Skip to content

Commit

Permalink
GCP IAM Updates Detected
Browse files Browse the repository at this point in the history
  • Loading branch information
jdyke committed Feb 18, 2024
1 parent bc096e5 commit c5f0f10
Show file tree
Hide file tree
Showing 34 changed files with 210 additions and 0 deletions.
16 changes: 16 additions & 0 deletions roles/aiplatform.notebookExecutorUser
Original file line number Diff line number Diff line change
@@ -0,0 +1,16 @@
{
"description": "Grants users full access to schedules and notebook execution jobs.",
"etag": "AA==",
"includedPermissions": [
"aiplatform.operations.list",
"aiplatform.pipelineJobs.create",
"aiplatform.schedules.create",
"aiplatform.schedules.delete",
"aiplatform.schedules.get",
"aiplatform.schedules.list",
"aiplatform.schedules.update"
],
"name": "roles/aiplatform.notebookExecutorUser",
"stage": "BETA",
"title": "Notebook Executor User"
}
1 change: 1 addition & 0 deletions roles/cloudsql.admin
Original file line number Diff line number Diff line change
Expand Up @@ -42,6 +42,7 @@
"cloudsql.instances.stopReplica",
"cloudsql.instances.truncateLog",
"cloudsql.instances.update",
"cloudsql.schemas.view",
"cloudsql.sslCerts.create",
"cloudsql.sslCerts.delete",
"cloudsql.sslCerts.get",
Expand Down
1 change: 1 addition & 0 deletions roles/cloudsql.editor
Original file line number Diff line number Diff line change
Expand Up @@ -27,6 +27,7 @@
"cloudsql.instances.rotateServerCa",
"cloudsql.instances.truncateLog",
"cloudsql.instances.update",
"cloudsql.schemas.view",
"cloudsql.sslCerts.get",
"cloudsql.sslCerts.list",
"cloudsql.users.get",
Expand Down
2 changes: 2 additions & 0 deletions roles/cloudtpu.serviceAgent
Original file line number Diff line number Diff line change
Expand Up @@ -554,6 +554,8 @@
"compute.sslPolicies.listTagBindings",
"compute.sslPolicies.update",
"compute.sslPolicies.use",
"compute.storagePools.get",
"compute.storagePools.list",
"compute.subnetworks.create",
"compute.subnetworks.createTagBinding",
"compute.subnetworks.delete",
Expand Down
1 change: 1 addition & 0 deletions roles/composer.environmentAndStorageObjectAdmin
Original file line number Diff line number Diff line change
Expand Up @@ -46,6 +46,7 @@
"storage.objects.getIamPolicy",
"storage.objects.list",
"storage.objects.overrideUnlockedRetention",
"storage.objects.restore",
"storage.objects.setIamPolicy",
"storage.objects.setRetention",
"storage.objects.update"
Expand Down
8 changes: 8 additions & 0 deletions roles/composer.serviceAgent
Original file line number Diff line number Diff line change
Expand Up @@ -71,6 +71,7 @@
"cloudsql.instances.stopReplica",
"cloudsql.instances.truncateLog",
"cloudsql.instances.update",
"cloudsql.schemas.view",
"cloudsql.sslCerts.create",
"cloudsql.sslCerts.delete",
"cloudsql.sslCerts.get",
Expand Down Expand Up @@ -631,6 +632,8 @@
"compute.sslPolicies.listTagBindings",
"compute.sslPolicies.update",
"compute.sslPolicies.use",
"compute.storagePools.get",
"compute.storagePools.list",
"compute.subnetworks.create",
"compute.subnetworks.createTagBinding",
"compute.subnetworks.delete",
Expand Down Expand Up @@ -1644,6 +1647,9 @@
"serviceusage.services.list",
"stackdriver.projects.get",
"stackdriver.resourceMetadata.list",
"storage.bucketOperations.cancel",
"storage.bucketOperations.get",
"storage.bucketOperations.list",
"storage.buckets.create",
"storage.buckets.createTagBinding",
"storage.buckets.delete",
Expand All @@ -1655,6 +1661,7 @@
"storage.buckets.list",
"storage.buckets.listEffectiveTags",
"storage.buckets.listTagBindings",
"storage.buckets.restore",
"storage.buckets.setIamPolicy",
"storage.buckets.update",
"storage.managedFolders.create",
Expand All @@ -1673,6 +1680,7 @@
"storage.objects.getIamPolicy",
"storage.objects.list",
"storage.objects.overrideUnlockedRetention",
"storage.objects.restore",
"storage.objects.setIamPolicy",
"storage.objects.setRetention",
"storage.objects.update",
Expand Down
6 changes: 6 additions & 0 deletions roles/compute.admin
Original file line number Diff line number Diff line change
