Skip to content

Commit cf62a96

Browse files
committed
Fetch all roles
1 parent 49cd2f1 commit cf62a96

20 files changed

+33
-167
lines changed

gcp_roles_cai.json

Lines changed: 15 additions & 19 deletions
Large diffs are not rendered by default.

roles/backupdr.backupUser

Lines changed: 0 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -13,8 +13,6 @@
1313
"backupdr.backupPlanAssociations.triggerBackupForComputeInstance",
1414
"backupdr.backupPlanAssociations.updateForComputeDisk",
1515
"backupdr.backupPlanAssociations.updateForComputeInstance",
16-
"backupdr.backupPlanRevisions.get",
17-
"backupdr.backupPlanRevisions.list",
1816
"backupdr.backupPlans.get",
1917
"backupdr.backupPlans.list",
2018
"backupdr.backupPlans.useForComputeDisk",

roles/backupdr.serviceAgent

Lines changed: 0 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -2,7 +2,6 @@
22
"description": "Grants the Backup and DR Service access to discover and protect GCP resources.",
33
"etag": "AA==",
44
"includedPermissions": [
5-
"alloydb.operations.get",
65
"cloudsql.instances.get",
76
"compute.addresses.list",
87
"compute.addresses.use",

roles/chronicle.soarServiceAgent

Lines changed: 3 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -9,12 +9,15 @@
99
"cloudasset.assets.searchAllResources",
1010
"compute.firewalls.get",
1111
"compute.firewalls.update",
12+
"compute.globalOperations.get",
1213
"compute.instances.deleteAccessConfig",
1314
"compute.instances.get",
1415
"compute.instances.list",
1516
"compute.instances.stop",
1617
"compute.instances.updateNetworkInterface",
1718
"compute.networks.updatePolicy",
19+
"compute.regionOperations.get",
20+
"compute.zoneOperations.get",
1821
"compute.zones.list",
1922
"iam.serviceAccounts.disable",
2023
"iam.serviceAccounts.list",

roles/clouddeploy.developer

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -29,6 +29,7 @@
2929
"clouddeploy.operations.list",
3030
"clouddeploy.releases.abandon",
3131
"clouddeploy.releases.create",
32+
"clouddeploy.releases.delete",
3233
"clouddeploy.releases.get",
3334
"clouddeploy.releases.list",
3435
"clouddeploy.rollouts.get",

roles/clouddeploy.operator

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -38,6 +38,7 @@
3838
"clouddeploy.operations.list",
3939
"clouddeploy.releases.abandon",
4040
"clouddeploy.releases.create",
41+
"clouddeploy.releases.delete",
4142
"clouddeploy.releases.get",
4243
"clouddeploy.releases.list",
4344
"clouddeploy.rollouts.advance",

roles/compliancescanning.serviceAgent

Lines changed: 0 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -28,15 +28,12 @@
2828
"artifactregistry.tags.list",
2929
"artifactregistry.versions.get",
3030
"artifactregistry.versions.list",
31-
"compute.globalOperations.get",
3231
"compute.images.get",
3332
"compute.images.list",
3433
"compute.images.useReadOnly",
3534
"compute.instances.get",
3635
"compute.instances.getGuestAttributes",
3736
"compute.instances.list",
38-
"compute.regionOperations.get",
39-
"compute.zoneOperations.get",
4037
"compute.zones.get",
4138
"compute.zones.list",
4239
"containeranalysis.notes.attachOccurrence",

roles/compute.serviceAgent

Lines changed: 0 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -10,7 +10,6 @@
1010
"compute.disks.setLabels",
1111
"compute.disks.use",
1212
"compute.disks.useReadOnly",
13-
"compute.globalOperations.get",
1413
"compute.images.useReadOnly",
1514
"compute.instanceGroupManagers.get",
1615
"compute.instanceTemplates.useReadOnly",
@@ -25,12 +24,10 @@
2524
"compute.machineImages.useReadOnly",
2625
"compute.networks.use",
2726
"compute.networks.useExternalIp",
28-
"compute.regionOperations.get",
2927
"compute.resourcePolicies.use",
3028
"compute.snapshots.useReadOnly",
3129
"compute.subnetworks.use",
3230
"compute.subnetworks.useExternalIp",
33-
"compute.zoneOperations.get",
3431
"iam.serviceAccounts.actAs",
3532
"iam.serviceAccounts.getAccessToken",
3633
"iam.serviceAccounts.getOpenIdToken",

roles/datastream.bigqueryWriter

Lines changed: 0 additions & 72 deletions
This file was deleted.

