Skip to content

Commit

Permalink
GCP IAM Updates Detected
Browse files Browse the repository at this point in the history
  • Loading branch information
jdyke committed May 10, 2024
1 parent 61999b3 commit d0de827
Show file tree
Hide file tree
Showing 47 changed files with 151 additions and 31 deletions.
21 changes: 21 additions & 0 deletions roles/aiplatform.admin
Original file line number Diff line number Diff line change
Expand Up @@ -2,6 +2,16 @@
"description": "Grants full access to all resources in Vertex AI",
"etag": "AA==",
"includedPermissions": [
"aiplatform.agentExamples.create",
"aiplatform.agentExamples.delete",
"aiplatform.agentExamples.get",
"aiplatform.agentExamples.list",
"aiplatform.agentExamples.update",
"aiplatform.agents.create",
"aiplatform.agents.delete",
"aiplatform.agents.get",
"aiplatform.agents.list",
"aiplatform.agents.update",
"aiplatform.annotationSpecs.create",
"aiplatform.annotationSpecs.delete",
"aiplatform.annotationSpecs.get",
Expand All @@ -12,6 +22,11 @@
"aiplatform.annotations.get",
"aiplatform.annotations.list",
"aiplatform.annotations.update",
"aiplatform.apps.create",
"aiplatform.apps.delete",
"aiplatform.apps.get",
"aiplatform.apps.list",
"aiplatform.apps.update",
"aiplatform.artifacts.create",
"aiplatform.artifacts.delete",
"aiplatform.artifacts.get",
Expand All @@ -22,6 +37,8 @@
"aiplatform.batchPredictionJobs.delete",
"aiplatform.batchPredictionJobs.get",
"aiplatform.batchPredictionJobs.list",
"aiplatform.cacheConfigs.get",
"aiplatform.cacheConfigs.update",
"aiplatform.consents.get",
"aiplatform.consents.update",
"aiplatform.contexts.addContextArtifactsAndExecutions",
Expand Down Expand Up @@ -255,6 +272,9 @@
"aiplatform.schedules.get",
"aiplatform.schedules.list",
"aiplatform.schedules.update",
"aiplatform.sessions.get",
"aiplatform.sessions.list",
"aiplatform.sessions.run",
"aiplatform.specialistPools.create",
"aiplatform.specialistPools.delete",
"aiplatform.specialistPools.get",
Expand Down Expand Up @@ -307,6 +327,7 @@
"aiplatform.tuningJobs.delete",
"aiplatform.tuningJobs.get",
"aiplatform.tuningJobs.list",
"aiplatform.tuningJobs.vertexTune",
"resourcemanager.projects.get",
"resourcemanager.projects.list"
],
Expand Down
20 changes: 20 additions & 0 deletions roles/aiplatform.customCodeServiceAgent
Original file line number Diff line number Diff line change
Expand Up @@ -2,6 +2,16 @@
"description": "Gives Vertex AI Custom Code the proper permissions.",
"etag": "AA==",
"includedPermissions": [
"aiplatform.agentExamples.create",
"aiplatform.agentExamples.delete",
"aiplatform.agentExamples.get",
"aiplatform.agentExamples.list",
"aiplatform.agentExamples.update",
"aiplatform.agents.create",
"aiplatform.agents.delete",
"aiplatform.agents.get",
"aiplatform.agents.list",
"aiplatform.agents.update",
"aiplatform.annotationSpecs.create",
"aiplatform.annotationSpecs.delete",
"aiplatform.annotationSpecs.get",
Expand All @@ -12,6 +22,11 @@
"aiplatform.annotations.get",
"aiplatform.annotations.list",
"aiplatform.annotations.update",
"aiplatform.apps.create",
"aiplatform.apps.delete",
"aiplatform.apps.get",
"aiplatform.apps.list",
"aiplatform.apps.update",
"aiplatform.artifacts.create",
"aiplatform.artifacts.delete",
"aiplatform.artifacts.get",
Expand All @@ -22,6 +37,7 @@
"aiplatform.batchPredictionJobs.delete",
"aiplatform.batchPredictionJobs.get",
"aiplatform.batchPredictionJobs.list",
"aiplatform.cacheConfigs.get",
"aiplatform.consents.get",
"aiplatform.contexts.addContextArtifactsAndExecutions",
"aiplatform.contexts.addContextChildren",
Expand Down Expand Up @@ -242,6 +258,9 @@
"aiplatform.schedules.get",
"aiplatform.schedules.list",
"aiplatform.schedules.update",
"aiplatform.sessions.get",
"aiplatform.sessions.list",
"aiplatform.sessions.run",
"aiplatform.specialistPools.create",
"aiplatform.specialistPools.delete",
"aiplatform.specialistPools.get",
