Skip to content

Commit

Permalink
GCP IAM Updates Detected
Browse files Browse the repository at this point in the history
  • Loading branch information
jdyke committed Dec 13, 2023
1 parent b898b4e commit 305495b
Show file tree
Hide file tree
Showing 23 changed files with 78 additions and 22 deletions.
1 change: 0 additions & 1 deletion roles/aiplatform.serviceAgent
Original file line number Diff line number Diff line change
Expand Up @@ -336,7 +336,6 @@
"compute.networks.useExternalIp",
"compute.snapshots.create",
"compute.snapshots.delete",
"compute.snapshots.useReadOnly",
"compute.subnetworks.get",
"compute.subnetworks.list",
"compute.subnetworks.use",
Expand Down
2 changes: 0 additions & 2 deletions roles/apigee.securityAdmin
Original file line number Diff line number Diff line change
Expand Up @@ -32,8 +32,6 @@
"apigee.securityProfiles.get",
"apigee.securityProfiles.list",
"apigee.securityProfiles.update",
"apigee.securitySettings.get",
"apigee.securitySettings.update",
"apigee.securityStats.queryTabularStats",
"apigee.securityStats.queryTimeSeriesStats",
"apigee.securityreports.create",
Expand Down
1 change: 0 additions & 1 deletion roles/apigee.securityViewer
Original file line number Diff line number Diff line change
Expand Up @@ -22,7 +22,6 @@
"apigee.securityProfileEnvironments.computeScore",
"apigee.securityProfiles.get",
"apigee.securityProfiles.list",
"apigee.securitySettings.get",
"apigee.securityStats.queryTabularStats",
"apigee.securityStats.queryTimeSeriesStats",
"apigee.securityreports.get",
Expand Down
2 changes: 1 addition & 1 deletion roles/bigquery.studioUser
Original file line number Diff line number Diff line change
Expand Up @@ -24,5 +24,5 @@
],
"name": "roles/bigquery.studioUser",
"stage": "BETA",
"title": "Bigquery Studio User"
"title": "BigQuery Studio User"
}
1 change: 0 additions & 1 deletion roles/binaryauthorization.serviceAgent
Original file line number Diff line number Diff line change
Expand Up @@ -2,7 +2,6 @@
"description": "Can read Notes and Occurrences from the Container Analysis Service to find and verify signatures.",
"etag": "AA==",
"includedPermissions": [
"artifactregistry.dockerimages.get",
"artifactregistry.repositories.downloadArtifacts",
"binaryauthorization.attestors.get",
"binaryauthorization.attestors.list",
Expand Down
2 changes: 1 addition & 1 deletion roles/blockchainnodeengine.viewer
Original file line number Diff line number Diff line change
Expand Up @@ -12,6 +12,6 @@
"resourcemanager.projects.list"
],
"name": "roles/blockchainnodeengine.viewer",
"stage": "BETA",
"stage": "GA",
"title": "Blockchain Node Engine Viewer"
}
1 change: 1 addition & 0 deletions roles/capacityplanner.viewer
Original file line number Diff line number Diff line change
Expand Up @@ -5,6 +5,7 @@
"capacityplanner.forecasts.list",
"capacityplanner.usageHistories.list",
"capacityplanner.usageHistories.summarize",
"cloudquotas.quotas.get",
"monitoring.timeSeries.list",
"resourcemanager.projects.get",
"resourcemanager.projects.list",
Expand Down
Empty file.
