Skip to content

Commit

Permalink
GCP IAM Updates Detected
Browse files Browse the repository at this point in the history
  • Loading branch information
jdyke committed Sep 28, 2024
1 parent 92a260e commit ea95a9a
Show file tree
Hide file tree
Showing 44 changed files with 566 additions and 11 deletions.
5 changes: 5 additions & 0 deletions roles/apigee.securityAdmin
Original file line number Diff line number Diff line change
Expand Up @@ -38,6 +38,11 @@
"apigee.securityProfiles.get",
"apigee.securityProfiles.list",
"apigee.securityProfiles.update",
"apigee.securityProfilesV2.create",
"apigee.securityProfilesV2.delete",
"apigee.securityProfilesV2.get",
"apigee.securityProfilesV2.list",
"apigee.securityProfilesV2.update",
"apigee.securitySettings.get",
"apigee.securitySettings.update",
"apigee.securityStats.queryTabularStats",
Expand Down
5 changes: 5 additions & 0 deletions roles/artifactregistry.createOnPushRepoAdmin
Original file line number Diff line number Diff line change
Expand Up @@ -38,6 +38,11 @@
"artifactregistry.repositories.listTagBindings",
"artifactregistry.repositories.readViaVirtualRepository",
"artifactregistry.repositories.uploadArtifacts",
"artifactregistry.rules.create",
"artifactregistry.rules.delete",
"artifactregistry.rules.get",
"artifactregistry.rules.list",
"artifactregistry.rules.update",
"artifactregistry.tags.create",
"artifactregistry.tags.delete",
"artifactregistry.tags.get",
Expand Down
2 changes: 2 additions & 0 deletions roles/artifactregistry.createOnPushWriter
Original file line number Diff line number Diff line change
Expand Up @@ -34,6 +34,8 @@
"artifactregistry.repositories.listTagBindings",
"artifactregistry.repositories.readViaVirtualRepository",
"artifactregistry.repositories.uploadArtifacts",
"artifactregistry.rules.get",
"artifactregistry.rules.list",
"artifactregistry.tags.create",
"artifactregistry.tags.get",
"artifactregistry.tags.list",
Expand Down
2 changes: 2 additions & 0 deletions roles/artifactregistry.writer
Original file line number Diff line number Diff line change
Expand Up @@ -33,6 +33,8 @@
"artifactregistry.repositories.listTagBindings",
"artifactregistry.repositories.readViaVirtualRepository",
"artifactregistry.repositories.uploadArtifacts",
"artifactregistry.rules.get",
"artifactregistry.rules.list",
"artifactregistry.tags.create",
"artifactregistry.tags.get",
"artifactregistry.tags.list",
Expand Down
2 changes: 2 additions & 0 deletions roles/assuredoss.admin
Original file line number Diff line number Diff line change
Expand Up @@ -27,6 +27,8 @@
"artifactregistry.repositories.listEffectiveTags",
"artifactregistry.repositories.listTagBindings",
"artifactregistry.repositories.readViaVirtualRepository",
"artifactregistry.rules.get",
"artifactregistry.rules.list",
"artifactregistry.tags.get",
"artifactregistry.tags.list",
"artifactregistry.versions.get",
Expand Down
2 changes: 2 additions & 0 deletions roles/assuredoss.projectAdmin
Original file line number Diff line number Diff line change
Expand Up @@ -27,6 +27,8 @@
"artifactregistry.repositories.listEffectiveTags",
"artifactregistry.repositories.listTagBindings",
"artifactregistry.repositories.readViaVirtualRepository",
"artifactregistry.rules.get",
"artifactregistry.rules.list",
"artifactregistry.tags.get",
"artifactregistry.tags.list",
"artifactregistry.versions.get",
Expand Down
2 changes: 2 additions & 0 deletions roles/assuredoss.user
Original file line number Diff line number Diff line change