Expand Down Expand Up @@ -293,6 +312,7 @@
"aiplatform.tuningJobs.delete",
"aiplatform.tuningJobs.get",
"aiplatform.tuningJobs.list",
"aiplatform.tuningJobs.vertexTune",
"artifactregistry.repositories.downloadArtifacts",
"artifactregistry.repositories.get",
"artifactregistry.repositories.list",
Expand Down
1 change: 1 addition & 0 deletions roles/aiplatform.notebookRuntimeAdmin
Original file line number Diff line number Diff line change
Expand Up @@ -9,6 +9,7 @@
"aiplatform.notebookRuntimeTemplates.getIamPolicy",
"aiplatform.notebookRuntimeTemplates.list",
"aiplatform.notebookRuntimeTemplates.setIamPolicy",
"aiplatform.notebookRuntimeTemplates.update",
"aiplatform.notebookRuntimes.assign",
"aiplatform.notebookRuntimes.delete",
"aiplatform.notebookRuntimes.get",
Expand Down
20 changes: 20 additions & 0 deletions roles/aiplatform.user
Original file line number Diff line number Diff line change
Expand Up @@ -2,6 +2,16 @@
"description": "Grants access to use all resource in Vertex AI",
"etag": "AA==",
"includedPermissions": [
"aiplatform.agentExamples.create",
"aiplatform.agentExamples.delete",
"aiplatform.agentExamples.get",
"aiplatform.agentExamples.list",
"aiplatform.agentExamples.update",
"aiplatform.agents.create",
"aiplatform.agents.delete",
"aiplatform.agents.get",
"aiplatform.agents.list",
"aiplatform.agents.update",
"aiplatform.annotationSpecs.create",
"aiplatform.annotationSpecs.delete",
"aiplatform.annotationSpecs.get",
Expand All @@ -12,6 +22,11 @@
"aiplatform.annotations.get",
"aiplatform.annotations.list",
"aiplatform.annotations.update",
"aiplatform.apps.create",
"aiplatform.apps.delete",
"aiplatform.apps.get",
"aiplatform.apps.list",
"aiplatform.apps.update",
"aiplatform.artifacts.create",
"aiplatform.artifacts.delete",
"aiplatform.artifacts.get",
Expand All @@ -22,6 +37,7 @@
"aiplatform.batchPredictionJobs.delete",
"aiplatform.batchPredictionJobs.get",
"aiplatform.batchPredictionJobs.list",
"aiplatform.cacheConfigs.get",
"aiplatform.consents.get",
"aiplatform.contexts.addContextArtifactsAndExecutions",
"aiplatform.contexts.addContextChildren",
Expand Down Expand Up @@ -242,6 +258,9 @@
"aiplatform.schedules.get",
"aiplatform.schedules.list",
"aiplatform.schedules.update",
"aiplatform.sessions.get",
"aiplatform.sessions.list",
"aiplatform.sessions.run",
"aiplatform.specialistPools.create",
"aiplatform.specialistPools.delete",
"aiplatform.specialistPools.get",
Expand Down Expand Up @@ -293,6 +312,7 @@
"aiplatform.tuningJobs.delete",
"aiplatform.tuningJobs.get",
"aiplatform.tuningJobs.list",
"aiplatform.tuningJobs.vertexTune",
"resourcemanager.projects.get",
"resourcemanager.projects.list"
],
Expand Down
2 changes: 1 addition & 1 deletion roles/apihub.admin
Original file line number Diff line number Diff line change
@@ -1,5 +1,5 @@
{
"description": "Full access to Cloud API Hub Registry and Runtime resources.",
"description": "Full access to all API hub resources.",
"etag": "AA==",
"includedPermissions": [
"apihub.apiHubInstances.create",
Expand Down
4 changes: 2 additions & 2 deletions roles/apihub.attributeAdmin
Original file line number Diff line number Diff line change
@@ -1,5 +1,5 @@
{
"description": "API hub attribute admin",
"description": "Full access to all Cloud API hub attribute's resources.",
"etag": "AA==",
"includedPermissions": [
"apihub.attributes.create",
Expand All @@ -12,5 +12,5 @@
],
"name": "roles/apihub.attributeAdmin",
"stage": "BETA",
"title": "API hub attribute admin"
"title": "Cloud API hub Attributes Admin"
}
5 changes: 3 additions & 2 deletions roles/apihub.editor
Original file line number Diff line number Diff line change
@@ -1,5 +1,5 @@
{
"description": "Edit access to Cloud API Hub Registry resources.",
"description": "Edit access to most of Cloud API Hub resources.",
"etag": "AA==",
"includedPermissions": [
"apihub.apiHubInstances.get",
Expand Down Expand Up @@ -39,6 +39,8 @@
