindings",
Expand Down
16 changes: 16 additions & 0 deletions roles/bigquerydatapolicy.admin
Original file line number Diff line number Diff line change
@@ -0,0 +1,16 @@
{
"description": "Role for managing Data Policies in BigQuery",
"etag": "AA==",
"includedPermissions": [
"bigquery.dataPolicies.create",
"bigquery.dataPolicies.delete",
"bigquery.dataPolicies.get",
"bigquery.dataPolicies.getIamPolicy",
"bigquery.dataPolicies.list",
"bigquery.dataPolicies.setIamPolicy",
"bigquery.dataPolicies.update"
],
"name": "roles/bigquerydatapolicy.admin",
"stage": "ALPHA",
"title": "BigQuery Data Policy Admin"
}
11 changes: 11 additions & 0 deletions roles/bigquerydatapolicy.viewer
Original file line number Diff line number Diff line change
@@ -0,0 +1,11 @@
{
"description": "Role for viewing Data Policies in BigQuery",
"etag": "AA==",
"includedPermissions": [
"bigquery.dataPolicies.get",
"bigquery.dataPolicies.list"
],
"name": "roles/bigquerydatapolicy.viewer",
"stage": "ALPHA",
"title": "BigQuery Data Policy Viewer"
}
11 changes: 11 additions & 0 deletions roles/blockchainvalidatormanager.admin
Original file line number Diff line number Diff line change
@@ -0,0 +1,11 @@
{
"description": "Full access to Blockchain Validator Config resources.",
"etag": "AA==",
"includedPermissions": [
"resourcemanager.projects.get",
"resourcemanager.projects.list"
],
"name": "roles/blockchainvalidatormanager.admin",
"stage": "ALPHA",
"title": "Blockchain Validator Config Admin"
}
11 changes: 11 additions & 0 deletions roles/blockchainvalidatormanager.viewer
Original file line number Diff line number Diff line change
@@ -0,0 +1,11 @@
{
"description": "Readonly access to Blockchain Validator Config resources.",
"etag": "AA==",
"includedPermissions": [
"resourcemanager.projects.get",
"resourcemanager.projects.list"
],
"name": "roles/blockchainvalidatormanager.viewer",
"stage": "ALPHA",
"title": "Blockchain Validator Config Viewer"
}
2 changes: 2 additions & 0 deletions roles/chronicle.soarServiceAgent
Original file line number Diff line number Diff line change
Expand Up @@ -3,6 +3,8 @@
"etag": "AA==",
"includedPermissions": [
"cloudasset.assets.analyzeIamPolicy",
"cloudasset.assets.exportIamPolicy",
"cloudasset.assets.exportResource",
"cloudasset.assets.searchAllIamPolicies",
"cloudasset.assets.searchAllResources",
"compute.firewalls.get",
Expand Down
2 changes: 2 additions & 0 deletions roles/cloudcontrolspartner.admin
Original file line number Diff line number Diff line change
Expand Up @@ -3,6 +3,8 @@
"etag": "AA==",
"includedPermissions": [
"cloudcontrolspartner.accessapprovalrequests.list",
"cloudcontrolspartner.customers.create",
"cloudcontrolspartner.customers.delete",
"cloudcontrolspartner.customers.get",
"cloudcontrolspartner.customers.list",
"cloudcontrolspartner.ekmconnections.get",
Expand Down
2 changes: 2 additions & 0 deletions roles/cloudcontrolspartner.editor
Original file line number Diff line number Diff line change
Expand Up @@ -3,6 +3,8 @@
"etag": "AA==",
"includedPermissions": [
"cloudcontrolspartner.accessapprovalrequests.list",
"cloudcontrolspartner.customers.create",
"cloudcontrolspartner.customers.delete",
"cloudcontrolspartner.customers.get",
"cloudcontrolspartner.customers.list",
"cloudcontrolspartner.ekmconnections.get",
Expand Down
