Skip to content

Commit

Permalink
GCP IAM Updates Detected
Browse files Browse the repository at this point in the history
  • Loading branch information
jdyke committed Aug 31, 2024
1 parent aa85b66 commit c58e7cb
Show file tree
Hide file tree
Showing 29 changed files with 273 additions and 18 deletions.
10 changes: 10 additions & 0 deletions roles/bigquerydatapolicy.rawDataReader
Original file line number Diff line number Diff line change
@@ -0,0 +1,10 @@
{
"description": "Raw read access to sub-resources associated with a data policy, for example, BigQuery columns",
"etag": "AA==",
"includedPermissions": [
"bigquery.dataPolicies.getRawData"
],
"name": "roles/bigquerydatapolicy.rawDataReader",
"stage": "BETA",
"title": "Raw Data Reader"
}
27 changes: 27 additions & 0 deletions roles/cloudaicompanion.codeRepositoryIndexesAdmin
Original file line number Diff line number Diff line change
@@ -0,0 +1,27 @@
{
"description": "Grants full access to Code Repository Indexes resources.",
"etag": "AA==",
"includedPermissions": [
"cloudaicompanion.codeRepositoryIndexes.create",
"cloudaicompanion.codeRepositoryIndexes.delete",
"cloudaicompanion.codeRepositoryIndexes.get",
"cloudaicompanion.codeRepositoryIndexes.list",
"cloudaicompanion.codeRepositoryIndexes.update",
"cloudaicompanion.operations.cancel",
"cloudaicompanion.operations.delete",
"cloudaicompanion.operations.get",
"cloudaicompanion.operations.list",
"cloudaicompanion.repositoryGroups.create",
"cloudaicompanion.repositoryGroups.delete",
"cloudaicompanion.repositoryGroups.get",
"cloudaicompanion.repositoryGroups.getIamPolicy",
"cloudaicompanion.repositoryGroups.list",
"cloudaicompanion.repositoryGroups.setIamPolicy",
"cloudaicompanion.repositoryGroups.update",
"resourcemanager.projects.get",
"resourcemanager.projects.list"
],
"name": "roles/cloudaicompanion.codeRepositoryIndexesAdmin",
"stage": "BETA",
"title": "Cloud AI Companion Code Repository Indexes Admin"
}
18 changes: 18 additions & 0 deletions roles/cloudaicompanion.codeRepositoryIndexesViewer
Original file line number Diff line number Diff line change
@@ -0,0 +1,18 @@
{
"description": "Grants readonly access to Code Repository Indexes resources.",
"etag": "AA==",
"includedPermissions": [
"cloudaicompanion.codeRepositoryIndexes.get",
"cloudaicompanion.codeRepositoryIndexes.list",
"cloudaicompanion.operations.get",
"cloudaicompanion.operations.list",
"cloudaicompanion.repositoryGroups.get",
"cloudaicompanion.repositoryGroups.getIamPolicy",
"cloudaicompanion.repositoryGroups.list",
"resourcemanager.projects.get",
"resourcemanager.projects.list"
],
"name": "roles/cloudaicompanion.codeRepositoryIndexesViewer",
"stage": "BETA",
"title": "Cloud AI Companion Code Repository Indexes Viewer"
}
13 changes: 13 additions & 0 deletions roles/cloudaicompanion.repositoryGroupsUser
Original file line number Diff line number Diff line change
@@ -0,0 +1,13 @@
{
"description": "Grants Read/Use access to the Code Repository Indexes Repository Group.",
"etag": "AA==",
"includedPermissions": [
"cloudaicompanion.codeRepositoryIndexes.get",
"cloudaicompanion.repositoryGroups.get",
"cloudaicompanion.repositoryGroups.getIamPolicy",
"cloudaicompanion.repositoryGroups.use"
],
"name": "roles/cloudaicompanion.repositoryGroupsUser",
"stage": "BETA",
"title": "Cloud AI Companion Repository Groups User"
}
5 changes: 5 additions & 0 deletions roles/cloudaicompanion.serviceAgent
Original file line number Diff line number Diff line change
Expand Up @@ -2,6 +2,11 @@
"description": "Gives Cloud AI Companion components the proper permissions to function.",
"etag": "AA==",
"includedPermissions": [
"cloudaicompanion.codeRepositoryIndexes.get",
"cloudaicompanion.codeRepositoryIndexes.list",
"cloudaicompanion.repositoryGroups.get",
"cloudaicompanion.repositoryGroups.getIamPolicy",
"cloudaicompanion.repositoryGroups.list",
"cloudbuild.connections.get",
"cloudbuild.repositories.accessReadToken",
"cloudbuild.repositories.fetchGitRefs",
Expand Down
6 changes: 6 additions & 0 deletions roles/cloudtpu.serviceAgent
Original file line number Diff line number Diff line change
