Skip to content

Commit

Permalink
GCP IAM Updates Detected
Browse files Browse the repository at this point in the history
  • Loading branch information
jdyke committed Feb 19, 2024
1 parent c5f0f10 commit 8f6ceef
Show file tree
Hide file tree
Showing 22 changed files with 107 additions and 0 deletions.
8 changes: 8 additions & 0 deletions roles/alloydb.admin
Original file line number Diff line number Diff line change
Expand Up @@ -3,15 +3,23 @@
"etag": "AA==",
"includedPermissions": [
"alloydb.backups.create",
"alloydb.backups.createTagBinding",
"alloydb.backups.delete",
"alloydb.backups.deleteTagBinding",
"alloydb.backups.get",
"alloydb.backups.list",
"alloydb.backups.listEffectiveTags",
"alloydb.backups.listTagBindings",
"alloydb.backups.update",
"alloydb.clusters.create",
"alloydb.clusters.createTagBinding",
"alloydb.clusters.delete",
"alloydb.clusters.deleteTagBinding",
"alloydb.clusters.generateClientCertificate",
"alloydb.clusters.get",
"alloydb.clusters.list",
"alloydb.clusters.listEffectiveTags",
"alloydb.clusters.listTagBindings",
"alloydb.clusters.update",
"alloydb.databases.list",
"alloydb.instances.connect",
Expand Down
4 changes: 4 additions & 0 deletions roles/alloydb.viewer
Original file line number Diff line number Diff line change
Expand Up @@ -4,8 +4,12 @@
"includedPermissions": [
"alloydb.backups.get",
"alloydb.backups.list",
"alloydb.backups.listEffectiveTags",
"alloydb.backups.listTagBindings",
"alloydb.clusters.get",
"alloydb.clusters.list",
"alloydb.clusters.listEffectiveTags",
"alloydb.clusters.listTagBindings",
"alloydb.databases.list",
"alloydb.instances.get",
"alloydb.instances.list",
Expand Down
2 changes: 2 additions & 0 deletions roles/batch.serviceAgent
Original file line number Diff line number Diff line change
Expand Up @@ -322,6 +322,8 @@
"compute.sslPolicies.listAvailableFeatures",
"compute.sslPolicies.listEffectiveTags",
"compute.sslPolicies.listTagBindings",
"compute.storagePools.get",
"compute.storagePools.list",
"compute.subnetworks.get",
"compute.subnetworks.list",
"compute.subnetworks.listEffectiveTags",
Expand Down
10 changes: 10 additions & 0 deletions roles/cloudsql.schemaViewer
Original file line number Diff line number Diff line change
@@ -0,0 +1,10 @@
{
"description": "Role allowing access to the Cloud SQL instance schema on Dataplex",
"etag": "AA==",
"includedPermissions": [
"cloudsql.schemas.view"
],
"name": "roles/cloudsql.schemaViewer",
"stage": "ALPHA",
"title": "Cloud SQL Schema Viewer"
}
1 change: 1 addition & 0 deletions roles/composer.worker
Original file line number Diff line number Diff line change
Expand Up @@ -560,6 +560,7 @@
"storage.objects.getIamPolicy",
"storage.objects.list",
"storage.objects.overrideUnlockedRetention",
"storage.objects.restore",
"storage.objects.setIamPolicy",
"storage.objects.setRetention",
"storage.objects.update"
Expand Down
2 changes: 2 additions & 0 deletions roles/compute.instanceAdmin.v1
Original file line number Diff line number Diff line change
Expand Up @@ -333,6 +333,8 @@
"compute.sslPolicies.listAvailableFeatures",
"compute.sslPolicies.listEffectiveTags",
"compute.sslPolicies.listTagBindings",
"compute.storagePools.get",
"compute.storagePools.list",
"compute.subnetworks.get",
"compute.subnetworks.list",
"compute.subnetworks.listEffectiveTags",
Expand Down
3 changes: 3 additions & 0 deletions roles/compute.viewer
Original file line number Diff line number Diff line change
Expand Up @@ -244,6 +244,9 @@
"compute.sslPolicies.listAvailableFeatures",
"compute.sslPolicies.listEffectiveTags",
"compute.sslPolicies.listTagBindings",
"compute.storagePools.get",
"compute.storagePools.getIamPolicy",
"compute.storagePools.list",