Expand Up @@ -685,6 +685,12 @@
"compute.sslPolicies.listTagBindings",
"compute.sslPolicies.update",
"compute.sslPolicies.use",
"compute.storagePools.create",
"compute.storagePools.delete",
"compute.storagePools.get",
"compute.storagePools.getIamPolicy",
"compute.storagePools.list",
"compute.storagePools.update",
"compute.subnetworks.create",
"compute.subnetworks.createTagBinding",
"compute.subnetworks.delete",
Expand Down
2 changes: 2 additions & 0 deletions roles/compute.instanceAdmin
Original file line number Diff line number Diff line change
Expand Up @@ -178,6 +178,8 @@
"compute.reservations.get",
"compute.reservations.list",
"compute.resourcePolicies.useReadOnly",
"compute.storagePools.get",
"compute.storagePools.list",
"compute.subnetworks.get",
"compute.subnetworks.list",
"compute.subnetworks.listEffectiveTags",
Expand Down
6 changes: 6 additions & 0 deletions roles/compute.storageAdmin
Original file line number Diff line number Diff line change
Expand Up @@ -90,6 +90,12 @@
"compute.snapshots.setIamPolicy",
"compute.snapshots.setLabels",
"compute.snapshots.useReadOnly",
"compute.storagePools.create",
"compute.storagePools.delete",
"compute.storagePools.get",
"compute.storagePools.getIamPolicy",
"compute.storagePools.list",
"compute.storagePools.update",
"compute.zoneOperations.get",
"compute.zoneOperations.list",
"compute.zones.get",
Expand Down
6 changes: 6 additions & 0 deletions roles/container.serviceAgent
Original file line number Diff line number Diff line change
Expand Up @@ -639,6 +639,12 @@
"compute.sslPolicies.listTagBindings",
"compute.sslPolicies.update",
"compute.sslPolicies.use",
"compute.storagePools.create",
"compute.storagePools.delete",
"compute.storagePools.get",
"compute.storagePools.getIamPolicy",
"compute.storagePools.list",
"compute.storagePools.update",
"compute.subnetworks.create",
"compute.subnetworks.createTagBinding",
"compute.subnetworks.delete",
Expand Down
5 changes: 5 additions & 0 deletions roles/dataplex.serviceAgent
Original file line number Diff line number Diff line change
Expand Up @@ -212,6 +212,9 @@
"resourcemanager.projects.list",
"servicemanagement.services.report",
"serviceusage.services.use",
"storage.bucketOperations.cancel",
"storage.bucketOperations.get",
"storage.bucketOperations.list",
"storage.buckets.create",
"storage.buckets.createTagBinding",
"storage.buckets.delete",
Expand All @@ -223,6 +226,7 @@
"storage.buckets.list",
"storage.buckets.listEffectiveTags",
"storage.buckets.listTagBindings",
"storage.buckets.restore",
"storage.buckets.setIamPolicy",
"storage.buckets.update",
"storage.managedFolders.create",
Expand All @@ -241,6 +245,7 @@
"storage.objects.getIamPolicy",
"storage.objects.list",
"storage.objects.overrideUnlockedRetention",
"storage.objects.restore",
"storage.objects.setIamPolicy",
"storage.objects.setRetention",
"storage.objects.update"
Expand Down
7 changes: 7 additions & 0 deletions roles/dataproc.serviceAgent
Original file line number Diff line number Diff line change
Expand Up @@ -184,6 +184,8 @@
"compute.reservations.get",
"compute.reservations.list",
"compute.resourcePolicies.useReadOnly",
"compute.storagePools.get",
"compute.storagePools.list",
"compute.subnetworks.get",
"compute.subnetworks.list",
"compute.subnetworks.listEffectiveTags",
Expand Down Expand Up @@ -281,6 +283,9 @@
"serviceusage.services.get",
"serviceusage.services.list",
"serviceusage.services.use",
"storage.bucketOperations.cancel",
"storage.bucketOperations.get",
"storage.bucketOperations.list",
"storage.buckets.create",
"storage.buckets.createTagBinding",
"storage.buckets.delete",
Expand All @@ -292,6 +297,7 @@
"storage.buckets.list",
"storage.buckets.listEffectiveTags",
"storage.buckets.listTagBindings",
"storage.buckets.restore",
"storage.buckets.setIamPolicy",
"storage.buckets.update",
"storage.managedFolders.create",
Expand All @@ -310,6 +316,7 @@
"storage.objects.getIamPolicy",
"storage.objects.list",
"storage.objects.overrideUnlockedRetention",
"storage.objects.restore",