2 changes: 1 addition & 1 deletion roles/cloudcontrolspartner.supportCaseServiceAgent
Original file line number Diff line number Diff line change
Expand Up @@ -5,6 +5,6 @@
"cloudsupport.techCases.get"
],
"name": "roles/cloudcontrolspartner.supportCaseServiceAgent",
"stage": "ALPHA",
"stage": "GA",
"title": "Cloud Controls Partner Support Case Service Agent"
}
30 changes: 30 additions & 0 deletions roles/cloudfunctions.admin
Original file line number Diff line number Diff line change
Expand Up @@ -37,16 +37,46 @@
"eventarc.channels.setIamPolicy",
"eventarc.channels.undelete",
"eventarc.channels.update",
"eventarc.enrollments.create",
"eventarc.enrollments.delete",
"eventarc.enrollments.get",
"eventarc.enrollments.getIamPolicy",
"eventarc.enrollments.list",
"eventarc.enrollments.setIamPolicy",
"eventarc.enrollments.update",
"eventarc.events.receiveAuditLogWritten",
"eventarc.events.receiveEvent",
"eventarc.googleApiSources.create",
"eventarc.googleApiSources.delete",
"eventarc.googleApiSources.get",
"eventarc.googleApiSources.getIamPolicy",
"eventarc.googleApiSources.list",
"eventarc.googleApiSources.setIamPolicy",
"eventarc.googleApiSources.update",
"eventarc.googleChannelConfigs.get",
"eventarc.googleChannelConfigs.update",
"eventarc.locations.get",
"eventarc.locations.list",
"eventarc.messageBuses.create",
"eventarc.messageBuses.delete",
"eventarc.messageBuses.get",
"eventarc.messageBuses.getIamPolicy",
"eventarc.messageBuses.list",
"eventarc.messageBuses.publish",
"eventarc.messageBuses.setIamPolicy",
"eventarc.messageBuses.update",
"eventarc.messageBuses.use",
"eventarc.operations.cancel",
"eventarc.operations.delete",
"eventarc.operations.get",
"eventarc.operations.list",
"eventarc.pipelines.create",
"eventarc.pipelines.delete",
"eventarc.pipelines.get",
"eventarc.pipelines.getIamPolicy",
"eventarc.pipelines.list",
"eventarc.pipelines.setIamPolicy",
"eventarc.pipelines.update",
"eventarc.providers.get",
"eventarc.providers.list",
"eventarc.triggers.create",
Expand Down
18 changes: 18 additions & 0 deletions roles/cloudfunctions.developer
Original file line number Diff line number Diff line change
Expand Up @@ -33,6 +33,18 @@
"eventarc.channels.publish",
"eventarc.channels.undelete",
"eventarc.channels.update",
"eventarc.enrollments.create",
"eventarc.enrollments.delete",
"eventarc.enrollments.get",
"eventarc.enrollments.getIamPolicy",
"eventarc.enrollments.list",
"eventarc.enrollments.update",
"eventarc.googleApiSources.create",
"eventarc.googleApiSources.delete",
"eventarc.googleApiSources.get",
"eventarc.googleApiSources.getIamPolicy",
"eventarc.googleApiSources.list",
"eventarc.googleApiSources.update",
"eventarc.googleChannelConfigs.get",
"eventarc.googleChannelConfigs.update",
"eventarc.locations.get",
Expand All @@ -41,6 +53,12 @@
"eventarc.operations.delete",
"eventarc.operations.get",
"eventarc.operations.list",
"eventarc.pipelines.create",
"eventarc.pipelines.delete",
"eventarc.pipelines.get",
"eventarc.pipelines.getIamPolicy",
"eventarc.pipelines.list",
"eventarc.pipelines.update",
"eventarc.providers.get",
"eventarc.providers.list",
"eventarc.triggers.create",
Expand Down
18 changes: 18 additions & 0 deletions roles/cloudfunctions.serviceAgent
Original file line number Diff line number Diff line change
Expand Up @@ -90,6 +90,18 @@