Expand Up @@ -869,6 +869,12 @@
"networksecurity.urlLists.list",
"networksecurity.urlLists.update",
"networksecurity.urlLists.use",
"networkservices.authzExtensions.create",
"networkservices.authzExtensions.delete",
"networkservices.authzExtensions.get",
"networkservices.authzExtensions.list",
"networkservices.authzExtensions.update",
"networkservices.authzExtensions.use",
"networkservices.endpointConfigSelectors.create",
"networkservices.endpointConfigSelectors.delete",
"networkservices.endpointConfigSelectors.get",
Expand Down
6 changes: 6 additions & 0 deletions roles/composer.serviceAgent
Original file line number Diff line number Diff line change
Expand Up @@ -1464,6 +1464,12 @@
"networksecurity.urlLists.list",
"networksecurity.urlLists.update",
"networksecurity.urlLists.use",
"networkservices.authzExtensions.create",
"networkservices.authzExtensions.delete",
"networkservices.authzExtensions.get",
"networkservices.authzExtensions.list",
"networkservices.authzExtensions.update",
"networkservices.authzExtensions.use",
"networkservices.endpointConfigSelectors.create",
"networkservices.endpointConfigSelectors.delete",
"networkservices.endpointConfigSelectors.get",
Expand Down
6 changes: 6 additions & 0 deletions roles/compute.networkAdmin
Original file line number Diff line number Diff line change
Expand Up @@ -683,6 +683,12 @@
"networksecurity.urlLists.list",
"networksecurity.urlLists.update",
"networksecurity.urlLists.use",
"networkservices.authzExtensions.create",
"networkservices.authzExtensions.delete",
"networkservices.authzExtensions.get",
"networkservices.authzExtensions.list",
"networkservices.authzExtensions.update",
"networkservices.authzExtensions.use",
"networkservices.endpointConfigSelectors.create",
"networkservices.endpointConfigSelectors.delete",
"networkservices.endpointConfigSelectors.get",
Expand Down
3 changes: 3 additions & 0 deletions roles/compute.networkUser
Original file line number Diff line number Diff line change
Expand Up @@ -130,6 +130,9 @@
"networksecurity.urlLists.get",
"networksecurity.urlLists.list",
"networksecurity.urlLists.use",
"networkservices.authzExtensions.get",
"networkservices.authzExtensions.list",
"networkservices.authzExtensions.use",
"networkservices.endpointConfigSelectors.get",
"networkservices.endpointConfigSelectors.list",
"networkservices.endpointConfigSelectors.use",
Expand Down
2 changes: 2 additions & 0 deletions roles/compute.networkViewer
Original file line number Diff line number Diff line change
Expand Up @@ -239,6 +239,8 @@
"networksecurity.tlsInspectionPolicies.list",
"networksecurity.urlLists.get",
"networksecurity.urlLists.list",
"networkservices.authzExtensions.get",
"networkservices.authzExtensions.list",
"networkservices.endpointConfigSelectors.get",
"networkservices.endpointConfigSelectors.list",
"networkservices.endpointPolicies.get",
Expand Down
6 changes: 6 additions & 0 deletions roles/container.serviceAgent
Original file line number Diff line number Diff line change
Expand Up @@ -1449,6 +1449,12 @@
"networksecurity.urlLists.list",
"networksecurity.urlLists.update",
"networksecurity.urlLists.use",
"networkservices.authzExtensions.create",
"networkservices.authzExtensions.delete",
"networkservices.authzExtensions.get",
"networkservices.authzExtensions.list",
"networkservices.authzExtensions.update",
"networkservices.authzExtensions.use",
"networkservices.endpointConfigSelectors.create",
"networkservices.endpointConfigSelectors.delete",
"networkservices.endpointConfigSelectors.get",
Expand Down
6 changes: 6 additions & 0 deletions roles/dataflow.serviceAgent
Original file line number Diff line number Diff line change
Expand Up @@ -1129,6 +1129,12 @@
"networksecurity.urlLists.list",
"networksecurity.urlLists.update",
"networksecurity.urlLists.use",
"networkservices.authzExtensions.create",
"networkservices.authzExtensions.delete",
"networkservices.authzExtensions.get",
"networkservices.authzExtensions.list",
"networkservices.authzExtensions.update",
"networkservices.authzExtensions.use",
"networkservices.endpointConfigSelectors.create",