roles/developerconnect.insightsAdmin

Lines changed: 0 additions & 15 deletions
This file was deleted.

roles/developerconnect.insightsAgent

Lines changed: 0 additions & 17 deletions
This file was deleted.

roles/developerconnect.insightsViewer

Lines changed: 0 additions & 15 deletions
This file was deleted.

roles/discoveryengine.user

Lines changed: 0 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -18,7 +18,6 @@
1818
"discoveryengine.dataConnectors.checkRefreshToken",
1919
"discoveryengine.dataConnectors.executeAction",
2020
"discoveryengine.dataConnectors.queryAvailableActions",
21-
"discoveryengine.engines.get",
2221
"discoveryengine.notebooks.create",
2322
"discoveryengine.notebooks.list",
2423
"discoveryengine.servingConfigs.answer",

roles/documentai.admin

Lines changed: 3 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -4,7 +4,9 @@
44
"includedPermissions": [
55
"documentai.dataLabelingJobs.cancel",
66
"documentai.dataLabelingJobs.create",
7+
"documentai.dataLabelingJobs.delete",
78
"documentai.dataLabelingJobs.list",
9+
"documentai.dataLabelingJobs.update",
810
"documentai.datasetSchemas.get",
911
"documentai.datasetSchemas.update",
1012
"documentai.datasets.createDocuments",
@@ -25,6 +27,7 @@
2527
"documentai.labelerPools.delete",
2628
"documentai.labelerPools.get",
2729
"documentai.labelerPools.list",
30+
"documentai.labelerPools.update",
2831
"documentai.locations.get",
2932
"documentai.locations.list",
3033
"documentai.operations.getLegacy",

roles/documentai.editor

Lines changed: 3 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -4,7 +4,9 @@
44
"includedPermissions": [
55
"documentai.dataLabelingJobs.cancel",
66
"documentai.dataLabelingJobs.create",
7+
"documentai.dataLabelingJobs.delete",
78
"documentai.dataLabelingJobs.list",
9+
"documentai.dataLabelingJobs.update",
810
"documentai.datasetSchemas.get",
911
"documentai.datasetSchemas.update",
1012
"documentai.datasets.createDocuments",
@@ -25,6 +27,7 @@
2527
"documentai.labelerPools.delete",
2628
"documentai.labelerPools.get",
2729
"documentai.labelerPools.list",
30+
"documentai.labelerPools.update",
2831
"documentai.locations.get",
2932
"documentai.locations.list",
3033
"documentai.operations.getLegacy",

