Skip to content

Commit

Permalink
GCP IAM Updates Detected
Browse files Browse the repository at this point in the history
  • Loading branch information
jdyke committed Oct 4, 2024
1 parent 2480efe commit 2da0dd2
Show file tree
Hide file tree
Showing 73 changed files with 615 additions and 72 deletions.
5 changes: 5 additions & 0 deletions roles/aiplatform.admin
Original file line number Diff line number Diff line change
Expand Up @@ -39,6 +39,11 @@
"aiplatform.batchPredictionJobs.list",
"aiplatform.cacheConfigs.get",
"aiplatform.cacheConfigs.update",
"aiplatform.cachedContents.create",
"aiplatform.cachedContents.delete",
"aiplatform.cachedContents.get",
"aiplatform.cachedContents.list",
"aiplatform.cachedContents.update",
"aiplatform.consents.get",
"aiplatform.consents.update",
"aiplatform.contexts.addContextArtifactsAndExecutions",
Expand Down
5 changes: 5 additions & 0 deletions roles/aiplatform.customCodeServiceAgent
Original file line number Diff line number Diff line change
Expand Up @@ -38,6 +38,11 @@
"aiplatform.batchPredictionJobs.get",
"aiplatform.batchPredictionJobs.list",
"aiplatform.cacheConfigs.get",
"aiplatform.cachedContents.create",
"aiplatform.cachedContents.delete",
"aiplatform.cachedContents.get",
"aiplatform.cachedContents.list",
"aiplatform.cachedContents.update",
"aiplatform.consents.get",
"aiplatform.contexts.addContextArtifactsAndExecutions",
"aiplatform.contexts.addContextChildren",
Expand Down
5 changes: 5 additions & 0 deletions roles/aiplatform.extensionCustomCodeServiceAgent
Original file line number Diff line number Diff line change
Expand Up @@ -7,6 +7,11 @@
"orgpolicy.policy.get",
"resourcemanager.projects.get",
"resourcemanager.projects.list",
"storage.folders.create",
"storage.folders.delete",
"storage.folders.get",
"storage.folders.list",
"storage.folders.rename",
"storage.managedFolders.create",
"storage.managedFolders.delete",
"storage.managedFolders.get",
Expand Down
5 changes: 5 additions & 0 deletions roles/aiplatform.user
Original file line number Diff line number Diff line change
Expand Up @@ -38,6 +38,11 @@
"aiplatform.batchPredictionJobs.get",
"aiplatform.batchPredictionJobs.list",
"aiplatform.cacheConfigs.get",
"aiplatform.cachedContents.create",
"aiplatform.cachedContents.delete",
"aiplatform.cachedContents.get",
"aiplatform.cachedContents.list",
"aiplatform.cachedContents.update",
"aiplatform.consents.get",
"aiplatform.contexts.addContextArtifactsAndExecutions",
"aiplatform.contexts.addContextChildren",
Expand Down
5 changes: 5 additions & 0 deletions roles/billing.admin
Original file line number Diff line number Diff line change
Expand Up @@ -72,6 +72,11 @@
"consumerprocurement.consents.revoke",
"consumerprocurement.events.get",
"consumerprocurement.events.list",
"consumerprocurement.licensePools.assign",
"consumerprocurement.licensePools.enumerateLicensedUsers",
"consumerprocurement.licensePools.get",
"consumerprocurement.licensePools.unassign",
"consumerprocurement.licensePools.update",
"consumerprocurement.orderAttributions.get",
"consumerprocurement.orderAttributions.list",
"consumerprocurement.orderAttributions.update",
Expand Down
1 change: 1 addition & 0 deletions roles/cloudbuild.serviceAgent
Original file line number Diff line number Diff line change
Expand Up @@ -80,6 +80,7 @@
"containeranalysis.occurrences.get",
"containeranalysis.occurrences.list",
"containeranalysis.occurrences.update",