"eventarc.channels.publish",
"eventarc.channels.undelete",
"eventarc.channels.update",
"eventarc.enrollments.create",
"eventarc.enrollments.delete",
"eventarc.enrollments.get",
"eventarc.enrollments.getIamPolicy",
"eventarc.enrollments.list",
"eventarc.enrollments.update",
"eventarc.googleApiSources.create",
"eventarc.googleApiSources.delete",
"eventarc.googleApiSources.get",
"eventarc.googleApiSources.getIamPolicy",
"eventarc.googleApiSources.list",
"eventarc.googleApiSources.update",
"eventarc.googleChannelConfigs.get",
"eventarc.googleChannelConfigs.update",
"eventarc.locations.get",
Expand All @@ -98,6 +110,12 @@
"eventarc.operations.delete",
"eventarc.operations.get",
"eventarc.operations.list",
"eventarc.pipelines.create",
"eventarc.pipelines.delete",
"eventarc.pipelines.get",
"eventarc.pipelines.getIamPolicy",
"eventarc.pipelines.list",
"eventarc.pipelines.update",
"eventarc.providers.get",
"eventarc.providers.list",
"eventarc.triggers.create",
Expand Down
13 changes: 13 additions & 0 deletions roles/cloudfunctions.viewer
Original file line number Diff line number Diff line change
Expand Up @@ -18,11 +18,24 @@
"eventarc.channels.get",
"eventarc.channels.getIamPolicy",
"eventarc.channels.list",
"eventarc.enrollments.get",
"eventarc.enrollments.getIamPolicy",
"eventarc.enrollments.list",
"eventarc.googleApiSources.get",
"eventarc.googleApiSources.getIamPolicy",
"eventarc.googleApiSources.list",
"eventarc.googleChannelConfigs.get",
"eventarc.locations.get",
"eventarc.locations.list",
"eventarc.messageBuses.get",
"eventarc.messageBuses.getIamPolicy",
"eventarc.messageBuses.list",
"eventarc.messageBuses.use",
"eventarc.operations.get",
"eventarc.operations.list",
"eventarc.pipelines.get",
"eventarc.pipelines.getIamPolicy",
"eventarc.pipelines.list",
"eventarc.providers.get",
"eventarc.providers.list",
"eventarc.triggers.get",
Expand Down
1 change: 0 additions & 1 deletion roles/cloudmigration.inframanager
Original file line number Diff line number Diff line change
Expand Up @@ -53,7 +53,6 @@
"compute.licenseCodes.get",
"compute.licenseCodes.list",
"compute.licenseCodes.update",
"compute.licenseCodes.use",
"compute.licenses.get",
"compute.licenses.list",
"compute.machineTypes.get",
Expand Down
3 changes: 0 additions & 3 deletions roles/cloudtpu.serviceAgent
Original file line number Diff line number Diff line change
Expand Up @@ -335,7 +335,6 @@
"compute.licenseCodes.list",
"compute.licenseCodes.setIamPolicy",
"compute.licenseCodes.update",
"compute.licenseCodes.use",
"compute.licenses.create",
"compute.licenses.delete",
"compute.licenses.get",
Expand Down Expand Up @@ -369,11 +368,9 @@
"compute.networkEndpointGroups.deleteTagBinding",
"compute.networkEndpointGroups.detachNetworkEndpoints",
"compute.networkEndpointGroups.get",
"compute.networkEndpointGroups.getIamPolicy",
"compute.networkEndpointGroups.list",
"compute.networkEndpointGroups.listEffectiveTags",
"compute.networkEndpointGroups.listTagBindings",
"compute.networkEndpointGroups.setIamPolicy",
"compute.networkEndpointGroups.use",
"compute.networks.access",
"compute.networks.addPeering",
Expand Down
6 changes: 3 additions & 3 deletions roles/composer.serviceAgent
Original file line number Diff line number Diff line change
Expand Up @@ -425,7 +425,6 @@
"compute.licenseCodes.list",