"storage.objects.setIamPolicy",
"storage.objects.setRetention",
"storage.objects.update"
Expand Down
19 changes: 19 additions & 0 deletions roles/editor
Original file line number Diff line number Diff line change
Expand Up @@ -328,12 +328,16 @@
"alloydb.backups.delete",
"alloydb.backups.get",
"alloydb.backups.list",
"alloydb.backups.listEffectiveTags",
"alloydb.backups.listTagBindings",
"alloydb.backups.update",
"alloydb.clusters.create",
"alloydb.clusters.delete",
"alloydb.clusters.generateClientCertificate",
"alloydb.clusters.get",
"alloydb.clusters.list",
"alloydb.clusters.listEffectiveTags",
"alloydb.clusters.listTagBindings",
"alloydb.clusters.update",
"alloydb.databases.list",
"alloydb.instances.connect",
Expand Down Expand Up @@ -1928,6 +1932,7 @@
"cloudsql.instances.stopReplica",
"cloudsql.instances.truncateLog",
"cloudsql.instances.update",
"cloudsql.schemas.view",
"cloudsql.sslCerts.create",
"cloudsql.sslCerts.delete",
"cloudsql.sslCerts.get",
Expand Down Expand Up @@ -2765,6 +2770,12 @@
"compute.sslPolicies.listTagBindings",
"compute.sslPolicies.update",
"compute.sslPolicies.use",
"compute.storagePools.create",
"compute.storagePools.delete",
"compute.storagePools.get",
"compute.storagePools.getIamPolicy",
"compute.storagePools.list",
"compute.storagePools.update",
"compute.subnetworks.create",
"compute.subnetworks.delete",
"compute.subnetworks.expandIpCidrRange",
Expand Down Expand Up @@ -6504,6 +6515,14 @@
"recommender.cloudPerformanceGeneralRecommendations.get",
"recommender.cloudPerformanceGeneralRecommendations.list",
"recommender.cloudPerformanceGeneralRecommendations.update",
"recommender.cloudRecentChangeInsights.get",
"recommender.cloudRecentChangeInsights.list",
"recommender.cloudRecentChangeInsights.update",
"recommender.cloudRecentChangeRecommendations.get",
"recommender.cloudRecentChangeRecommendations.list",
"recommender.cloudRecentChangeRecommendations.update",
"recommender.cloudRecentChangeRecommenderConfig.get",
"recommender.cloudRecentChangeRecommenderConfig.update",
"recommender.cloudReliabilityGeneralInsights.get",
"recommender.cloudReliabilityGeneralInsights.list",
"recommender.cloudReliabilityGeneralInsights.update",
Expand Down
5 changes: 5 additions & 0 deletions roles/firebase.admin
Original file line number Diff line number Diff line change
Expand Up @@ -451,6 +451,9 @@
"serviceusage.quotas.get",
"serviceusage.services.get",
"serviceusage.services.list",
"storage.bucketOperations.cancel",
"storage.bucketOperations.get",
"storage.bucketOperations.list",
"storage.buckets.create",
"storage.buckets.createTagBinding",
"storage.buckets.delete",
Expand All @@ -462,6 +465,7 @@
"storage.buckets.list",
"storage.buckets.listEffectiveTags",
"storage.buckets.listTagBindings",
"storage.buckets.restore",
"storage.buckets.setIamPolicy",
"storage.buckets.update",
"storage.managedFolders.create",
Expand All @@ -480,6 +484,7 @@
"storage.objects.getIamPolicy",
"storage.objects.list",
"storage.objects.overrideUnlockedRetention",
"storage.objects.restore",
"storage.objects.setIamPolicy",
"storage.objects.setRetention",
"storage.objects.update"
Expand Down
5 changes: 5 additions & 0 deletions roles/firebase.developAdmin
Original file line number Diff line number Diff line change
Expand Up @@ -355,6 +355,9 @@
"serviceusage.quotas.get",
"serviceusage.services.get",
"serviceusage.services.list",
"storage.bucketOperations.cancel",
"storage.bucketOperations.get",
"storage.bucketOperations.list",
"storage.buckets.create",
"storage.buckets.createTagBinding",
"storage.buckets.delete",
Expand All @@ -366,6 +369,7 @@
"storage.buckets.list",
"storage.buckets.listEffectiveTags",
"storage.buckets.listTagBindings",
"storage.buckets.restore",
"storage.buckets.setIamPolicy",
"storage.buckets.update",
"storage.managedFolders.create",
Expand All @@ -384,6 +388,7 @@
"storage.objects.getIamPolicy",
"storage.objects.list",
"storage.objects.overrideUnlockedRetention",
"storage.objects.restore",
"storage.objects.setIamPolicy",
"storage.objects.setRetention",