Expand Up @@ -26,6 +26,8 @@
"artifactregistry.repositories.listEffectiveTags",
"artifactregistry.repositories.listTagBindings",
"artifactregistry.repositories.readViaVirtualRepository",
"artifactregistry.rules.get",
"artifactregistry.rules.list",
"artifactregistry.tags.get",
"artifactregistry.tags.list",
"artifactregistry.versions.get",
Expand Down
2 changes: 2 additions & 0 deletions roles/cloudbuild.serviceAgent
Original file line number Diff line number Diff line change
Expand Up @@ -35,6 +35,8 @@
"artifactregistry.repositories.listTagBindings",
"artifactregistry.repositories.readViaVirtualRepository",
"artifactregistry.repositories.uploadArtifacts",
"artifactregistry.rules.get",
"artifactregistry.rules.list",
"artifactregistry.tags.create",
"artifactregistry.tags.get",
"artifactregistry.tags.list",
Expand Down
19 changes: 18 additions & 1 deletion roles/cloudtpu.serviceAgent
Original file line number Diff line number Diff line change
Expand Up @@ -6,10 +6,14 @@
"compute.acceleratorTypes.list",
"compute.addresses.create",
"compute.addresses.createInternal",
"compute.addresses.createTagBinding",
"compute.addresses.delete",
"compute.addresses.deleteInternal",
"compute.addresses.deleteTagBinding",
"compute.addresses.get",
"compute.addresses.list",
"compute.addresses.listEffectiveTags",
"compute.addresses.listTagBindings",
"compute.addresses.setLabels",
"compute.addresses.use",
"compute.addresses.useInternal",
Expand Down Expand Up @@ -112,10 +116,14 @@
"compute.forwardingRules.use",
"compute.globalAddresses.create",
"compute.globalAddresses.createInternal",
"compute.globalAddresses.createTagBinding",
"compute.globalAddresses.delete",
"compute.globalAddresses.deleteInternal",
"compute.globalAddresses.deleteTagBinding",
"compute.globalAddresses.get",
"compute.globalAddresses.list",
"compute.globalAddresses.listEffectiveTags",
"compute.globalAddresses.listTagBindings",
"compute.globalAddresses.setLabels",
"compute.globalAddresses.use",
"compute.globalForwardingRules.create",
Expand Down Expand Up @@ -151,7 +159,6 @@
"compute.globalPublicDelegatedPrefixes.delete",
"compute.globalPublicDelegatedPrefixes.get",
"compute.globalPublicDelegatedPrefixes.list",
"compute.globalPublicDelegatedPrefixes.update",
"compute.globalPublicDelegatedPrefixes.updatePolicy",
"compute.healthChecks.create",
"compute.healthChecks.createTagBinding",
Expand Down Expand Up @@ -345,10 +352,14 @@
"compute.machineTypes.get",
"compute.machineTypes.list",
"compute.networkAttachments.create",
"compute.networkAttachments.createTagBinding",
"compute.networkAttachments.delete",
"compute.networkAttachments.deleteTagBinding",
"compute.networkAttachments.get",
"compute.networkAttachments.getIamPolicy",
"compute.networkAttachments.list",
"compute.networkAttachments.listEffectiveTags",
"compute.networkAttachments.listTagBindings",
"compute.networkAttachments.setIamPolicy",
"compute.networkAttachments.update",
"compute.networkEndpointGroups.attachNetworkEndpoints",
Expand Down Expand Up @@ -395,6 +406,8 @@
"compute.publicDelegatedPrefixes.delete",
"compute.publicDelegatedPrefixes.get",
"compute.publicDelegatedPrefixes.list",
"compute.publicDelegatedPrefixes.listEffectiveTags",
"compute.publicDelegatedPrefixes.listTagBindings",
"compute.publicDelegatedPrefixes.update",
"compute.publicDelegatedPrefixes.updatePolicy",
"compute.regionBackendServices.create",
Expand Down Expand Up @@ -557,10 +570,14 @@
"compute.securityPolicies.listTagBindings",
"compute.securityPolicies.use",