"apihub.llmEnablements.list",
"apihub.llmEnablements.register",
"apihub.locations.searchResources",
"apihub.operations.get",
"apihub.operations.list",
"apihub.plugins.get",
"apihub.plugins.list",
"apihub.runTimeProjectAttachments.get",
Expand All @@ -50,7 +52,6 @@
"apihub.specs.list",
"apihub.specs.update",
"apihub.styleGuides.get",
"apihub.styleGuides.update",
"apihub.versions.create",
"apihub.versions.delete",
"apihub.versions.get",
Expand Down
4 changes: 2 additions & 2 deletions roles/apihub.pluginAdmin
Original file line number Diff line number Diff line change
@@ -1,5 +1,5 @@
{
"description": "API hub plugin admin",
"description": "Full access to all Cloud API hub plugin's resources.",
"etag": "AA==",
"includedPermissions": [
"apihub.plugins.disable",
Expand All @@ -14,5 +14,5 @@
],
"name": "roles/apihub.pluginAdmin",
"stage": "BETA",
"title": "API hub plugin admin"
"title": "Cloud API hub Plugins Admin"
}
8 changes: 6 additions & 2 deletions roles/apihub.provisioningAdmin
Original file line number Diff line number Diff line change
@@ -1,5 +1,5 @@
{
"description": "API hub all permissions related to provisioning",
"description": "Full access to Cloud API hub provisioning related resources.",
"etag": "AA==",
"includedPermissions": [
"apihub.apiHubInstances.create",
Expand All @@ -11,6 +11,10 @@
"apihub.hostProjectRegistrations.get",
"apihub.hostProjectRegistrations.list",
"apihub.hostProjectRegistrations.register",
"apihub.operations.cancel",
"apihub.operations.delete",
"apihub.operations.get",
"apihub.operations.list",
"apihub.runTimeProjectAttachments.attach",
"apihub.runTimeProjectAttachments.create",
"apihub.runTimeProjectAttachments.delete",
Expand All @@ -22,5 +26,5 @@
],
"name": "roles/apihub.provisioningAdmin",
"stage": "BETA",
"title": "API hub all permissions related to provisioning"
"title": "Cloud API hub Provisioning Admin"
}
4 changes: 3 additions & 1 deletion roles/apihub.runtimeProjectServiceAgent
Original file line number Diff line number Diff line change
Expand Up @@ -5,9 +5,11 @@
"apigee.deployments.list",
"apigee.envgroupattachments.list",
"apigee.envgroups.list",
"apigee.environments.get",
"apigee.organizations.get",
"apigee.proxyrevisions.get"
],
"name": "roles/apihub.runtimeProjectServiceAgent",
"stage": "ALPHA",
"stage": "GA",
"title": "API-Hub Runtime Project Service Agent"
}
6 changes: 4 additions & 2 deletions roles/apihub.viewer
Original file line number Diff line number Diff line change
@@ -1,5 +1,5 @@
{
"description": "This role can view all resources in API hub",
"description": "View access to all Cloud API hub resources.",
"etag": "AA==",
"includedPermissions": [
"apihub.apiHubInstances.get",
Expand All @@ -23,6 +23,8 @@
"apihub.llmEnablements.get",
"apihub.llmEnablements.list",
"apihub.locations.searchResources",
"apihub.operations.get",
"apihub.operations.list",
"apihub.plugins.get",
"apihub.plugins.list",
"apihub.runTimeProjectAttachments.get",
Expand All @@ -37,5 +39,5 @@
],
"name": "roles/apihub.viewer",
"stage": "BETA",
"title": "API hub all resource viewer"
"title": "Cloud API hub Viewer"
}
2 changes: 1 addition & 1 deletion roles/apim.admin
Original file line number Diff line number Diff line change
Expand Up @@ -26,6 +26,6 @@
"resourcemanager.projects.list"
],
"name": "roles/apim.admin",
"stage": "ALPHA",
"stage": "BETA",
"title": "API Management Admin"
}
2 changes: 1 addition & 1 deletion roles/apim.viewer
Original file line number Diff line number Diff line change
Expand Up @@ -18,6 +18,6 @@
"resourcemanager.projects.list"
],
"name": "roles/apim.viewer",
"stage": "ALPHA",
"stage": "BETA",
"title": "API Management Viewer"
}
1 change: 1 addition & 0 deletions roles/auditmanager.serviceAgent
Original file line number Diff line number Diff line change
Expand Up @@ -2,6 +2,7 @@
"description": "Grants Audit Manager Service Agent access to various list/get rpcs of products to perform an audit.",