roles/editor

Lines changed: 4 additions & 11 deletions
Original file line numberDiff line numberDiff line change
@@ -1875,10 +1875,6 @@
18751875
"chronicle.instances.permitFederationAccess",
18761876
"chronicle.instances.report",
18771877
"chronicle.instances.verifyNonce",
1878-
"chronicle.iocAssociations.batchGet",
1879-
"chronicle.iocAssociations.fetchRelatedIocAssociations",
1880-
"chronicle.iocAssociations.fetchRelatedThreatCollections",
1881-
"chronicle.iocAssociations.get",
18821878
"chronicle.iocMatches.get",
18831879
"chronicle.iocMatches.list",
18841880
"chronicle.iocState.get",
@@ -1973,10 +1969,6 @@
19731969
"chronicle.searchQueries.get",
19741970
"chronicle.searchQueries.list",
19751971
"chronicle.searchQueries.update",
1976-
"chronicle.threatCollections.fetchIocMatchMetadata",
1977-
"chronicle.threatCollections.fetchRuleMetadata",
1978-
"chronicle.threatCollections.get",
1979-
"chronicle.threatCollections.list",
19801972
"chronicle.watchlists.get",
19811973
"chronicle.watchlists.list",
19821974
"chroniclesm.gcpAssociations.get",
@@ -2291,6 +2283,7 @@
22912283
"clouddeploy.operations.list",
22922284
"clouddeploy.releases.abandon",
22932285
"clouddeploy.releases.create",
2286+
"clouddeploy.releases.delete",
22942287
"clouddeploy.releases.get",
22952288
"clouddeploy.releases.list",
22962289
"clouddeploy.rollouts.advance",
@@ -5626,7 +5619,9 @@
56265619
"dns.responsePolicyRules.update",
56275620
"documentai.dataLabelingJobs.cancel",
56285621
"documentai.dataLabelingJobs.create",
5622+
"documentai.dataLabelingJobs.delete",
56295623
"documentai.dataLabelingJobs.list",
5624+
"documentai.dataLabelingJobs.update",
56305625
"documentai.datasetSchemas.get",
56315626
"documentai.datasetSchemas.update",
56325627
"documentai.datasets.createDocuments",
@@ -5647,6 +5642,7 @@
56475642
"documentai.labelerPools.delete",
56485643
"documentai.labelerPools.get",
56495644
"documentai.labelerPools.list",
5645+
"documentai.labelerPools.update",
56505646
"documentai.locations.get",
56515647
"documentai.locations.list",
56525648
"documentai.operations.getLegacy",
@@ -6599,9 +6595,6 @@
65996595
"iam.principalaccessboundarypolicies.searchPolicyBindings",
66006596
"iam.roles.get",
66016597
"iam.roles.list",
6602-
"iam.serviceAccountApiKeyBindings.create",
6603-
"iam.serviceAccountApiKeyBindings.delete",
6604-
"iam.serviceAccountApiKeyBindings.undelete",
66056598
"iam.serviceAccountKeys.create",
66066599
"iam.serviceAccountKeys.delete",
66076600
"iam.serviceAccountKeys.disable",

roles/iam.securityAdmin

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -483,6 +483,7 @@
483483
"chronicle.ruleExecutionErrors.list",
484484
"chronicle.rules.list",
485485
"chronicle.searchQueries.list",
486+
"chronicle.threatCollections.list",
486487
"chronicle.validationErrors.list",
487488
"chronicle.watchlists.list",
488489
"chroniclesm.gcpAssociations.list",

roles/iam.serviceAccountApiKeyBindingAdmin

Lines changed: 0 additions & 5 deletions
Original file line numberDiff line numberDiff line change
@@ -1,11 +1,6 @@
11
{
22
"description": "Create and delete service account API Key bindings",
33
"etag": "AA==",
4-
"includedPermissions": [
5-
"iam.serviceAccountApiKeyBindings.create",
6-
"iam.serviceAccountApiKeyBindings.delete",
7-
"iam.serviceAccountApiKeyBindings.undelete"
8-
],
94
"name": "roles/iam.serviceAccountApiKeyBindingAdmin",
105
"stage": "GA",
116
"title": "Service Account API Key Binding Admin"

roles/observability.analyticsUser

Lines changed: 0 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -2,9 +2,6 @@
22
"description": "Grants permissions to use Cloud Observability Analytics.",
33
"etag": "AA==",
44
"includedPermissions": [
5-
"logging.queries.getShared",
6-
"logging.queries.listShared",
7-
"logging.queries.usePrivate",
85
"observability.analyticsViews.create",
96
"observability.analyticsViews.delete",
107
"observability.analyticsViews.get",

roles/securitycenter.serviceAgent

Lines changed: 2 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -584,6 +584,8 @@
584584
"compute.instances.list",
585585
"compute.networkEndpointGroups.get",
586586
"compute.projects.get",
587+
"compute.regionOperations.get",
588+
"compute.zoneOperations.get",
587589
"container.clusters.get",
588590
"iam.denypolicies.get",
589591
"iam.denypolicies.list",

0 commit comments

Comments
 (0)