"networkservices.endpointConfigSelectors.delete",
"networkservices.endpointConfigSelectors.get",
Expand Down
2 changes: 2 additions & 0 deletions roles/datafusion.serviceAgent
Original file line number Diff line number Diff line change
Expand Up @@ -458,6 +458,8 @@
"networksecurity.tlsInspectionPolicies.list",
"networksecurity.urlLists.get",
"networksecurity.urlLists.list",
"networkservices.authzExtensions.get",
"networkservices.authzExtensions.list",
"networkservices.endpointConfigSelectors.get",
"networkservices.endpointConfigSelectors.list",
"networkservices.endpointPolicies.get",
Expand Down
1 change: 1 addition & 0 deletions roles/datastore.bulkAdmin
Original file line number Diff line number Diff line change
Expand Up @@ -2,6 +2,7 @@
"description": "Full access to manage bulk operations.",
"etag": "AA==",
"includedPermissions": [
"datastore.databases.bulkDelete",
"datastore.databases.getMetadata",
"datastore.operations.cancel",
"datastore.operations.get",
Expand Down
32 changes: 32 additions & 0 deletions roles/editor
Original file line number Diff line number Diff line change
Expand Up @@ -1809,13 +1809,29 @@
"clientauthconfig.clients.update",
"cloud.locations.get",
"cloud.locations.list",
"cloudaicompanion.codeRepositoryIndexes.create",
"cloudaicompanion.codeRepositoryIndexes.delete",
"cloudaicompanion.codeRepositoryIndexes.get",
"cloudaicompanion.codeRepositoryIndexes.list",
"cloudaicompanion.codeRepositoryIndexes.update",
"cloudaicompanion.companions.generateChat",
"cloudaicompanion.companions.generateCode",
"cloudaicompanion.entitlements.get",
"cloudaicompanion.instances.completeCode",
"cloudaicompanion.instances.completeTask",
"cloudaicompanion.instances.generateCode",
"cloudaicompanion.instances.generateText",
"cloudaicompanion.operations.cancel",
"cloudaicompanion.operations.delete",
"cloudaicompanion.operations.get",
"cloudaicompanion.operations.list",
"cloudaicompanion.repositoryGroups.create",
"cloudaicompanion.repositoryGroups.delete",
"cloudaicompanion.repositoryGroups.get",
"cloudaicompanion.repositoryGroups.getIamPolicy",
"cloudaicompanion.repositoryGroups.list",
"cloudaicompanion.repositoryGroups.update",
"cloudaicompanion.repositoryGroups.use",
"cloudasset.assets.analyzeIamPolicy",
"cloudasset.assets.analyzeMove",
"cloudasset.assets.analyzeOrgPolicy",
Expand Down Expand Up @@ -6175,6 +6191,11 @@
"managedflink.operations.delete",
"managedflink.operations.get",
"managedflink.operations.list",
"managedflink.sessions.create",
"managedflink.sessions.delete",
"managedflink.sessions.get",
"managedflink.sessions.list",
"managedflink.sessions.update",
"managedidentities.backups.create",
"managedidentities.backups.delete",
"managedidentities.backups.get",
Expand Down Expand Up @@ -6753,6 +6774,12 @@
"networksecurity.urlLists.list",
"networksecurity.urlLists.update",
"networksecurity.urlLists.use",
"networkservices.authzExtensions.create",
"networkservices.authzExtensions.delete",
"networkservices.authzExtensions.get",
"networkservices.authzExtensions.list",
"networkservices.authzExtensions.update",
"networkservices.authzExtensions.use",
"networkservices.endpointConfigSelectors.create",
"networkservices.endpointConfigSelectors.delete",
"networkservices.endpointConfigSelectors.get",
Expand Down Expand Up @@ -7779,6 +7806,11 @@
"securedlandingzone.overwatches.list",
"securedlandingzone.overwatches.suspend",
"securedlandingzone.overwatches.update",
"securesourcemanager.branchRules.create",
"securesourcemanager.branchRules.delete",
"securesourcemanager.branchRules.get",
"securesourcemanager.branchRules.list",
"securesourcemanager.branchRules.update",
"securesourcemanager.instances.access",
"securesourcemanager.instances.create",
"securesourcemanager.instances.createRepository",
Expand Down
1 change: 1 addition & 0 deletions roles/firebase.admin
Original file line number Diff line number Diff line change
Expand Up @@ -120,6 +120,7 @@
"datastore.backups.get",
"datastore.backups.list",
"datastore.backups.restoreDatabase",
"datastore.databases.bulkDelete",
"datastore.databases.create",