"compute.licenseCodes.setIamPolicy",
"compute.licenseCodes.update",
"compute.licenseCodes.use",
"compute.licenses.create",
"compute.licenses.delete",
"compute.licenses.get",
Expand Down Expand Up @@ -459,11 +458,9 @@
"compute.networkEndpointGroups.deleteTagBinding",
"compute.networkEndpointGroups.detachNetworkEndpoints",
"compute.networkEndpointGroups.get",
"compute.networkEndpointGroups.getIamPolicy",
"compute.networkEndpointGroups.list",
"compute.networkEndpointGroups.listEffectiveTags",
"compute.networkEndpointGroups.listTagBindings",
"compute.networkEndpointGroups.setIamPolicy",
"compute.networkEndpointGroups.use",
"compute.networks.access",
"compute.networks.addPeering",
Expand Down Expand Up @@ -1297,6 +1294,7 @@
"iam.serviceAccounts.actAs",
"iam.serviceAccounts.get",
"iam.serviceAccounts.getAccessToken",
"iam.serviceAccounts.getOpenIdToken",
"iam.serviceAccounts.list",
"logging.buckets.create",
"logging.buckets.createTagBinding",
Expand Down Expand Up @@ -1344,6 +1342,8 @@
"logging.sinks.get",
"logging.sinks.list",
"logging.sinks.update",
"logging.sqlAlerts.create",
"logging.sqlAlerts.update",
"logging.views.create",
"logging.views.delete",
"logging.views.get",
Expand Down
5 changes: 0 additions & 5 deletions roles/compute.admin
Original file line number Diff line number Diff line change
Expand Up @@ -364,7 +364,6 @@
"compute.licenseCodes.list",
"compute.licenseCodes.setIamPolicy",
"compute.licenseCodes.update",
"compute.licenseCodes.use",
"compute.licenses.create",
"compute.licenses.delete",
"compute.licenses.get",
Expand Down Expand Up @@ -403,11 +402,9 @@
"compute.networkEndpointGroups.deleteTagBinding",
"compute.networkEndpointGroups.detachNetworkEndpoints",
"compute.networkEndpointGroups.get",
"compute.networkEndpointGroups.getIamPolicy",
"compute.networkEndpointGroups.list",
"compute.networkEndpointGroups.listEffectiveTags",
"compute.networkEndpointGroups.listTagBindings",
"compute.networkEndpointGroups.setIamPolicy",
"compute.networkEndpointGroups.use",
"compute.networks.access",
"compute.networks.addPeering",
Expand Down Expand Up @@ -676,13 +673,11 @@
"compute.securityPolicies.delete",
"compute.securityPolicies.deleteTagBinding",
"compute.securityPolicies.get",
"compute.securityPolicies.getIamPolicy",
"compute.securityPolicies.list",
"compute.securityPolicies.listEffectiveTags",
"compute.securityPolicies.listTagBindings",
"compute.securityPolicies.move",
"compute.securityPolicies.removeAssociation",
"compute.securityPolicies.setIamPolicy",
"compute.securityPolicies.setLabels",
"compute.securityPolicies.update",
"compute.securityPolicies.use",
Expand Down
2 changes: 0 additions & 2 deletions roles/compute.instanceAdmin
Original file line number Diff line number Diff line change
Expand Up @@ -157,11 +157,9 @@
"compute.networkEndpointGroups.deleteTagBinding",
"compute.networkEndpointGroups.detachNetworkEndpoints",
"compute.networkEndpointGroups.get",
"compute.networkEndpointGroups.getIamPolicy",
"compute.networkEndpointGroups.list",
"compute.networkEndpointGroups.listEffectiveTags",
"compute.networkEndpointGroups.listTagBindings",
"compute.networkEndpointGroups.setIamPolicy",
"compute.networkEndpointGroups.use",
"compute.networks.get",
"compute.networks.list",
Expand Down
Loading

0 comments on commit 96364e2

Please sign in to comment.