"compute.subnetworks.get",
"compute.subnetworks.getIamPolicy",
"compute.subnetworks.list",
Expand Down
11 changes: 11 additions & 0 deletions roles/dataflow.serviceAgent
Original file line number Diff line number Diff line change
Expand Up @@ -662,6 +662,12 @@
"compute.sslPolicies.listTagBindings",
"compute.sslPolicies.update",
"compute.sslPolicies.use",
"compute.storagePools.create",
"compute.storagePools.delete",
"compute.storagePools.get",
"compute.storagePools.getIamPolicy",
"compute.storagePools.list",
"compute.storagePools.update",
"compute.subnetworks.create",
"compute.subnetworks.createTagBinding",
"compute.subnetworks.delete",
Expand Down Expand Up @@ -1240,6 +1246,9 @@
"serviceusage.services.use",
"stackdriver.projects.get",
"stackdriver.resourceMetadata.list",
"storage.bucketOperations.cancel",
"storage.bucketOperations.get",
"storage.bucketOperations.list",
"storage.buckets.create",
"storage.buckets.createTagBinding",
"storage.buckets.delete",
Expand All @@ -1251,6 +1260,7 @@
"storage.buckets.list",
"storage.buckets.listEffectiveTags",
"storage.buckets.listTagBindings",
"storage.buckets.restore",
"storage.buckets.setIamPolicy",
"storage.buckets.update",
"storage.managedFolders.create",
Expand All @@ -1269,6 +1279,7 @@
"storage.objects.getIamPolicy",
"storage.objects.list",
"storage.objects.overrideUnlockedRetention",
"storage.objects.restore",
"storage.objects.setIamPolicy",
"storage.objects.setRetention",
"storage.objects.update",
Expand Down
5 changes: 5 additions & 0 deletions roles/datafusion.serviceAgent
Original file line number Diff line number Diff line change
Expand Up @@ -470,6 +470,9 @@
"spanner.sessions.delete",
"spanner.sessions.get",
"spanner.sessions.list",
"storage.bucketOperations.cancel",
"storage.bucketOperations.get",
"storage.bucketOperations.list",
"storage.buckets.create",
"storage.buckets.createTagBinding",
"storage.buckets.delete",
Expand All @@ -481,6 +484,7 @@
"storage.buckets.list",
"storage.buckets.listEffectiveTags",
"storage.buckets.listTagBindings",
"storage.buckets.restore",
"storage.buckets.setIamPolicy",
"storage.buckets.update",
"storage.managedFolders.create",
Expand All @@ -499,6 +503,7 @@
"storage.objects.getIamPolicy",
"storage.objects.list",
"storage.objects.overrideUnlockedRetention",
"storage.objects.restore",
"storage.objects.setIamPolicy",
"storage.objects.setRetention",
"storage.objects.update",
Expand Down
5 changes: 5 additions & 0 deletions roles/datapipelines.serviceAgent
Original file line number Diff line number Diff line change
Expand Up @@ -58,6 +58,9 @@
"resourcemanager.projects.list",
"serviceusage.services.get",
"serviceusage.services.list",
"storage.bucketOperations.cancel",
"storage.bucketOperations.get",
"storage.bucketOperations.list",
"storage.buckets.create",
"storage.buckets.createTagBinding",
"storage.buckets.delete",
Expand All @@ -69,6 +72,7 @@
"storage.buckets.list",
"storage.buckets.listEffectiveTags",
"storage.buckets.listTagBindings",
"storage.buckets.restore",
"storage.buckets.setIamPolicy",
"storage.buckets.update",
"storage.managedFolders.create",
Expand All @@ -87,6 +91,7 @@
"storage.objects.getIamPolicy",
"storage.objects.list",
"storage.objects.overrideUnlockedRetention",
"storage.objects.restore",
"storage.objects.setIamPolicy",
"storage.objects.setRetention",
"storage.objects.update"
Expand Down
4 changes: 4 additions & 0 deletions roles/dataprep.serviceAgent
Original file line number Diff line number Diff line change
Expand Up @@ -301,6 +301,9 @@
"compute.sslPolicies.listAvailableFeatures",
"compute.sslPolicies.listEffectiveTags",
"compute.sslPolicies.listTagBindings",
"compute.storagePools.get",
"compute.storagePools.getIamPolicy",