"developerconnect.connections.get",
"iam.serviceAccounts.get",
"iam.serviceAccounts.getAccessToken",
"iam.serviceAccounts.getOpenIdToken",
Expand Down
2 changes: 1 addition & 1 deletion roles/cloudjobdiscovery.jobsEditor
Original file line number Diff line number Diff line change
Expand Up @@ -22,5 +22,5 @@
],
"name": "roles/cloudjobdiscovery.jobsEditor",
"stage": "GA",
"title": "Job Editor"
"title": "Cloud Talent Solution Job Editor"
}
2 changes: 1 addition & 1 deletion roles/cloudjobdiscovery.jobsViewer
Original file line number Diff line number Diff line change
Expand Up @@ -12,5 +12,5 @@
],
"name": "roles/cloudjobdiscovery.jobsViewer",
"stage": "GA",
"title": "Job Viewer"
"title": "Cloud Talent Solution Job Viewer"
}
2 changes: 1 addition & 1 deletion roles/cloudjobdiscovery.profilesEditor
Original file line number Diff line number Diff line change
Expand Up @@ -17,5 +17,5 @@
],
"name": "roles/cloudjobdiscovery.profilesEditor",
"stage": "GA",
"title": "Profile Editor"
"title": "Cloud Talent Solution Profile Editor"
}
2 changes: 1 addition & 1 deletion roles/cloudjobdiscovery.profilesViewer
Original file line number Diff line number Diff line change
Expand Up @@ -10,5 +10,5 @@
],
"name": "roles/cloudjobdiscovery.profilesViewer",
"stage": "GA",
"title": "Profile Viewer"
"title": "Cloud Talent Solution Profile Viewer"
}
7 changes: 7 additions & 0 deletions roles/cloudsql.admin
Original file line number Diff line number Diff line change
Expand Up @@ -7,6 +7,11 @@
"cloudsql.backupRuns.delete",
"cloudsql.backupRuns.get",
"cloudsql.backupRuns.list",
"cloudsql.backups.create",
"cloudsql.backups.delete",
"cloudsql.backups.get",
"cloudsql.backups.list",
"cloudsql.backups.update",
"cloudsql.databases.create",
"cloudsql.databases.delete",
"cloudsql.databases.get",
Expand Down Expand Up @@ -47,6 +52,8 @@
"cloudsql.instances.stopReplica",
"cloudsql.instances.truncateLog",
"cloudsql.instances.update",
"cloudsql.operations.get",
"cloudsql.operations.list",
"cloudsql.schemas.view",
"cloudsql.sslCerts.create",
"cloudsql.sslCerts.delete",
Expand Down
6 changes: 6 additions & 0 deletions roles/cloudsql.editor
Original file line number Diff line number Diff line change
Expand Up @@ -6,6 +6,10 @@
"cloudsql.backupRuns.create",
"cloudsql.backupRuns.get",
"cloudsql.backupRuns.list",
"cloudsql.backups.create",
"cloudsql.backups.get",
"cloudsql.backups.list",
"cloudsql.backups.update",
"cloudsql.databases.create",
"cloudsql.databases.get",
"cloudsql.databases.list",
Expand All @@ -31,6 +35,8 @@
"cloudsql.instances.rotateServerCertificate",
"cloudsql.instances.truncateLog",
"cloudsql.instances.update",
"cloudsql.operations.get",
"cloudsql.operations.list",
"cloudsql.schemas.view",
"cloudsql.sslCerts.get",
"cloudsql.sslCerts.list",
Expand Down
4 changes: 4 additions & 0 deletions roles/cloudsql.viewer
Original file line number Diff line number Diff line change
Expand Up @@ -5,6 +5,8 @@
"cloudaicompanion.entitlements.get",
"cloudsql.backupRuns.get",
"cloudsql.backupRuns.list",
"cloudsql.backups.get",
"cloudsql.backups.list",
"cloudsql.databases.get",
"cloudsql.databases.list",
"cloudsql.instances.export",
Expand All @@ -15,6 +17,8 @@
"cloudsql.instances.listServerCas",
"cloudsql.instances.listServerCertificates",
"cloudsql.instances.listTagBindings",
"cloudsql.operations.get",
"cloudsql.operations.list",
"cloudsql.sslCerts.get",
"cloudsql.sslCerts.list",
"cloudsql.users.get",
Expand Down
