Skip to content

Commit 7f29b8e

Browse files
authored
Merge pull request #2322 from cncf-ci/autoaudit-prow
audit: update as of 2021-07-16
2 parents 7b8072e + 007f83a commit 7f29b8e

File tree

23 files changed

+53
-29
lines changed

23 files changed

+53
-29
lines changed

audit/projects/k8s-artifacts-prod/services/logging/logs.json

Lines changed: 0 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -1,7 +1,5 @@
11
[
22
"projects/k8s-artifacts-prod/logs/cip-audit-log",
3-
"projects/k8s-artifacts-prod/logs/cloudaudit.googleapis.com%2Factivity",
4-
"projects/k8s-artifacts-prod/logs/cloudaudit.googleapis.com%2Fsystem_event",
53
"projects/k8s-artifacts-prod/logs/requests",
64
"projects/k8s-artifacts-prod/logs/run.googleapis.com%2Frequests",
75
"projects/k8s-artifacts-prod/logs/run.googleapis.com%2Fstderr"
Lines changed: 1 addition & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -1,4 +1 @@
1-
[
2-
"projects/k8s-cip-test-prod/logs/cloudaudit.googleapis.com%2Factivity",
3-
"projects/k8s-cip-test-prod/logs/cloudaudit.googleapis.com%2Fsystem_event"
4-
]
1+
[]

audit/projects/k8s-release/buckets/k8s-release-dev-asia/iam.json

Lines changed: 4 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -3,6 +3,7 @@
33
{
44
"members": [
55
6+
67
"projectEditor:k8s-release",
78
"projectOwner:k8s-release"
89
],
@@ -18,15 +19,18 @@
1819
"members": [
1920
2021
22+
"serviceAccount:[email protected]",
2123
"serviceAccount:[email protected]"
2224
],
2325
"role": "roles/storage.legacyBucketWriter"
2426
},
2527
{
2628
"members": [
2729
30+
2831
2932
33+
"serviceAccount:[email protected]",
3034
"serviceAccount:[email protected]"
3135
],
3236
"role": "roles/storage.objectAdmin"
Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1 @@
1+
{"rule": [{"action": {"type": "Delete"}, "condition": {"age": 90}}]}
Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1 @@
1+
{"logBucket": "k8s-infra-artifacts-gcslogs", "logObjectPrefix": "k8s-release-dev-asia"}

audit/projects/k8s-release/buckets/k8s-release-dev-asia/metadata.txt

Lines changed: 4 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -3,16 +3,16 @@ gs://k8s-release-dev-asia/ :
33
Location type: multi-region
44
Location constraint: US
55
Versioning enabled: None
6-
Logging configuration: None
6+
Logging configuration: Present
77
Website configuration: None
88
CORS configuration: None
9-
Lifecycle configuration: None
9+
Lifecycle configuration: Present
1010
Requester Pays enabled: None
1111
Labels: None
1212
Default KMS key: None
1313
Time created: Mon, 31 Aug 2020 23:11:19 GMT
14-
Time updated: Mon, 31 Aug 2020 23:11:44 GMT
15-
Metageneration: 11
14+
Time updated: Thu, 15 Jul 2021 22:40:22 GMT
15+
Metageneration: 18
1616
Bucket Policy Only enabled: True
1717
ACL: []
1818
Default ACL: []

audit/projects/k8s-release/buckets/k8s-release-dev-eu/iam.json

Lines changed: 4 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -3,6 +3,7 @@
33
{
44
"members": [
55
6+
67
"projectEditor:k8s-release",
78
"projectOwner:k8s-release"
89
],
@@ -18,15 +19,18 @@
1819
"members": [
1920
2021
22+
"serviceAccount:[email protected]",
2123
"serviceAccount:[email protected]"
2224
],
2325
"role": "roles/storage.legacyBucketWriter"
2426
},
2527
{
2628
"members": [
2729
30+
2831
2932
33+
"serviceAccount:[email protected]",
3034
"serviceAccount:[email protected]"
3135
],
3236
"role": "roles/storage.objectAdmin"
Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1 @@
1+
{"rule": [{"action": {"type": "Delete"}, "condition": {"age": 90}}]}
Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1 @@
1+
{"logBucket": "k8s-infra-artifacts-gcslogs", "logObjectPrefix": "k8s-release-dev-eu"}