"datastore.databases.createTagBinding",
"datastore.databases.delete",
Expand Down
1 change: 1 addition & 0 deletions roles/firebase.developAdmin
Original file line number Diff line number Diff line change
Expand Up @@ -96,6 +96,7 @@
"datastore.backups.get",
"datastore.backups.list",
"datastore.backups.restoreDatabase",
"datastore.databases.bulkDelete",
"datastore.databases.create",
"datastore.databases.createTagBinding",
"datastore.databases.delete",
Expand Down
8 changes: 8 additions & 0 deletions roles/iam.securityAdmin
Original file line number Diff line number Diff line change
Expand Up @@ -454,6 +454,11 @@
"clientauthconfig.brands.list",
"clientauthconfig.clients.list",
"cloud.locations.list",
"cloudaicompanion.codeRepositoryIndexes.list",
"cloudaicompanion.operations.list",
"cloudaicompanion.repositoryGroups.getIamPolicy",
"cloudaicompanion.repositoryGroups.list",
"cloudaicompanion.repositoryGroups.setIamPolicy",
"cloudasset.assets.searchAllResources",
"cloudasset.feeds.list",
"cloudasset.savedqueries.list",
Expand Down Expand Up @@ -1487,6 +1492,7 @@
"managedflink.jobs.list",
"managedflink.locations.list",
"managedflink.operations.list",
"managedflink.sessions.list",
"managedidentities.backups.getIamPolicy",
"managedidentities.backups.list",
"managedidentities.backups.setIamPolicy",
Expand Down Expand Up @@ -1648,6 +1654,7 @@
"networksecurity.serverTlsPolicies.setIamPolicy",
"networksecurity.tlsInspectionPolicies.list",
"networksecurity.urlLists.list",
"networkservices.authzExtensions.list",
"networkservices.endpointConfigSelectors.getIamPolicy",
"networkservices.endpointConfigSelectors.list",
"networkservices.endpointConfigSelectors.setIamPolicy",
Expand Down Expand Up @@ -1966,6 +1973,7 @@
"secretmanager.secrets.setIamPolicy",
"secretmanager.versions.list",
"securedlandingzone.overwatches.list",
"securesourcemanager.branchRules.list",
"securesourcemanager.instances.getIamPolicy",
"securesourcemanager.instances.list",
"securesourcemanager.instances.setIamPolicy",
Expand Down
5 changes: 5 additions & 0 deletions roles/managedflink.admin
Original file line number Diff line number Diff line change
Expand Up @@ -18,6 +18,11 @@
"managedflink.operations.delete",
"managedflink.operations.get",
"managedflink.operations.list",
"managedflink.sessions.create",
"managedflink.sessions.delete",
"managedflink.sessions.get",
"managedflink.sessions.list",
"managedflink.sessions.update",
"resourcemanager.projects.get",
"resourcemanager.projects.list"
],
Expand Down
32 changes: 32 additions & 0 deletions roles/managedflink.serviceAgent
Original file line number Diff line number Diff line change
@@ -0,0 +1,32 @@
{
"description": "Gives Managed Flink Service Agent access to Cloud Platform resources.",
"etag": "AA==",
"includedPermissions": [
"compute.networkAttachments.create",
"compute.networkAttachments.delete",
"compute.networkAttachments.get",
"compute.networkAttachments.list",
"compute.networkAttachments.update",
"compute.networks.get",
"compute.networks.list",
"compute.regionOperations.get",
"compute.subnetworks.get",
"compute.subnetworks.list",
"compute.subnetworks.use",
"dns.networks.targetWithPeeringZone",
"managedkafka.clusters.get",
"managedkafka.clusters.list",
"managedkafka.clusters.update",
"monitoring.metricDescriptors.create",
"monitoring.metricDescriptors.get",
"monitoring.metricDescriptors.list",
"monitoring.monitoredResourceDescriptors.get",
"monitoring.monitoredResourceDescriptors.list",
"monitoring.timeSeries.create",
"serviceusage.services.use",
"storage.objects.get"
],
"name": "roles/managedflink.serviceAgent",
"stage": "GA",
"title": "Managed Flink Service Agent"
}
2 changes: 2 additions & 0 deletions roles/managedflink.viewer
Original file line number Diff line number Diff line change
Expand Up @@ -10,6 +10,8 @@
"managedflink.locations.list",
"managedflink.operations.get",
"managedflink.operations.list",
"managedflink.sessions.get",
"managedflink.sessions.list",
"resourcemanager.projects.get",
"resourcemanager.projects.list"
],
Expand Down
Loading

0 comments on commit c58e7cb

Please sign in to comment.