Skip to content

Commit

Permalink
GCP IAM Updates Detected
Browse files Browse the repository at this point in the history
  • Loading branch information
jdyke committed May 23, 2024
1 parent b5437e2 commit 1ace903
Show file tree
Hide file tree
Showing 8 changed files with 58 additions and 0 deletions.
2 changes: 2 additions & 0 deletions roles/bigquery.dataOwner
Original file line number Diff line number Diff line change
Expand Up @@ -57,6 +57,8 @@
"bigquery.tables.getData",
"bigquery.tables.getIamPolicy",
"bigquery.tables.list",
"bigquery.tables.listEffectiveTags",
"bigquery.tables.listTagBindings",
"bigquery.tables.replicateData",
"bigquery.tables.restoreSnapshot",
"bigquery.tables.setCategory",
Expand Down
2 changes: 2 additions & 0 deletions roles/bigquery.studioAdmin
Original file line number Diff line number Diff line change
Expand Up @@ -116,6 +116,8 @@
"bigquery.tables.getData",
"bigquery.tables.getIamPolicy",
"bigquery.tables.list",
"bigquery.tables.listEffectiveTags",
"bigquery.tables.listTagBindings",
"bigquery.tables.replicateData",
"bigquery.tables.restoreSnapshot",
"bigquery.tables.setCategory",
Expand Down
43 changes: 43 additions & 0 deletions roles/configdelivery.serviceAgent
Original file line number Diff line number Diff line change
@@ -0,0 +1,43 @@
{
"description": "Gives the Config Delivery service account permission to manage resources ",
"etag": "AA==",
"includedPermissions": [
"artifactregistry.dockerimages.get",
"artifactregistry.dockerimages.list",
"artifactregistry.projectsettings.get",
"artifactregistry.repositories.create",
"artifactregistry.repositories.downloadArtifacts",
"artifactregistry.repositories.get",
"artifactregistry.repositories.getIamPolicy",
"artifactregistry.repositories.list",
"artifactregistry.repositories.listEffectiveTags",
"artifactregistry.repositories.listTagBindings",
"artifactregistry.repositories.setIamPolicy",
"artifactregistry.repositories.uploadArtifacts",
"artifactregistry.tags.create",
"artifactregistry.tags.delete",
"artifactregistry.tags.get",
"artifactregistry.tags.list",
"artifactregistry.tags.update",
"artifactregistry.versions.delete",
"artifactregistry.versions.get",
"artifactregistry.versions.list",
"cloudbuild.builds.create",
"cloudbuild.builds.get",
"cloudbuild.builds.list",
"cloudbuild.builds.update",
"container.customResourceDefinitions.get",
"container.customResourceDefinitions.list",
"container.serviceAccounts.get",
"container.serviceAccounts.list",
"container.thirdPartyObjects.create",
"container.thirdPartyObjects.delete",
"container.thirdPartyObjects.get",
"container.thirdPartyObjects.list",
"container.thirdPartyObjects.update",
"iam.serviceAccounts.actAs"
],
"name": "roles/configdelivery.serviceAgent",
"stage": "ALPHA",
"title": "Config Delivery Service Agent"
}
2 changes: 2 additions & 0 deletions roles/dataflow.serviceAgent
Original file line number Diff line number Diff line change
Expand Up @@ -100,6 +100,8 @@
"bigquery.tables.getData",
"bigquery.tables.getIamPolicy",
"bigquery.tables.list",
"bigquery.tables.listEffectiveTags",
"bigquery.tables.listTagBindings",
"bigquery.tables.replicateData",
"bigquery.tables.restoreSnapshot",
"bigquery.tables.setCategory",
Expand Down
2 changes: 2 additions & 0 deletions roles/dataplex.serviceAgent
Original file line number Diff line number Diff line change
Expand Up @@ -100,6 +100,8 @@
"bigquery.tables.getData",
"bigquery.tables.getIamPolicy",
"bigquery.tables.list",
"bigquery.tables.listEffectiveTags",
"bigquery.tables.listTagBindings",
"bigquery.tables.replicateData",
"bigquery.tables.restoreSnapshot",
"bigquery.tables.setCategory",
Expand Down
3 changes: 3 additions & 0 deletions roles/editor
Original file line number Diff line number Diff line change
Expand Up @@ -1336,6 +1336,8 @@
"bigquery.tables.createSnapshot",
"bigquery.tables.deleteIndex",
"bigquery.tables.getIamPolicy",
"bigquery.tables.listEffectiveTags",
"bigquery.tables.listTagBindings",
"bigquery.tables.replicateData",
"bigquery.tables.restoreSnapshot",
"bigquery.transfers.get",
Expand Down Expand Up @@ -5874,6 +5876,7 @@
"logging.queries.list",
"logging.queries.listShared",
"logging.queries.update",
"logging.queries.usePrivate",
"logging.settings.get",
"logging.settings.update",
"logging.sinks.get",
Expand Down
1 change: 1 addition & 0 deletions roles/logging.privateLogViewer
Original file line number Diff line number Diff line change
Expand Up @@ -24,6 +24,7 @@
"logging.queries.list",
"logging.queries.listShared",
"logging.queries.update",
"logging.queries.usePrivate",
"logging.sinks.get",
"logging.sinks.list",
"logging.usage.get",
Expand Down
3 changes: 3 additions & 0 deletions roles/viewer
Original file line number Diff line number Diff line change
Expand Up @@ -639,6 +639,8 @@
"bigquery.savedqueries.list",
"bigquery.tables.createSnapshot",
"bigquery.tables.getIamPolicy",
"bigquery.tables.listEffectiveTags",
"bigquery.tables.listTagBindings",
"bigquery.tables.replicateData",
"bigquery.transfers.get",
"bigquerymigration.locations.get",
Expand Down Expand Up @@ -2891,6 +2893,7 @@
"logging.queries.list",
"logging.queries.listShared",
"logging.queries.update",
"logging.queries.usePrivate",
"logging.settings.get",
"logging.sinks.get",
"logging.sinks.list",
Expand Down

0 comments on commit 1ace903

Please sign in to comment.