Skip to content

Commit

Permalink
GCP IAM Updates Detected
Browse files Browse the repository at this point in the history
  • Loading branch information
jdyke committed Jan 18, 2025
1 parent a1e93e4 commit d81fd91
Show file tree
Hide file tree
Showing 21 changed files with 78 additions and 10 deletions.
3 changes: 2 additions & 1 deletion roles/apigee.serviceAgent
Original file line number Diff line number Diff line change
Expand Up @@ -42,7 +42,8 @@
"monitoring.metricDescriptors.list",
"monitoring.monitoredResourceDescriptors.get",
"monitoring.monitoredResourceDescriptors.list",
"monitoring.timeSeries.create"
"monitoring.timeSeries.create",
"telemetry.traces.write"
],
"name": "roles/apigee.serviceAgent",
"stage": "GA",
Expand Down
2 changes: 1 addition & 1 deletion roles/backupdr.managementServerAccessor
Original file line number Diff line number Diff line change
Expand Up @@ -5,6 +5,6 @@
"backupdr.managementServers.createConnection"
],
"name": "roles/backupdr.managementServerAccessor",
"stage": "BETA",
"stage": "GA",
"title": "Backup and DR Management Server Accessor"
}
3 changes: 2 additions & 1 deletion roles/cloudtrace.admin
Original file line number Diff line number Diff line change
Expand Up @@ -19,7 +19,8 @@
"cloudtrace.traces.patch",
"observability.scopes.get",
"resourcemanager.projects.get",
"resourcemanager.projects.list"
"resourcemanager.projects.list",
"telemetry.traces.write"
],
"name": "roles/cloudtrace.admin",
"stage": "GA",
Expand Down
7 changes: 7 additions & 0 deletions roles/dataform.codeCommenter
Original file line number Diff line number Diff line change
@@ -0,0 +1,7 @@
{
"description": "Permissions to comment, at the repository level. Grants CRUD access over commentThread and comment resources.",
"etag": "AA==",
"name": "roles/dataform.codeCommenter",
"stage": "BETA",
"title": "Code Commenter"
}
2 changes: 1 addition & 1 deletion roles/dataplex.encryptionAdmin
Original file line number Diff line number Diff line change
Expand Up @@ -11,6 +11,6 @@
"dataplex.operations.list"
],
"name": "roles/dataplex.encryptionAdmin",
"stage": "BETA",
"stage": "GA",
"title": "Dataplex Encryption Admin"
}
2 changes: 1 addition & 1 deletion roles/dataplex.metadataJobOwner
Original file line number Diff line number Diff line change
Expand Up @@ -11,6 +11,6 @@
"resourcemanager.projects.list"
],
"name": "roles/dataplex.metadataJobOwner",
"stage": "BETA",
"stage": "GA",
"title": "Dataplex Metadata Job Owner"
}
2 changes: 1 addition & 1 deletion roles/dataplex.metadataJobViewer
Original file line number Diff line number Diff line change
Expand Up @@ -9,6 +9,6 @@
"resourcemanager.projects.list"
],
"name": "roles/dataplex.metadataJobViewer",
"stage": "BETA",
"stage": "GA",
"title": "Dataplex Metadata Job Viewer"
}
3 changes: 3 additions & 0 deletions roles/editor
Original file line number Diff line number Diff line change
Expand Up @@ -6806,6 +6806,7 @@
"netapp.storagePools.validateDirectoryService",
"netapp.volumes.create",
"netapp.volumes.delete",
"netapp.volumes.findValidCRRRegions",
"netapp.volumes.get",
"netapp.volumes.list",
"netapp.volumes.revert",
Expand Down Expand Up @@ -8659,6 +8660,8 @@
"telcoautomation.orchestrationClusters.list",
"telcoautomation.publicBlueprints.get",
"telcoautomation.publicBlueprints.list",
"telemetry.metrics.write",
"telemetry.traces.write",
"timeseriesinsights.datasets.create",
"timeseriesinsights.datasets.delete",
"timeseriesinsights.datasets.evaluate",
Expand Down
2 changes: 2 additions & 0 deletions roles/firebase.viewer
Original file line number Diff line number Diff line change
Expand Up @@ -49,6 +49,8 @@
"cloudtoolresults.settings.get",
"cloudtoolresults.steps.get",
"cloudtoolresults.steps.list",
"datastore.backups.get",
"datastore.backups.list",
"datastore.databases.get",
"datastore.databases.getMetadata",
"datastore.databases.list",
Expand Down
3 changes: 2 additions & 1 deletion roles/memorystore.admin
Original file line number Diff line number Diff line change
Expand Up @@ -2,6 +2,7 @@
"description": "Full access to Memorystore resources.",
"etag": "AA==",
"includedPermissions": [
"memorystore.instances.connect",
"memorystore.instances.create",
"memorystore.instances.delete",
"memorystore.instances.get",
Expand All @@ -17,6 +18,6 @@
"resourcemanager.projects.list"
],
"name": "roles/memorystore.admin",
"stage": "BETA",
"stage": "GA",
"title": "Memorystore Admin"
}
2 changes: 1 addition & 1 deletion roles/memorystore.dbConnectionUser
Original file line number Diff line number Diff line change
Expand Up @@ -5,6 +5,6 @@