1 change: 0 additions & 1 deletion roles/cloudtpu.serviceAgent
Original file line number Diff line number Diff line change
Expand Up @@ -493,7 +493,6 @@
"compute.regionTargetHttpProxies.listEffectiveTags",
"compute.regionTargetHttpProxies.listTagBindings",
"compute.regionTargetHttpProxies.setUrlMap",
"compute.regionTargetHttpProxies.update",
"compute.regionTargetHttpProxies.use",
"compute.regionTargetHttpsProxies.create",
"compute.regionTargetHttpsProxies.createTagBinding",
Expand Down
5 changes: 5 additions & 0 deletions roles/cloudtrace.admin
Original file line number Diff line number Diff line change
Expand Up @@ -9,6 +9,11 @@
"cloudtrace.tasks.delete",
"cloudtrace.tasks.get",
"cloudtrace.tasks.list",
"cloudtrace.traceScopes.create",
"cloudtrace.traceScopes.delete",
"cloudtrace.traceScopes.get",
"cloudtrace.traceScopes.list",
"cloudtrace.traceScopes.update",
"cloudtrace.traces.get",
"cloudtrace.traces.list",
"cloudtrace.traces.patch",
Expand Down
5 changes: 5 additions & 0 deletions roles/cloudtrace.user
Original file line number Diff line number Diff line change
Expand Up @@ -9,6 +9,11 @@
"cloudtrace.tasks.delete",
"cloudtrace.tasks.get",
"cloudtrace.tasks.list",
"cloudtrace.traceScopes.create",
"cloudtrace.traceScopes.delete",
"cloudtrace.traceScopes.get",
"cloudtrace.traceScopes.list",
"cloudtrace.traceScopes.update",
"cloudtrace.traces.get",
"cloudtrace.traces.list",
"observability.scopes.get",
Expand Down
5 changes: 5 additions & 0 deletions roles/composer.environmentAndStorageObjectAdmin
Original file line number Diff line number Diff line change
Expand Up @@ -32,6 +32,11 @@
"serviceusage.quotas.get",
"serviceusage.services.get",
"serviceusage.services.list",
"storage.folders.create",
"storage.folders.delete",
"storage.folders.get",
"storage.folders.list",
"storage.folders.rename",
"storage.managedFolders.create",
"storage.managedFolders.delete",
"storage.managedFolders.get",
Expand Down
2 changes: 2 additions & 0 deletions roles/composer.environmentAndStorageObjectUser
Original file line number Diff line number Diff line change
Expand Up @@ -20,6 +20,8 @@
"serviceusage.quotas.get",
"serviceusage.services.get",
"serviceusage.services.list",
"storage.folders.get",
"storage.folders.list",
"storage.managedFolders.get",
"storage.managedFolders.list",
"storage.objects.get",
Expand Down
2 changes: 2 additions & 0 deletions roles/composer.environmentAndStorageObjectViewer
Original file line number Diff line number Diff line change
Expand Up @@ -20,6 +20,8 @@
"serviceusage.quotas.get",
"serviceusage.services.get",
"serviceusage.services.list",
"storage.folders.get",
"storage.folders.list",
"storage.managedFolders.get",
"storage.managedFolders.list",
"storage.objects.get",
Expand Down
17 changes: 16 additions & 1 deletion roles/composer.serviceAgent
Original file line number Diff line number Diff line change
Expand Up @@ -36,6 +36,11 @@
"cloudsql.backupRuns.delete",
"cloudsql.backupRuns.get",
"cloudsql.backupRuns.list",
"cloudsql.backups.create",
"cloudsql.backups.delete",
"cloudsql.backups.get",
"cloudsql.backups.list",
"cloudsql.backups.update",
"cloudsql.databases.create",
"cloudsql.databases.delete",
"cloudsql.databases.get",
Expand Down Expand Up @@ -76,6 +81,8 @@
"cloudsql.instances.stopReplica",
"cloudsql.instances.truncateLog",
"cloudsql.instances.update",
"cloudsql.operations.get",
"cloudsql.operations.list",
"cloudsql.schemas.view",
"cloudsql.sslCerts.create",