17 changes: 17 additions & 0 deletions roles/connectors.customConnectorViewer
Original file line number Diff line number Diff line change
@@ -0,0 +1,17 @@
{
"description": "Custom Connector is a regional resource which creates custom connector with the given target project. This role grants Read-only access to Custom Connector & Custom Connector Version resources.",
"etag": "AA==",
"includedPermissions": [
"connectors.customConnectorVersions.get",
"connectors.customConnectorVersions.getIamPolicy",
"connectors.customConnectorVersions.list",
"connectors.customConnectors.get",
"connectors.customConnectors.getIamPolicy",
"connectors.customConnectors.list",
"connectors.locations.get",
"connectors.locations.list"
],
"name": "roles/connectors.customConnectorViewer",
"stage": "GA",
"title": "Custom Connector Viewer"
}
6 changes: 6 additions & 0 deletions roles/connectors.viewer
Original file line number Diff line number Diff line change
Expand Up @@ -10,6 +10,12 @@
"connectors.connections.list",
"connectors.connectors.get",
"connectors.connectors.list",
"connectors.customConnectorVersions.get",
"connectors.customConnectorVersions.getIamPolicy",
"connectors.customConnectorVersions.list",
"connectors.customConnectors.get",
"connectors.customConnectors.getIamPolicy",
"connectors.customConnectors.list",
"connectors.endpointAttachments.get",
"connectors.endpointAttachments.getIamPolicy",
"connectors.endpointAttachments.list",
Expand Down
4 changes: 3 additions & 1 deletion roles/datamigration.serviceAgent
Original file line number Diff line number Diff line change
Expand Up @@ -21,6 +21,7 @@
"cloudsql.instances.delete",
"cloudsql.instances.demoteMaster",
"cloudsql.instances.get",
"cloudsql.instances.import",
"cloudsql.instances.list",
"cloudsql.instances.migrate",
"cloudsql.instances.promoteReplica",
Expand Down Expand Up @@ -52,7 +53,8 @@
"compute.subnetworks.get",
"compute.subnetworks.list",
"compute.subnetworks.use",
"storage.objects.get"
"storage.objects.get",
"storage.objects.list"
],
"name": "roles/datamigration.serviceAgent",
"stage": "GA",
Expand Down
1 change: 1 addition & 0 deletions roles/dataplex.serviceAgent
Original file line number Diff line number Diff line change
Expand Up @@ -111,6 +111,7 @@
"datacatalog.catalogs.searchAll",
"datacatalog.categories.getIamPolicy",
"datacatalog.categories.setIamPolicy",
"datacatalog.entries.get",
"datacatalog.taxonomies.create",
"datacatalog.taxonomies.delete",
"datacatalog.taxonomies.get",
Expand Down
2 changes: 1 addition & 1 deletion roles/fleetengine.deliveryAdmin
Original file line number Diff line number Diff line change
Expand Up @@ -22,6 +22,6 @@
"serviceusage.services.use"
],
"name": "roles/fleetengine.deliveryAdmin",
"stage": "GA",
"stage": "ALPHA",
"title": "Fleet Engine Delivery Admin"
}
2 changes: 1 addition & 1 deletion roles/fleetengine.ondemandAdmin
Original file line number Diff line number Diff line change
Expand Up @@ -21,6 +21,6 @@
"serviceusage.services.use"
],
"name": "roles/fleetengine.ondemandAdmin",
"stage": "ALPHA",
"stage": "GA",
"title": "Fleet Engine On-Demand Admin"
}
3 changes: 2 additions & 1 deletion roles/gkemulticloud.nodePoolMachineServiceAgent
Original file line number Diff line number Diff line change
Expand Up @@ -4,7 +4,8 @@
"includedPermissions": [
"artifactregistry.dockerimages.get",
"artifactregistry.repositories.downloadArtifacts",
"artifactregistry.repositories.get"
"artifactregistry.repositories.get",
"serviceusage.services.use"
],
"name": "roles/gkemulticloud.nodePoolMachineServiceAgent",
"stage": "GA",
Expand Down
6 changes: 0 additions & 6 deletions roles/iam.securityAdmin
Original file line number Diff line number Diff line change
Expand Up @@ -662,12 +662,6 @@
"connectors.connections.list",
"connectors.connections.setIamPolicy",
"connectors.connectors.list",
"connectors.customConnectorVersions.getIamPolicy",
"connectors.customConnectorVersions.list",
"connectors.customConnectorVersions.setIamPolicy",
"connectors.customConnectors.getIamPolicy",
"connectors.customConnectors.list",
"connectors.customConnectors.setIamPolicy",
"connectors.endpointAttachments.getIamPolicy",
"connectors.endpointAttachments.list",
"connectors.endpointAttachments.setIamPolicy",
Expand Down
2 changes: 1 addition & 1 deletion roles/kubernetesmetadata.publisher
Original file line number Diff line number Diff line change
Expand Up @@ -7,6 +7,6 @@
"kubernetesmetadata.metadata.snapshot"
],