"compute.storagePools.list",
"compute.subnetworks.get",
"compute.subnetworks.getIamPolicy",
"compute.subnetworks.list",
Expand Down Expand Up @@ -392,6 +395,7 @@
"storage.objects.getIamPolicy",
"storage.objects.list",
"storage.objects.overrideUnlockedRetention",
"storage.objects.restore",
"storage.objects.setIamPolicy",
"storage.objects.setRetention",
"storage.objects.update"
Expand Down
1 change: 1 addition & 0 deletions roles/dataproc.worker
Original file line number Diff line number Diff line change
Expand Up @@ -33,6 +33,7 @@
"storage.objects.getIamPolicy",
"storage.objects.list",
"storage.objects.overrideUnlockedRetention",
"storage.objects.restore",
"storage.objects.setIamPolicy",
"storage.objects.setRetention",
"storage.objects.update"
Expand Down
5 changes: 5 additions & 0 deletions roles/dlp.serviceAgent
Original file line number Diff line number Diff line change
Expand Up @@ -168,6 +168,9 @@
"serviceusage.services.get",
"serviceusage.services.list",
"serviceusage.services.use",
"storage.bucketOperations.cancel",
"storage.bucketOperations.get",
"storage.bucketOperations.list",
"storage.buckets.create",
"storage.buckets.createTagBinding",
"storage.buckets.delete",
Expand All @@ -179,6 +182,7 @@
"storage.buckets.list",
"storage.buckets.listEffectiveTags",
"storage.buckets.listTagBindings",
"storage.buckets.restore",
"storage.buckets.setIamPolicy",
"storage.buckets.update",
"storage.managedFolders.create",
Expand All @@ -197,6 +201,7 @@
"storage.objects.getIamPolicy",
"storage.objects.list",
"storage.objects.overrideUnlockedRetention",
"storage.objects.restore",
"storage.objects.setIamPolicy",
"storage.objects.setRetention",
"storage.objects.update"
Expand Down
5 changes: 5 additions & 0 deletions roles/iam.securityReviewer
Original file line number Diff line number Diff line change
Expand Up @@ -568,6 +568,8 @@
"compute.snapshots.list",
"compute.sslCertificates.list",
"compute.sslPolicies.list",
"compute.storagePools.getIamPolicy",
"compute.storagePools.list",
"compute.subnetworks.getIamPolicy",
"compute.subnetworks.list",
"compute.targetGrpcProxies.list",
Expand Down Expand Up @@ -1413,6 +1415,8 @@
"recommender.cloudManageabilityGeneralRecommendations.list",
"recommender.cloudPerformanceGeneralInsights.list",
"recommender.cloudPerformanceGeneralRecommendations.list",
"recommender.cloudRecentChangeInsights.list",
"recommender.cloudRecentChangeRecommendations.list",
"recommender.cloudReliabilityGeneralInsights.list",
"recommender.cloudReliabilityGeneralRecommendations.list",
"recommender.cloudSecurityGeneralInsights.list",
Expand Down Expand Up @@ -1646,6 +1650,7 @@
"speech.phraseSets.list",
"speech.recognizers.list",
"stackdriver.resourceMetadata.list",
"storage.bucketOperations.list",
"storage.buckets.getIamPolicy",
"storage.buckets.list",
"storage.hmacKeys.list",
Expand Down
5 changes: 5 additions & 0 deletions roles/ml.serviceAgent
Original file line number Diff line number Diff line change
Expand Up @@ -58,6 +58,9 @@
"recommender.iamPolicyRecommendations.update",
"resourcemanager.projects.get",
"resourcemanager.projects.list",
"storage.bucketOperations.cancel",
"storage.bucketOperations.get",
"storage.bucketOperations.list",
"storage.buckets.create",
"storage.buckets.createTagBinding",
"storage.buckets.delete",
Expand All @@ -69,6 +72,7 @@
"storage.buckets.list",
"storage.buckets.listEffectiveTags",
"storage.buckets.listTagBindings",
"storage.buckets.restore",
"storage.buckets.setIamPolicy",
"storage.buckets.update",
"storage.managedFolders.create",
Expand All @@ -87,6 +91,7 @@
"storage.objects.getIamPolicy",
"storage.objects.list",
"storage.objects.overrideUnlockedRetention",
"storage.objects.restore",