"storage.objects.update"
Expand Down
1 change: 1 addition & 0 deletions roles/firebase.sdkAdminServiceAgent
Original file line number Diff line number Diff line change
Expand Up @@ -122,6 +122,7 @@
"storage.objects.getIamPolicy",
"storage.objects.list",
"storage.objects.overrideUnlockedRetention",
"storage.objects.restore",
"storage.objects.setIamPolicy",
"storage.objects.setRetention",
"storage.objects.update"
Expand Down
2 changes: 2 additions & 0 deletions roles/genomics.serviceAgent
Original file line number Diff line number Diff line change
Expand Up @@ -333,6 +333,8 @@
"compute.sslPolicies.listAvailableFeatures",
"compute.sslPolicies.listEffectiveTags",
"compute.sslPolicies.listTagBindings",
"compute.storagePools.get",
"compute.storagePools.list",
"compute.subnetworks.get",
"compute.subnetworks.list",
"compute.subnetworks.listEffectiveTags",
Expand Down
5 changes: 5 additions & 0 deletions roles/iam.securityAdmin
Original file line number Diff line number Diff line change
Expand Up @@ -653,6 +653,8 @@
"compute.snapshots.setIamPolicy",
"compute.sslCertificates.list",
"compute.sslPolicies.list",
"compute.storagePools.getIamPolicy",
"compute.storagePools.list",
"compute.subnetworks.getIamPolicy",
"compute.subnetworks.list",
"compute.subnetworks.setIamPolicy",
Expand Down Expand Up @@ -1646,6 +1648,8 @@
"recommender.cloudManageabilityGeneralRecommendations.list",
"recommender.cloudPerformanceGeneralInsights.list",
"recommender.cloudPerformanceGeneralRecommendations.list",
"recommender.cloudRecentChangeInsights.list",
"recommender.cloudRecentChangeRecommendations.list",
"recommender.cloudReliabilityGeneralInsights.list",
"recommender.cloudReliabilityGeneralRecommendations.list",
"recommender.cloudSecurityGeneralInsights.list",
Expand Down Expand Up @@ -1904,6 +1908,7 @@
"speech.phraseSets.list",
"speech.recognizers.list",
"stackdriver.resourceMetadata.list",
"storage.bucketOperations.list",
"storage.buckets.getIamPolicy",
"storage.buckets.list",
"storage.buckets.setIamPolicy",
Expand Down
2 changes: 2 additions & 0 deletions roles/lifesciences.serviceAgent
Original file line number Diff line number Diff line change
Expand Up @@ -333,6 +333,8 @@
"compute.sslPolicies.listAvailableFeatures",
"compute.sslPolicies.listEffectiveTags",
"compute.sslPolicies.listTagBindings",
"compute.storagePools.get",
"compute.storagePools.list",
"compute.subnetworks.get",
"compute.subnetworks.list",
"compute.subnetworks.listEffectiveTags",
Expand Down
6 changes: 6 additions & 0 deletions roles/notebooks.legacyAdmin
Original file line number Diff line number Diff line change
Expand Up @@ -685,6 +685,12 @@
"compute.sslPolicies.listTagBindings",
"compute.sslPolicies.update",
"compute.sslPolicies.use",
"compute.storagePools.create",
"compute.storagePools.delete",
"compute.storagePools.get",
"compute.storagePools.getIamPolicy",
"compute.storagePools.list",
"compute.storagePools.update",
"compute.subnetworks.create",
"compute.subnetworks.createTagBinding",
"compute.subnetworks.delete",
Expand Down
3 changes: 3 additions & 0 deletions roles/notebooks.runner
Original file line number Diff line number Diff line change
Expand Up @@ -244,6 +244,9 @@
"compute.sslPolicies.listAvailableFeatures",
"compute.sslPolicies.listEffectiveTags",
"compute.sslPolicies.listTagBindings",
"compute.storagePools.get",
"compute.storagePools.getIamPolicy",
"compute.storagePools.list",
"compute.subnetworks.get",
"compute.subnetworks.getIamPolicy",
"compute.subnetworks.list",
Expand Down
3 changes: 3 additions & 0 deletions roles/notebooks.viewer
Original file line number Diff line number Diff line change
Expand Up @@ -244,6 +244,9 @@
"compute.sslPolicies.listAvailableFeatures",
"compute.sslPolicies.listEffectiveTags",
"compute.sslPolicies.listTagBindings",
"compute.storagePools.get",
"compute.storagePools.getIamPolicy",
"compute.storagePools.list",
"compute.subnetworks.get",
"compute.subnetworks.getIamPolicy",
"compute.subnetworks.list",
Expand Down
Loading

0 comments on commit c5f0f10

Please sign in to comment.