"etag": "AA==",
"includedPermissions": [
"bigquery.datasets.get",
"cloudasset.assets.analyzeIamPolicy",
"cloudasset.assets.analyzeMove",
"cloudasset.assets.analyzeOrgPolicy",
Expand Down
1 change: 1 addition & 0 deletions roles/bigquery.studioAdmin
Original file line number Diff line number Diff line change
Expand Up @@ -9,6 +9,7 @@
"aiplatform.notebookRuntimeTemplates.getIamPolicy",
"aiplatform.notebookRuntimeTemplates.list",
"aiplatform.notebookRuntimeTemplates.setIamPolicy",
"aiplatform.notebookRuntimeTemplates.update",
"aiplatform.notebookRuntimes.assign",
"aiplatform.notebookRuntimes.delete",
"aiplatform.notebookRuntimes.get",
Expand Down
1 change: 1 addition & 0 deletions roles/capacityplanner.viewer
Original file line number Diff line number Diff line change
Expand Up @@ -7,6 +7,7 @@
"capacityplanner.usageHistories.summarize",
"cloudquotas.quotas.get",
"monitoring.timeSeries.list",
"resourcemanager.folders.get",
"resourcemanager.organizations.get",
"resourcemanager.projects.get",
"resourcemanager.projects.list",
Expand Down
1 change: 1 addition & 0 deletions roles/chronicle.admin
Original file line number Diff line number Diff line change
Expand Up @@ -133,6 +133,7 @@
"chronicle.instances.generateSoarAuthJwt",
"chronicle.instances.generateWorkspaceConnectionToken",
"chronicle.instances.get",
"chronicle.instances.logTypeClassifier",
"chronicle.instances.report",
"chronicle.iocMatches.get",
"chronicle.iocMatches.list",
Expand Down
5 changes: 4 additions & 1 deletion roles/chronicle.restrictedDataAccessViewer
Original file line number Diff line number Diff line change
Expand Up @@ -6,6 +6,10 @@
"chronicle.ais.translateUdmQuery",
"chronicle.ais.translateYlRule",
"chronicle.dataAccessScopes.list",
"chronicle.dataTableRows.get",
"chronicle.dataTableRows.list",
"chronicle.dataTables.get",
"chronicle.dataTables.list",
"chronicle.entities.find",
"chronicle.entities.findRelatedEntities",
"chronicle.entities.get",
Expand All @@ -24,7 +28,6 @@
"chronicle.findingsGraphs.initializeGraph",
"chronicle.instances.generateCollectionAgentAuth",
"chronicle.instances.generateSoarAuthJwt",
"chronicle.instances.generateWorkspaceConnectionToken",
"chronicle.instances.get",
"chronicle.instances.report",
"chronicle.legacies.legacyBatchGetCases",
Expand Down
3 changes: 3 additions & 0 deletions roles/cloudbuild.serviceAgent
Original file line number Diff line number Diff line change
Expand Up @@ -56,7 +56,10 @@
"cloudbuild.workerpools.use",
"compute.firewalls.get",
"compute.firewalls.list",
"compute.networkAttachments.get",
"compute.networkAttachments.update",
"compute.networks.get",
"compute.regionOperations.get",
"compute.subnetworks.get",
"containeranalysis.notes.attachOccurrence",
"containeranalysis.notes.create",
Expand Down
2 changes: 1 addition & 1 deletion roles/clouddeploy.customTargetTypeAdmin
Original file line number Diff line number Diff line change
Expand Up @@ -14,6 +14,6 @@
"resourcemanager.projects.list"
],
"name": "roles/clouddeploy.customTargetTypeAdmin",
"stage": "BETA",
"stage": "GA",
"title": "Cloud Deploy Custom Target Type Admin"
}
2 changes: 1 addition & 1 deletion roles/cloudkms.autokeyAdmin
Original file line number Diff line number Diff line change
Expand Up @@ -7,6 +7,6 @@
"cloudkms.projects.showEffectiveAutokeyConfig"
],
"name": "roles/cloudkms.autokeyAdmin",
"stage": "ALPHA",
"stage": "BETA",
"title": "Cloud KMS Autokey Admin"
}
1 change: 1 addition & 0 deletions roles/compute.instanceAdmin
Original file line number Diff line number Diff line change
Expand Up @@ -181,6 +181,7 @@
"compute.regions.list",
"compute.reservations.get",
"compute.reservations.list",
"compute.resourcePolicies.list",
"compute.resourcePolicies.useReadOnly",
"compute.storagePools.get",
"compute.storagePools.list",
Expand Down
Loading

0 comments on commit d0de827

Please sign in to comment.