"cloudsql.sslCerts.delete",
Expand Down Expand Up @@ -576,7 +583,6 @@
"compute.regionTargetHttpProxies.listEffectiveTags",
"compute.regionTargetHttpProxies.listTagBindings",
"compute.regionTargetHttpProxies.setUrlMap",
"compute.regionTargetHttpProxies.update",
"compute.regionTargetHttpProxies.use",
"compute.regionTargetHttpsProxies.create",
"compute.regionTargetHttpsProxies.createTagBinding",
Expand Down Expand Up @@ -1293,9 +1299,13 @@
"iam.serviceAccounts.getAccessToken",
"iam.serviceAccounts.list",
"logging.buckets.create",
"logging.buckets.createTagBinding",
"logging.buckets.delete",
"logging.buckets.deleteTagBinding",
"logging.buckets.get",
"logging.buckets.list",
"logging.buckets.listEffectiveTags",
"logging.buckets.listTagBindings",
"logging.buckets.undelete",
"logging.buckets.update",
"logging.exclusions.create",
Expand Down Expand Up @@ -1746,6 +1756,11 @@
"storage.buckets.restore",
"storage.buckets.setIamPolicy",
"storage.buckets.update",
"storage.folders.create",
"storage.folders.delete",
"storage.folders.get",
"storage.folders.list",
"storage.folders.rename",
"storage.managedFolders.create",
"storage.managedFolders.delete",
"storage.managedFolders.get",
Expand Down
5 changes: 5 additions & 0 deletions roles/composer.worker
Original file line number Diff line number Diff line change
Expand Up @@ -561,6 +561,11 @@
"storage.buckets.create",
"storage.buckets.get",
"storage.buckets.list",
"storage.folders.create",
"storage.folders.delete",
"storage.folders.get",
"storage.folders.list",
"storage.folders.rename",
"storage.managedFolders.create",
"storage.managedFolders.delete",
"storage.managedFolders.get",
Expand Down
8 changes: 0 additions & 8 deletions roles/compute.admin
Original file line number Diff line number Diff line change
Expand Up @@ -380,13 +380,6 @@
"compute.machineImages.useReadOnly",
"compute.machineTypes.get",
"compute.machineTypes.list",
"compute.maintenancePolicies.create",
"compute.maintenancePolicies.delete",
"compute.maintenancePolicies.get",
"compute.maintenancePolicies.getIamPolicy",
"compute.maintenancePolicies.list",
"compute.maintenancePolicies.setIamPolicy",
"compute.maintenancePolicies.use",
"compute.networkAttachments.create",
"compute.networkAttachments.createTagBinding",
"compute.networkAttachments.delete",
Expand Down Expand Up @@ -602,7 +595,6 @@
"compute.regionTargetHttpProxies.listEffectiveTags",
"compute.regionTargetHttpProxies.listTagBindings",
"compute.regionTargetHttpProxies.setUrlMap",
"compute.regionTargetHttpProxies.update",
"compute.regionTargetHttpProxies.use",
"compute.regionTargetHttpsProxies.create",
"compute.regionTargetHttpsProxies.createTagBinding",
Expand Down
1 change: 0 additions & 1 deletion roles/compute.loadBalancerAdmin
Original file line number Diff line number Diff line change
Expand Up @@ -261,7 +261,6 @@
"compute.regionTargetHttpProxies.listEffectiveTags",
"compute.regionTargetHttpProxies.listTagBindings",
"compute.regionTargetHttpProxies.setUrlMap",
"compute.regionTargetHttpProxies.update",
"compute.regionTargetHttpProxies.use",
"compute.regionTargetHttpsProxies.create",
"compute.regionTargetHttpsProxies.createTagBinding",
Expand Down
1 change: 0 additions & 1 deletion roles/compute.networkAdmin
Original file line number Diff line number Diff line change
Expand Up @@ -342,7 +342,6 @@
"compute.regionTargetHttpProxies.listEffectiveTags",
"compute.regionTargetHttpProxies.listTagBindings",
