Skip to content

Commit

Permalink
audit: update as of 2021-10-14
Browse files Browse the repository at this point in the history
  • Loading branch information
Kubernetes Prow Robot committed Oct 14, 2021
1 parent 3e37551 commit cc1d366
Show file tree
Hide file tree
Showing 10 changed files with 126 additions and 6 deletions.
4 changes: 1 addition & 3 deletions audit/projects/k8s-cip-test-prod/services/logging/logs.json
Original file line number Diff line number Diff line change
@@ -1,3 +1 @@
[
"projects/k8s-cip-test-prod/logs/cloudaudit.googleapis.com%2Fsystem_event"
]
[]
Original file line number Diff line number Diff line change
@@ -1,4 +1,3 @@
[
"projects/k8s-staging-ci-images/logs/cloudaudit.googleapis.com%2Factivity",
"projects/k8s-staging-ci-images/logs/cloudaudit.googleapis.com%2Fsystem_event"
"projects/k8s-staging-ci-images/logs/cloudaudit.googleapis.com%2Factivity"
]
Original file line number Diff line number Diff line change
@@ -1,7 +1,6 @@
[
"projects/k8s-staging-cluster-api-gcp/logs/cloudaudit.googleapis.com%2Factivity",
"projects/k8s-staging-cluster-api-gcp/logs/cloudaudit.googleapis.com%2Fdata_access",
"projects/k8s-staging-cluster-api-gcp/logs/cloudaudit.googleapis.com%2Fsystem_event",
"projects/k8s-staging-cluster-api-gcp/logs/cloudbuild",
"projects/k8s-staging-cluster-api-gcp/logs/compute.googleapis.com%2Fshielded_vm_integrity"
]
29 changes: 29 additions & 0 deletions audit/projects/kubernetes-public/buckets/k8s-infra-tf-gcp/iam.json
Original file line number Diff line number Diff line change
@@ -0,0 +1,29 @@
{
"bindings": [
{
"members": [
"group:k8s-infra-gcp-org-admins@kubernetes.io"
],
"role": "roles/storage.admin"
},
{
"members": [
"group:k8s-infra-gcp-org-admins@kubernetes.io",
"projectOwner:kubernetes-public"
],
"role": "roles/storage.legacyBucketOwner"
},
{
"members": [
"projectViewer:kubernetes-public"
],
"role": "roles/storage.legacyBucketReader"
},
{
"members": [
"group:k8s-infra-gcp-org-admins@kubernetes.io"
],
"role": "roles/storage.objectAdmin"
}
]
}
Original file line number Diff line number Diff line change
@@ -0,0 +1,20 @@
gs://k8s-infra-tf-gcp/ :
Storage class: STANDARD
Location type: multi-region
Location constraint: US
Versioning enabled: None
Logging configuration: None
Website configuration: None
CORS configuration: None
Lifecycle configuration: None
Requester Pays enabled: None
Labels: None
Default KMS key: None
Time created: Thu, 14 Oct 2021 16:46:11 GMT
Time updated: Thu, 14 Oct 2021 16:46:32 GMT
Metageneration: 6
Bucket Policy Only enabled: True
Public access prevention: unspecified
RPO: DEFAULT
ACL: []
Default ACL: []
Original file line number Diff line number Diff line change
@@ -0,0 +1,29 @@
{
"bindings": [
{
"members": [
"group:k8s-infra-gcp-org-admins@kubernetes.io"
],
"role": "roles/storage.admin"
},
{
"members": [
"group:k8s-infra-cluster-admins@kubernetes.io",
"projectOwner:kubernetes-public"
],
"role": "roles/storage.legacyBucketOwner"
},
{
"members": [
"projectViewer:kubernetes-public"
],
"role": "roles/storage.legacyBucketReader"
},
{
"members": [
"group:k8s-infra-cluster-admins@kubernetes.io"
],
"role": "roles/storage.objectAdmin"
}
]
}
Original file line number Diff line number Diff line change
@@ -0,0 +1,20 @@
gs://k8s-infra-tf-monitoring/ :
Storage class: STANDARD
Location type: multi-region
Location constraint: US
Versioning enabled: None
Logging configuration: None
Website configuration: None
CORS configuration: None
Lifecycle configuration: None
Requester Pays enabled: None
Labels: None
Default KMS key: None
Time created: Thu, 14 Oct 2021 04:54:40 GMT
Time updated: Thu, 14 Oct 2021 04:55:14 GMT
Metageneration: 6
Bucket Policy Only enabled: True
Public access prevention: unspecified
RPO: DEFAULT
ACL: []
Default ACL: []
7 changes: 7 additions & 0 deletions audit/projects/kubernetes-public/iam.json
Original file line number Diff line number Diff line change
Expand Up @@ -117,6 +117,12 @@
],
"role": "roles/logging.privateLogViewer"
},
{
"members": [
"serviceAccount:tf-monitoring-deployer@kubernetes-public.iam.gserviceaccount.com"
],
"role": "roles/monitoring.admin"
},
{
"members": [
"serviceAccount:gke-nodes-aaa@kubernetes-public.iam.gserviceaccount.com"
Expand Down Expand Up @@ -161,6 +167,7 @@
"group:k8s-infra-artifact-admins@kubernetes.io",
"group:k8s-infra-aws-admins@kubernetes.io",
"group:k8s-infra-cluster-admins@kubernetes.io",
"group:k8s-infra-gcp-org-admins@kubernetes.io",
"group:k8s-infra-ii-coop@kubernetes.io",
"group:k8s-infra-prow-oncall@kubernetes.io",
"group:k8s-infra-sandbox-capg@kubernetes.io",
Expand Down
Original file line number Diff line number Diff line change
@@ -0,0 +1,8 @@
{
"displayName": "tf-monitoring-deployer",
"email": "tf-monitoring-deployer@kubernetes-public.iam.gserviceaccount.com",
"name": "projects/kubernetes-public/serviceAccounts/tf-monitoring-deployer@kubernetes-public.iam.gserviceaccount.com",
"oauth2ClientId": "105944484171419312033",
"projectId": "kubernetes-public",
"uniqueId": "105944484171419312033"
}
Original file line number Diff line number Diff line change
@@ -0,0 +1,11 @@
{
"bindings": [
{
"members": [
"serviceAccount:kubernetes-public.svc.id.goog[test-pods/tf-monitoring-deployer]"
],
"role": "roles/iam.workloadIdentityUser"
}
],
"version": 1
}

0 comments on commit cc1d366

Please sign in to comment.