"memorystore.instances.connect"
],
"name": "roles/memorystore.dbConnectionUser",
"stage": "BETA",
"stage": "GA",
"title": "Memorystore DB Connector User"
}
3 changes: 2 additions & 1 deletion roles/meshdataplane.serviceAgent
Original file line number Diff line number Diff line change
Expand Up @@ -13,7 +13,8 @@
"monitoring.monitoredResourceDescriptors.get",
"monitoring.monitoredResourceDescriptors.list",
"monitoring.timeSeries.create",
"serviceusage.services.use"
"serviceusage.services.use",
"telemetry.traces.write"
],
"name": "roles/meshdataplane.serviceAgent",
"stage": "GA",
Expand Down
2 changes: 1 addition & 1 deletion roles/modelarmor.serviceAgent
Original file line number Diff line number Diff line change
Expand Up @@ -21,6 +21,6 @@
"serviceusage.services.use"
],
"name": "roles/modelarmor.serviceAgent",
"stage": "ALPHA",
"stage": "GA",
"title": "Model Armor Service Agent"
}
1 change: 1 addition & 0 deletions roles/netapp.admin
Original file line number Diff line number Diff line change
Expand Up @@ -64,6 +64,7 @@
"netapp.storagePools.validateDirectoryService",
"netapp.volumes.create",
"netapp.volumes.delete",
"netapp.volumes.findValidCRRRegions",
"netapp.volumes.get",
"netapp.volumes.list",
"netapp.volumes.revert",
Expand Down
4 changes: 4 additions & 0 deletions roles/orgpolicy.policyAdmin
Original file line number Diff line number Diff line change
Expand Up @@ -2,6 +2,10 @@
"description": "The permission to set Organization Policies on resources.",
"etag": "AA==",
"includedPermissions": [
"cloudasset.assets.analyzeOrgPolicy",
"cloudasset.assets.exportResource",
"cloudasset.assets.listResource",
"cloudasset.assets.searchAllResources",
"orgpolicy.constraints.list",
"orgpolicy.customConstraints.create",
"orgpolicy.customConstraints.delete",
Expand Down
12 changes: 12 additions & 0 deletions roles/osconfig.rolloutServiceAgent
Original file line number Diff line number Diff line change
@@ -0,0 +1,12 @@
{
"description": "Grants OS Config Rollout Service Account access to zonal OS Config resources.",
"etag": "AA==",
"includedPermissions": [
"osconfig.osPolicyAssignments.delete",
"osconfig.osPolicyAssignments.get",
"osconfig.osPolicyAssignments.update"
],
"name": "roles/osconfig.rolloutServiceAgent",
"stage": "GA",
"title": "Cloud OS Config Rollout Service Agent"
}
3 changes: 3 additions & 0 deletions roles/owner
Original file line number Diff line number Diff line change
Expand Up @@ -7911,6 +7911,7 @@
"netapp.storagePools.validateDirectoryService",
"netapp.volumes.create",
"netapp.volumes.delete",
"netapp.volumes.findValidCRRRegions",
"netapp.volumes.get",
"netapp.volumes.list",
"netapp.volumes.revert",
Expand Down Expand Up @@ -9888,6 +9889,8 @@
"telcoautomation.orchestrationClusters.list",
"telcoautomation.publicBlueprints.get",
"telcoautomation.publicBlueprints.list",
"telemetry.metrics.write",
"telemetry.traces.write",
"timeseriesinsights.datasets.create",
"timeseriesinsights.datasets.delete",
"timeseriesinsights.datasets.evaluate",
Expand Down
10 changes: 10 additions & 0 deletions roles/telemetry.metricsWriter
Original file line number Diff line number Diff line change
@@ -0,0 +1,10 @@
{
"description": "Access to write metrics.",
"etag": "AA==",
"includedPermissions": [
"telemetry.metrics.write"
],
"name": "roles/telemetry.metricsWriter",
"stage": "BETA",
"title": "Cloud Telemetry Metrics Writer"
}
10 changes: 10 additions & 0 deletions roles/telemetry.tracesWriter
Original file line number Diff line number Diff line change
@@ -0,0 +1,10 @@
{
"description": "Access to write trace spans.",
"etag": "AA==",
"includedPermissions": [
"telemetry.traces.write"
],
"name": "roles/telemetry.tracesWriter",
"stage": "BETA",
"title": "Cloud Telemetry Traces Writer"
}
11 changes: 11 additions & 0 deletions roles/telemetry.writer
Original file line number Diff line number Diff line change
@@ -0,0 +1,11 @@
{
"description": "Full access to write all telemetry data.",
"etag": "AA==",
"includedPermissions": [
"telemetry.metrics.write",
"telemetry.traces.write"
],
"name": "roles/telemetry.writer",
"stage": "BETA",
"title": "Cloud Telemetry Writer"
}
1 change: 1 addition & 0 deletions roles/viewer
Original file line number Diff line number Diff line change
Expand Up @@ -3357,6 +3357,7 @@
"netapp.snapshots.list",
"netapp.storagePools.get",
"netapp.storagePools.list",
"netapp.volumes.findValidCRRRegions",
"netapp.volumes.get",
"netapp.volumes.list",
"networkconnectivity.groups.get",
Expand Down

0 comments on commit d81fd91

Please sign in to comment.