"compute.serviceAttachments.create",
"compute.serviceAttachments.createTagBinding",
"compute.serviceAttachments.delete",
"compute.serviceAttachments.deleteTagBinding",
"compute.serviceAttachments.get",
"compute.serviceAttachments.getIamPolicy",
"compute.serviceAttachments.list",
"compute.serviceAttachments.listEffectiveTags",
"compute.serviceAttachments.listTagBindings",
"compute.serviceAttachments.setIamPolicy",
"compute.serviceAttachments.update",
"compute.serviceAttachments.use",
Expand Down
27 changes: 26 additions & 1 deletion roles/composer.serviceAgent
Original file line number Diff line number Diff line change
Expand Up @@ -92,10 +92,14 @@
"compute.acceleratorTypes.list",
"compute.addresses.create",
"compute.addresses.createInternal",
"compute.addresses.createTagBinding",
"compute.addresses.delete",
"compute.addresses.deleteInternal",
"compute.addresses.deleteTagBinding",
"compute.addresses.get",
"compute.addresses.list",
"compute.addresses.listEffectiveTags",
"compute.addresses.listTagBindings",
"compute.addresses.setLabels",
"compute.addresses.use",
"compute.addresses.useInternal",
Expand Down Expand Up @@ -195,10 +199,14 @@
"compute.forwardingRules.use",
"compute.globalAddresses.create",
"compute.globalAddresses.createInternal",
"compute.globalAddresses.createTagBinding",
"compute.globalAddresses.delete",
"compute.globalAddresses.deleteInternal",
"compute.globalAddresses.deleteTagBinding",
"compute.globalAddresses.get",
"compute.globalAddresses.list",
"compute.globalAddresses.listEffectiveTags",
"compute.globalAddresses.listTagBindings",
"compute.globalAddresses.setLabels",
"compute.globalAddresses.use",
"compute.globalForwardingRules.create",
Expand Down Expand Up @@ -234,7 +242,6 @@
"compute.globalPublicDelegatedPrefixes.delete",
"compute.globalPublicDelegatedPrefixes.get",
"compute.globalPublicDelegatedPrefixes.list",
"compute.globalPublicDelegatedPrefixes.update",
"compute.globalPublicDelegatedPrefixes.updatePolicy",
"compute.healthChecks.create",
"compute.healthChecks.createTagBinding",
Expand Down Expand Up @@ -428,10 +435,14 @@
"compute.machineTypes.get",
"compute.machineTypes.list",
"compute.networkAttachments.create",
"compute.networkAttachments.createTagBinding",
"compute.networkAttachments.delete",
"compute.networkAttachments.deleteTagBinding",
"compute.networkAttachments.get",
"compute.networkAttachments.getIamPolicy",
"compute.networkAttachments.list",
"compute.networkAttachments.listEffectiveTags",
"compute.networkAttachments.listTagBindings",
"compute.networkAttachments.setIamPolicy",
"compute.networkAttachments.update",
"compute.networkEndpointGroups.attachNetworkEndpoints",
Expand Down Expand Up @@ -478,6 +489,8 @@
"compute.publicDelegatedPrefixes.delete",
"compute.publicDelegatedPrefixes.get",
"compute.publicDelegatedPrefixes.list",
"compute.publicDelegatedPrefixes.listEffectiveTags",
"compute.publicDelegatedPrefixes.listTagBindings",
"compute.publicDelegatedPrefixes.update",
"compute.publicDelegatedPrefixes.updatePolicy",
"compute.regionBackendServices.create",
Expand Down Expand Up @@ -640,10 +653,14 @@
"compute.securityPolicies.listTagBindings",
"compute.securityPolicies.use",
"compute.serviceAttachments.create",
"compute.serviceAttachments.createTagBinding",
"compute.serviceAttachments.delete",
"compute.serviceAttachments.deleteTagBinding",
"compute.serviceAttachments.get",
"compute.serviceAttachments.getIamPolicy",
"compute.serviceAttachments.list",
"compute.serviceAttachments.listEffectiveTags",