"name": "roles/kubernetesmetadata.publisher",
"stage": "BETA",
"stage": "ALPHA",
"title": "Metadata Publisher"
}
16 changes: 16 additions & 0 deletions roles/owner
Original file line number Diff line number Diff line change
Expand Up @@ -659,6 +659,8 @@
"apigee.securityProfiles.get",
"apigee.securityProfiles.list",
"apigee.securityProfiles.update",
"apigee.securitySettings.get",
"apigee.securitySettings.update",
"apigee.securityStats.queryTabularStats",
"apigee.securityStats.queryTimeSeriesStats",
"apigee.securityreports.create",
Expand Down Expand Up @@ -3561,6 +3563,20 @@
"connectors.connections.update",
"connectors.connectors.get",
"connectors.connectors.list",
"connectors.customConnectorVersions.create",
"connectors.customConnectorVersions.delete",
"connectors.customConnectorVersions.get",
"connectors.customConnectorVersions.getIamPolicy",
"connectors.customConnectorVersions.list",
"connectors.customConnectorVersions.setIamPolicy",
"connectors.customConnectorVersions.update",
"connectors.customConnectors.create",
"connectors.customConnectors.delete",
"connectors.customConnectors.get",
"connectors.customConnectors.getIamPolicy",
"connectors.customConnectors.list",
"connectors.customConnectors.setIamPolicy",
"connectors.customConnectors.update",
"connectors.endpointAttachments.create",
"connectors.endpointAttachments.delete",
"connectors.endpointAttachments.get",
Expand Down
23 changes: 23 additions & 0 deletions roles/visionai.serviceAgent
Original file line number Diff line number Diff line change
Expand Up @@ -72,23 +72,32 @@
"visionai.applications.list",
"visionai.applications.undeploy",
"visionai.applications.update",
"visionai.assets.analyze",
"visionai.assets.clip",
"visionai.assets.create",
"visionai.assets.delete",
"visionai.assets.generateHlsUri",
"visionai.assets.get",
"visionai.assets.index",
"visionai.assets.ingest",
"visionai.assets.list",
"visionai.assets.removeIndex",
"visionai.assets.search",
"visionai.assets.update",
"visionai.assets.upload",
"visionai.clusters.create",
"visionai.clusters.delete",
"visionai.clusters.get",
"visionai.clusters.list",
"visionai.clusters.update",
"visionai.clusters.watch",
"visionai.corpora.analyze",
"visionai.corpora.create",
"visionai.corpora.delete",
"visionai.corpora.get",
"visionai.corpora.import",
"visionai.corpora.list",
"visionai.corpora.suggest",
"visionai.corpora.update",
"visionai.dataSchemas.create",
"visionai.dataSchemas.delete",
Expand All @@ -106,6 +115,20 @@
"visionai.events.get",
"visionai.events.list",
"visionai.events.update",
"visionai.indexEndpoints.create",
"visionai.indexEndpoints.delete",
"visionai.indexEndpoints.deploy",
"visionai.indexEndpoints.get",
"visionai.indexEndpoints.list",
"visionai.indexEndpoints.search",
"visionai.indexEndpoints.undeploy",
"visionai.indexEndpoints.update",
"visionai.indexes.create",
"visionai.indexes.delete",
"visionai.indexes.get",
"visionai.indexes.list",
"visionai.indexes.update",
"visionai.indexes.viewAssets",
"visionai.instances.get",
"visionai.instances.list",
"visionai.operations.get",
Expand Down
2 changes: 1 addition & 1 deletion roles/workloadmanager.deploymentAdmin
Original file line number Diff line number Diff line change
Expand Up @@ -32,6 +32,6 @@
"workloadmanager.operations.list"
],
"name": "roles/workloadmanager.deploymentAdmin",
"stage": "BETA",
"stage": "ALPHA",
"title": "Workload Manager Deployment Admin"
}
2 changes: 1 addition & 1 deletion roles/workloadmanager.deploymentViewer
Original file line number Diff line number Diff line change
Expand Up @@ -10,6 +10,6 @@
"workloadmanager.deployments.list"
],
"name": "roles/workloadmanager.deploymentViewer",
"stage": "BETA",
"stage": "ALPHA",
"title": "Workload Manager Deployment Viewer"
}
2 changes: 1 addition & 1 deletion roles/workloadmanager.evaluationAdmin
Original file line number Diff line number Diff line change
Expand Up @@ -24,6 +24,6 @@
"workloadmanager.rules.list"
],
"name": "roles/workloadmanager.evaluationAdmin",
"stage": "BETA",
"stage": "ALPHA",
"title": "Workload Manager Evaluation Admin"
}
2 changes: 1 addition & 1 deletion roles/workloadmanager.evaluationViewer
Original file line number Diff line number Diff line change
Expand Up @@ -13,6 +13,6 @@
"workloadmanager.rules.list"
],
"name": "roles/workloadmanager.evaluationViewer",
"stage": "ALPHA",
"stage": "BETA",
"title": "Workload Manager Evaluation Viewer"
}

0 comments on commit 305495b

Please sign in to comment.