Skip to content

Commit

Permalink
GCP IAM Updates Detected
Browse files Browse the repository at this point in the history
  • Loading branch information
jdyke committed Mar 24, 2024
1 parent a38ae82 commit 74d9f01
Show file tree
Hide file tree
Showing 9 changed files with 56 additions and 21 deletions.
19 changes: 19 additions & 0 deletions roles/apihub.admin
Original file line number Diff line number Diff line change
Expand Up @@ -2,6 +2,25 @@
"description": "Full access to Cloud API Hub Registry and Runtime resources.",
"etag": "AA==",
"includedPermissions": [
"apihub.apis.create",
"apihub.apis.delete",
"apihub.apis.get",
"apihub.apis.list",
"apihub.apis.update",
"apihub.operations.cancel",
"apihub.operations.delete",
"apihub.operations.get",
"apihub.operations.list",
"apihub.specs.create",
"apihub.specs.delete",
"apihub.specs.get",
"apihub.specs.list",
"apihub.specs.update",
"apihub.versions.create",
"apihub.versions.delete",
"apihub.versions.get",
"apihub.versions.list",
"apihub.versions.update",
"resourcemanager.projects.get",
"resourcemanager.projects.list"
],
Expand Down
6 changes: 6 additions & 0 deletions roles/apihub.viewer
Original file line number Diff line number Diff line change
Expand Up @@ -2,6 +2,12 @@
"description": "Read-only access to Cloud API Hub Registry resources.",
"etag": "AA==",
"includedPermissions": [
"apihub.apis.get",
"apihub.apis.list",
"apihub.specs.get",
"apihub.specs.list",
"apihub.versions.get",
"apihub.versions.list",
"resourcemanager.projects.get",
"resourcemanager.projects.list"
],
Expand Down
5 changes: 5 additions & 0 deletions roles/gdchardwaremanagement.admin
Original file line number Diff line number Diff line change
Expand Up @@ -33,6 +33,11 @@
"gdchardwaremanagement.sites.update",
"gdchardwaremanagement.skus.get",
"gdchardwaremanagement.skus.list",
"gdchardwaremanagement.zones.create",
"gdchardwaremanagement.zones.delete",
"gdchardwaremanagement.zones.get",
"gdchardwaremanagement.zones.list",
"gdchardwaremanagement.zones.update",
"resourcemanager.projects.get",
"resourcemanager.projects.list"
],
Expand Down
5 changes: 5 additions & 0 deletions roles/gdchardwaremanagement.operator
Original file line number Diff line number Diff line change
Expand Up @@ -29,6 +29,11 @@
"gdchardwaremanagement.sites.update",
"gdchardwaremanagement.skus.get",
"gdchardwaremanagement.skus.list",
"gdchardwaremanagement.zones.create",
"gdchardwaremanagement.zones.delete",
"gdchardwaremanagement.zones.get",
"gdchardwaremanagement.zones.list",
"gdchardwaremanagement.zones.update",
"resourcemanager.projects.get",
"resourcemanager.projects.list"
],
Expand Down
2 changes: 2 additions & 0 deletions roles/gdchardwaremanagement.reader
Original file line number Diff line number Diff line change
Expand Up @@ -20,6 +20,8 @@
"gdchardwaremanagement.sites.list",
"gdchardwaremanagement.skus.get",
"gdchardwaremanagement.skus.list",
"gdchardwaremanagement.zones.get",
"gdchardwaremanagement.zones.list",
"resourcemanager.projects.get",
"resourcemanager.projects.list"
],
Expand Down
1 change: 1 addition & 0 deletions roles/privilegedaccessmanager.admin
Original file line number Diff line number Diff line change
Expand Up @@ -11,6 +11,7 @@
"privilegedaccessmanager.grants.get",
"privilegedaccessmanager.grants.list",
"privilegedaccessmanager.grants.revoke",
"privilegedaccessmanager.locations.checkOnboardingStatus",
"privilegedaccessmanager.locations.get",
"privilegedaccessmanager.locations.list",
"privilegedaccessmanager.operations.delete",
Expand Down
14 changes: 0 additions & 14 deletions roles/privilegedaccessmanager.approver

This file was deleted.

7 changes: 0 additions & 7 deletions roles/privilegedaccessmanager.requester

This file was deleted.

18 changes: 18 additions & 0 deletions roles/privilegedaccessmanager.serviceAgent
Original file line number Diff line number Diff line change
@@ -0,0 +1,18 @@
{
"description": "Gives privileged access manager service account access to modify IAM policies on GCP resources",
"etag": "AA==",
"includedPermissions": [
"resourcemanager.folders.get",
"resourcemanager.folders.getIamPolicy",
"resourcemanager.folders.setIamPolicy",
"resourcemanager.organizations.get",
"resourcemanager.organizations.getIamPolicy",
"resourcemanager.organizations.setIamPolicy",
"resourcemanager.projects.get",
"resourcemanager.projects.getIamPolicy",
"resourcemanager.projects.setIamPolicy"
],
"name": "roles/privilegedaccessmanager.serviceAgent",
"stage": "ALPHA",
"title": "Privileged Access Manager Service Agent"
}

0 comments on commit 74d9f01

Please sign in to comment.