"compute.serviceAttachments.listTagBindings",
"compute.serviceAttachments.setIamPolicy",
"compute.serviceAttachments.update",
"compute.serviceAttachments.use",
Expand Down Expand Up @@ -1677,6 +1694,12 @@
"recommender.networkAnalyzerGkeIpAddressInsights.get",
"recommender.networkAnalyzerGkeIpAddressInsights.list",
"recommender.networkAnalyzerGkeIpAddressInsights.update",
"recommender.storageBucketSoftDeleteInsights.get",
"recommender.storageBucketSoftDeleteInsights.list",
"recommender.storageBucketSoftDeleteInsights.update",
"recommender.storageBucketSoftDeleteRecommendations.get",
"recommender.storageBucketSoftDeleteRecommendations.list",
"recommender.storageBucketSoftDeleteRecommendations.update",
"resourcemanager.hierarchyNodes.listEffectiveTags",
"resourcemanager.projects.get",
"resourcemanager.projects.getIamPolicy",
Expand Down Expand Up @@ -1729,6 +1752,8 @@
"storage.managedFolders.getIamPolicy",
"storage.managedFolders.list",
"storage.managedFolders.setIamPolicy",
"storage.managementHubs.get",
"storage.managementHubs.update",
"storage.multipartUploads.abort",
"storage.multipartUploads.create",
"storage.multipartUploads.list",
Expand Down
24 changes: 20 additions & 4 deletions roles/compute.admin
Original file line number Diff line number Diff line change
Expand Up @@ -6,10 +6,14 @@
"compute.acceleratorTypes.list",
"compute.addresses.create",
"compute.addresses.createInternal",
"compute.addresses.createTagBinding",
"compute.addresses.delete",
"compute.addresses.deleteInternal",
"compute.addresses.deleteTagBinding",
"compute.addresses.get",
"compute.addresses.list",
"compute.addresses.listEffectiveTags",
"compute.addresses.listTagBindings",
"compute.addresses.setLabels",
"compute.addresses.use",
"compute.addresses.useInternal",
Expand Down Expand Up @@ -137,10 +141,14 @@
"compute.futureReservations.update",
"compute.globalAddresses.create",
"compute.globalAddresses.createInternal",
"compute.globalAddresses.createTagBinding",
"compute.globalAddresses.delete",
"compute.globalAddresses.deleteInternal",
"compute.globalAddresses.deleteTagBinding",
"compute.globalAddresses.get",
"compute.globalAddresses.list",
"compute.globalAddresses.listEffectiveTags",
"compute.globalAddresses.listTagBindings",
"compute.globalAddresses.setLabels",
"compute.globalAddresses.use",
"compute.globalForwardingRules.create",
Expand Down Expand Up @@ -180,9 +188,7 @@
"compute.globalPublicDelegatedPrefixes.delete",
"compute.globalPublicDelegatedPrefixes.get",
"compute.globalPublicDelegatedPrefixes.list",
"compute.globalPublicDelegatedPrefixes.update",
"compute.globalPublicDelegatedPrefixes.updatePolicy",
"compute.globalPublicDelegatedPrefixes.use",
"compute.healthChecks.create",
"compute.healthChecks.createTagBinding",
"compute.healthChecks.delete",
Expand Down Expand Up @@ -382,10 +388,14 @@
"compute.maintenancePolicies.setIamPolicy",
"compute.maintenancePolicies.use",
"compute.networkAttachments.create",
"compute.networkAttachments.createTagBinding",
"compute.networkAttachments.delete",
"compute.networkAttachments.deleteTagBinding",
"compute.networkAttachments.get",
"compute.networkAttachments.getIamPolicy",
"compute.networkAttachments.list",
"compute.networkAttachments.listEffectiveTags",
"compute.networkAttachments.listTagBindings",
"compute.networkAttachments.setIamPolicy",
"compute.networkAttachments.update",
"compute.networkEdgeSecurityServices.create",
Expand Down Expand Up @@ -448,7 +458,6 @@
"compute.nodeTemplates.setIamPolicy",