"compute.regionTargetHttpProxies.setUrlMap",
"compute.regionTargetHttpProxies.update",
"compute.regionTargetHttpProxies.use",
"compute.regionTargetHttpsProxies.create",
"compute.regionTargetHttpsProxies.createTagBinding",
Expand Down
3 changes: 0 additions & 3 deletions roles/compute.viewer
Original file line number Diff line number Diff line change
Expand Up @@ -135,9 +135,6 @@
"compute.machineImages.list",
"compute.machineTypes.get",
"compute.machineTypes.list",
"compute.maintenancePolicies.get",
"compute.maintenancePolicies.getIamPolicy",
"compute.maintenancePolicies.list",
"compute.networkAttachments.get",
"compute.networkAttachments.getIamPolicy",
"compute.networkAttachments.list",
Expand Down
1 change: 0 additions & 1 deletion roles/container.serviceAgent
Original file line number Diff line number Diff line change
Expand Up @@ -565,7 +565,6 @@
"compute.regionTargetHttpProxies.listEffectiveTags",
"compute.regionTargetHttpProxies.listTagBindings",
"compute.regionTargetHttpProxies.setUrlMap",
"compute.regionTargetHttpProxies.update",
"compute.regionTargetHttpProxies.use",
"compute.regionTargetHttpsProxies.create",
"compute.regionTargetHttpsProxies.createTagBinding",
Expand Down
10 changes: 9 additions & 1 deletion roles/dataflow.serviceAgent
Original file line number Diff line number Diff line change
Expand Up @@ -604,7 +604,6 @@
"compute.regionTargetHttpProxies.listEffectiveTags",
"compute.regionTargetHttpProxies.listTagBindings",
"compute.regionTargetHttpProxies.setUrlMap",
"compute.regionTargetHttpProxies.update",
"compute.regionTargetHttpProxies.use",
"compute.regionTargetHttpsProxies.create",
"compute.regionTargetHttpsProxies.createTagBinding",
Expand Down Expand Up @@ -955,9 +954,13 @@
"iam.serviceAccounts.signBlob",
"iam.serviceAccounts.signJwt",
"logging.buckets.create",
"logging.buckets.createTagBinding",
"logging.buckets.delete",
"logging.buckets.deleteTagBinding",
"logging.buckets.get",
"logging.buckets.list",
"logging.buckets.listEffectiveTags",
"logging.buckets.listTagBindings",
"logging.buckets.undelete",
"logging.buckets.update",
"logging.exclusions.create",
Expand Down Expand Up @@ -1346,6 +1349,11 @@
"storage.buckets.restore",
"storage.buckets.setIamPolicy",
"storage.buckets.update",
"storage.folders.create",
"storage.folders.delete",
"storage.folders.get",
"storage.folders.list",
"storage.folders.rename",
"storage.managedFolders.create",
"storage.managedFolders.delete",
"storage.managedFolders.get",
Expand Down
5 changes: 5 additions & 0 deletions roles/datafusion.serviceAgent
Original file line number Diff line number Diff line change
Expand Up @@ -585,6 +585,11 @@
"storage.buckets.restore",
"storage.buckets.setIamPolicy",
"storage.buckets.update",
"storage.folders.create",
"storage.folders.delete",
"storage.folders.get",
"storage.folders.list",
"storage.folders.rename",
"storage.managedFolders.create",
"storage.managedFolders.delete",
"storage.managedFolders.get",
Expand Down
1 change: 1 addition & 0 deletions roles/datamigration.serviceAgent
Original file line number Diff line number Diff line change
Expand Up @@ -33,6 +33,7 @@
"cloudsql.instances.startReplica",
"cloudsql.instances.stopReplica",
"cloudsql.instances.update",
"cloudsql.operations.get",
"compute.forwardingRules.use",
"compute.globalAddresses.create",
"compute.globalAddresses.createInternal",
Expand Down
Loading

0 comments on commit 2da0dd2

Please sign in to comment.