"storage.objects.setIamPolicy",
"storage.objects.setRetention",
"storage.objects.update"
Expand Down
3 changes: 3 additions & 0 deletions roles/notebooks.admin
Original file line number Diff line number Diff line change
Expand Up @@ -244,6 +244,9 @@
"compute.sslPolicies.listAvailableFeatures",
"compute.sslPolicies.listEffectiveTags",
"compute.sslPolicies.listTagBindings",
"compute.storagePools.get",
"compute.storagePools.getIamPolicy",
"compute.storagePools.list",
"compute.subnetworks.get",
"compute.subnetworks.getIamPolicy",
"compute.subnetworks.list",
Expand Down
3 changes: 3 additions & 0 deletions roles/notebooks.legacyViewer
Original file line number Diff line number Diff line change
Expand Up @@ -244,6 +244,9 @@
"compute.sslPolicies.listAvailableFeatures",
"compute.sslPolicies.listEffectiveTags",
"compute.sslPolicies.listTagBindings",
"compute.storagePools.get",
"compute.storagePools.getIamPolicy",
"compute.storagePools.list",
"compute.subnetworks.get",
"compute.subnetworks.getIamPolicy",
"compute.subnetworks.list",
Expand Down
3 changes: 3 additions & 0 deletions roles/notebooks.serviceAgent
Original file line number Diff line number Diff line change
Expand Up @@ -395,6 +395,9 @@
"compute.sslPolicies.listAvailableFeatures",
"compute.sslPolicies.listEffectiveTags",
"compute.sslPolicies.listTagBindings",
"compute.storagePools.get",
"compute.storagePools.getIamPolicy",
"compute.storagePools.list",
"compute.subnetworks.get",
"compute.subnetworks.getIamPolicy",
"compute.subnetworks.list",
Expand Down
8 changes: 8 additions & 0 deletions roles/recommender.recentchangeriskAdmin
Original file line number Diff line number Diff line change
Expand Up @@ -2,6 +2,14 @@
"description": "Admin of Recent Change Risk Insights and Recommendations.",
"etag": "AA==",
"includedPermissions": [
"recommender.cloudRecentChangeInsights.get",
"recommender.cloudRecentChangeInsights.list",
"recommender.cloudRecentChangeInsights.update",
"recommender.cloudRecentChangeRecommendations.get",
"recommender.cloudRecentChangeRecommendations.list",
"recommender.cloudRecentChangeRecommendations.update",
"recommender.cloudRecentChangeRecommenderConfig.get",
"recommender.cloudRecentChangeRecommenderConfig.update",
"recommender.locations.get",
"recommender.locations.list",
"resourcemanager.projects.get",
Expand Down
5 changes: 5 additions & 0 deletions roles/storage.admin
Original file line number Diff line number Diff line change
Expand Up @@ -12,6 +12,9 @@
"recommender.iamPolicyRecommendations.update",
"resourcemanager.projects.get",
"resourcemanager.projects.list",
"storage.bucketOperations.cancel",
"storage.bucketOperations.get",
"storage.bucketOperations.list",
"storage.buckets.create",
"storage.buckets.createTagBinding",
"storage.buckets.delete",
Expand All @@ -23,6 +26,7 @@
"storage.buckets.list",
"storage.buckets.listEffectiveTags",
"storage.buckets.listTagBindings",
"storage.buckets.restore",
"storage.buckets.setIamPolicy",
"storage.buckets.update",
"storage.managedFolders.create",
Expand All @@ -41,6 +45,7 @@
"storage.objects.getIamPolicy",
"storage.objects.list",
"storage.objects.overrideUnlockedRetention",
"storage.objects.restore",
"storage.objects.setIamPolicy",
"storage.objects.setRetention",
"storage.objects.update"
Expand Down
1 change: 1 addition & 0 deletions roles/storage.legacyBucketWriter
Original file line number Diff line number Diff line change
Expand Up @@ -14,6 +14,7 @@
"storage.objects.create",
"storage.objects.delete",
"storage.objects.list",
"storage.objects.restore",
"storage.objects.setRetention"
],
"name": "roles/storage.legacyBucketWriter",
Expand Down
Loading

0 comments on commit 8f6ceef

Please sign in to comment.