"compute.nodeTypes.get",
"compute.nodeTypes.list",
"compute.organizations.administerXpn",
"compute.organizations.disableXpnHost",
"compute.organizations.disableXpnResource",
"compute.organizations.enableXpnHost",
Expand Down Expand Up @@ -479,11 +488,14 @@
"compute.publicAdvertisedPrefixes.list",
"compute.publicAdvertisedPrefixes.update",
"compute.publicAdvertisedPrefixes.updatePolicy",
"compute.publicAdvertisedPrefixes.use",
"compute.publicDelegatedPrefixes.create",
"compute.publicDelegatedPrefixes.createTagBinding",
"compute.publicDelegatedPrefixes.delete",
"compute.publicDelegatedPrefixes.deleteTagBinding",
"compute.publicDelegatedPrefixes.get",
"compute.publicDelegatedPrefixes.list",
"compute.publicDelegatedPrefixes.listEffectiveTags",
"compute.publicDelegatedPrefixes.listTagBindings",
"compute.publicDelegatedPrefixes.update",
"compute.publicDelegatedPrefixes.updatePolicy",
"compute.publicDelegatedPrefixes.use",
Expand Down Expand Up @@ -683,10 +695,14 @@
"compute.securityPolicies.update",
"compute.securityPolicies.use",
"compute.serviceAttachments.create",
"compute.serviceAttachments.createTagBinding",
"compute.serviceAttachments.delete",
"compute.serviceAttachments.deleteTagBinding",
"compute.serviceAttachments.get",
"compute.serviceAttachments.getIamPolicy",
"compute.serviceAttachments.list",
"compute.serviceAttachments.listEffectiveTags",
"compute.serviceAttachments.listTagBindings",
"compute.serviceAttachments.setIamPolicy",
"compute.serviceAttachments.update",
"compute.serviceAttachments.use",
Expand Down
8 changes: 8 additions & 0 deletions roles/compute.networkViewer
Original file line number Diff line number Diff line change
Expand Up @@ -6,6 +6,8 @@
"compute.acceleratorTypes.list",
"compute.addresses.get",
"compute.addresses.list",
"compute.addresses.listEffectiveTags",
"compute.addresses.listTagBindings",
"compute.autoscalers.get",
"compute.autoscalers.list",
"compute.backendBuckets.get",
Expand All @@ -32,6 +34,8 @@
"compute.forwardingRules.listTagBindings",
"compute.globalAddresses.get",
"compute.globalAddresses.list",
"compute.globalAddresses.listEffectiveTags",
"compute.globalAddresses.listTagBindings",
"compute.globalForwardingRules.get",
"compute.globalForwardingRules.list",
"compute.globalForwardingRules.listEffectiveTags",
Expand Down Expand Up @@ -84,6 +88,8 @@
"compute.machineTypes.list",
"compute.networkAttachments.get",
"compute.networkAttachments.list",
"compute.networkAttachments.listEffectiveTags",
"compute.networkAttachments.listTagBindings",
"compute.networks.get",
"compute.networks.getEffectiveFirewalls",
"compute.networks.getRegionEffectiveFirewalls",
Expand Down Expand Up @@ -148,6 +154,8 @@
"compute.routes.listTagBindings",
"compute.serviceAttachments.get",
"compute.serviceAttachments.list",
"compute.serviceAttachments.listEffectiveTags",
"compute.serviceAttachments.listTagBindings",
"compute.snapshots.listEffectiveTags",
"compute.snapshots.listTagBindings",
"compute.sslCertificates.get",
Expand Down
1 change: 1 addition & 0 deletions roles/connectors.viewer
Original file line number Diff line number Diff line change
Expand Up @@ -2,6 +2,7 @@
"description": "Read-only access to Connectors all resources.",
"etag": "AA==",
"includedPermissions": [
"connectors.connections.generateOpenAPISpec",
"connectors.connections.get",
"connectors.connections.getConnectionSchemaMetadata",
"connectors.connections.getIamPolicy",
Expand Down
Loading

0 comments on commit ea95a9a

Please sign in to comment.