audit/projects/k8s-release/buckets/k8s-release-dev-eu/metadata.txt

Lines changed: 4 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -3,16 +3,16 @@ gs://k8s-release-dev-eu/ :
33
Location type: multi-region
44
Location constraint: US
55
Versioning enabled: None
6-
Logging configuration: None
6+
Logging configuration: Present
77
Website configuration: None
88
CORS configuration: None
9-
Lifecycle configuration: None
9+
Lifecycle configuration: Present
1010
Requester Pays enabled: None
1111
Labels: None
1212
Default KMS key: None
1313
Time created: Mon, 31 Aug 2020 23:11:48 GMT
14-
Time updated: Mon, 31 Aug 2020 23:12:12 GMT
15-
Metageneration: 11
14+
Time updated: Thu, 15 Jul 2021 22:40:55 GMT
15+
Metageneration: 18
1616
Bucket Policy Only enabled: True
1717
ACL: []
1818
Default ACL: []

audit/projects/k8s-release/buckets/k8s-release-dev/iam.json

Lines changed: 4 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -3,6 +3,7 @@
33
{
44
"members": [
55
6+
67
"projectEditor:k8s-release",
78
"projectOwner:k8s-release"
89
],
@@ -18,15 +19,18 @@
1819
"members": [
1920
2021
22+
"serviceAccount:[email protected]",
2123
"serviceAccount:[email protected]"
2224
],
2325
"role": "roles/storage.legacyBucketWriter"
2426
},
2527
{
2628
"members": [
2729
30+
2831
2932
33+
"serviceAccount:[email protected]",
3034
"serviceAccount:[email protected]"
3135
],
3236
"role": "roles/storage.objectAdmin"
Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1 @@
1+
{"logBucket": "k8s-infra-artifacts-gcslogs", "logObjectPrefix": "k8s-release-dev"}

audit/projects/k8s-release/buckets/k8s-release-dev/metadata.txt

Lines changed: 3 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -3,16 +3,16 @@ gs://k8s-release-dev/ :
33
Location type: multi-region
44
Location constraint: US
55
Versioning enabled: None
6-
Logging configuration: None
6+
Logging configuration: Present
77
Website configuration: None
88
CORS configuration: None
99
Lifecycle configuration: Present
1010
Requester Pays enabled: None
1111
Labels: None
1212
Default KMS key: None
1313
Time created: Tue, 04 Aug 2020 20:14:09 GMT
14-
Time updated: Mon, 31 Aug 2020 23:12:43 GMT
15-
Metageneration: 14
14+
Time updated: Thu, 15 Jul 2021 22:39:48 GMT
15+
Metageneration: 20
1616
Bucket Policy Only enabled: True
1717
ACL: []
1818
Default ACL: []

audit/projects/k8s-release/buckets/k8s-release-pull/iam.json

Lines changed: 4 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -3,6 +3,7 @@
33
{
44
"members": [
55
6+
67
"projectEditor:k8s-release",
78
"projectOwner:k8s-release"
89
],
@@ -19,15 +20,18 @@
1920
"members": [
2021
2122
23+
"serviceAccount:[email protected]",
2224
"serviceAccount:[email protected]"
2325
],
2426
"role": "roles/storage.legacyBucketWriter"
2527
},
2628
{
2729
"members": [
2830
31+
2932
3033
34+
"serviceAccount:[email protected]",
3135
"serviceAccount:project-304687256732@storage-transfer-service.iam.gserviceaccount.com",
3236
"serviceAccount:[email protected]"
3337
],
Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1 @@
1+
{"logBucket": "k8s-infra-artifacts-gcslogs", "logObjectPrefix": "k8s-release-pull"}

audit/projects/k8s-release/buckets/k8s-release-pull/metadata.txt

Lines changed: 3 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -3,16 +3,16 @@ gs://k8s-release-pull/ :
33
Location type: multi-region
44
Location constraint: US
55
Versioning enabled: None
6-
Logging configuration: None
6+
Logging configuration: Present
77
Website configuration: None
88
CORS configuration: None
99
Lifecycle configuration: Present
1010
Requester Pays enabled: None
1111
Labels: None
1212
Default KMS key: None
1313
Time created: Tue, 04 Aug 2020 20:14:16 GMT
14-
Time updated: Fri, 08 Jan 2021 21:10:11 GMT
15-
Metageneration: 15
14+
Time updated: Thu, 15 Jul 2021 22:41:28 GMT
15+
Metageneration: 21
1616
Bucket Policy Only enabled: True
1717
ACL: []
1818
Default ACL: []

audit/projects/k8s-release/buckets/k8s-release/metadata.txt

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -11,8 +11,8 @@ gs://k8s-release/ :
1111
Labels: None
1212
Default KMS key: None
1313
Time created: Fri, 07 Aug 2020 20:50:17 GMT
14-
Time updated: Fri, 07 Aug 2020 20:50:37 GMT
15-
Metageneration: 9
14+
Time updated: Thu, 15 Jul 2021 23:25:55 GMT
15+
Metageneration: 12
1616
Bucket Policy Only enabled: True
1717
ACL: []
1818
Default ACL: []

audit/projects/k8s-release/iam.json

Lines changed: 6 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -38,6 +38,12 @@
3838
],
3939
"role": "roles/containeranalysis.ServiceAgent"
4040
},
41+
{
42+
"members": [
43+
"serviceAccount:[email protected]"
44+
],
45+
"role": "roles/containerregistry.ServiceAgent"
46+
},
4147
{
4248
"members": [
4349
"serviceAccount:service-304687256732@gcp-sa-containerscanning.iam.gserviceaccount.com"

audit/projects/k8s-release/services/enabled.txt

Lines changed: 0 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -3,7 +3,6 @@ cloudbuild.googleapis.com Cloud Build API
33
cloudkms.googleapis.com Cloud Key Management Service (KMS) API
44
containeranalysis.googleapis.com Container Analysis API
55
containerregistry.googleapis.com Container Registry API
6-
containerscanning.googleapis.com Container Scanning API
76
logging.googleapis.com Cloud Logging API
87
monitoring.googleapis.com Cloud Monitoring API
98
pubsub.googleapis.com Cloud Pub/Sub API
Lines changed: 4 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -1 +1,4 @@
1-
[]
1+
[
2+
"projects/k8s-release/logs/cloudaudit.googleapis.com%2Factivity",
3+
"projects/k8s-release/logs/cloudaudit.googleapis.com%2Fsystem_event"
4+
]
Lines changed: 0 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -1,7 +1,6 @@
11
[
22
"projects/k8s-staging-cluster-api-gcp/logs/cloudaudit.googleapis.com%2Factivity",
33
"projects/k8s-staging-cluster-api-gcp/logs/cloudaudit.googleapis.com%2Fdata_access",
4-
"projects/k8s-staging-cluster-api-gcp/logs/cloudaudit.googleapis.com%2Fsystem_event",
54
"projects/k8s-staging-cluster-api-gcp/logs/cloudbuild",
65
"projects/k8s-staging-cluster-api-gcp/logs/compute.googleapis.com%2Fshielded_vm_integrity"
76
]

audit/projects/kubernetes-public/iam.json

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -123,7 +123,7 @@
123123
},
124124
{
125125
"members": [
126-
"serviceAccount:service-127754664067@serverless-robot-prod.iam.gserviceaccount.com"
126+
"deleted:serviceAccount:service-127754664067@serverless-robot-prod.iam.gserviceaccount.com?uid=118182660088477675409"
127127
],
128128
"role": "roles/run.serviceAgent"
129129
},

audit/projects/kubernetes-public/services/container/clusters/aaa.json

Lines changed: 3 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -37,7 +37,7 @@
3737
"clusterIpv4Cidr": "10.40.0.0/14",
3838
"createTime": "2019-09-18T23:39:24+00:00",
3939
"currentMasterVersion": "1.19.9-gke.1900",
40-
"currentNodeVersion": "1.18.17-gke.1901 *",
40+
"currentNodeVersion": "1.19.9-gke.1900",
4141
"databaseEncryption": {
4242
"state": "DECRYPTED"
4343
},
@@ -168,7 +168,7 @@
168168
"upgradeSettings": {
169169
"maxSurge": 1
170170
},
171-
"version": "1.18.17-gke.1901"
171+
"version": "1.19.9-gke.1900"
172172
},
173173
{
174174
"autoscaling": {
@@ -219,7 +219,7 @@
219219
"upgradeSettings": {
220220
"maxSurge": 1
221221
},
222-
"version": "1.18.17-gke.1901"
222+
"version": "1.19.9-gke.1900"
223223
}
224224
],
225225
"releaseChannel": {

0 commit comments

Comments
 (0)