Skip to content

Commit be94640

Browse files
committed
audit: update as of 2021-07-14
1 parent 3d2e8f2 commit be94640

File tree

33 files changed

+302
-31
lines changed

33 files changed

+302
-31
lines changed

audit/projects/k8s-artifacts-prod/services/logging/logs.json

Lines changed: 0 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -1,7 +1,5 @@
11
[
22
"projects/k8s-artifacts-prod/logs/cip-audit-log",
3-
"projects/k8s-artifacts-prod/logs/cloudaudit.googleapis.com%2Factivity",
4-
"projects/k8s-artifacts-prod/logs/cloudaudit.googleapis.com%2Fsystem_event",
53
"projects/k8s-artifacts-prod/logs/requests",
64
"projects/k8s-artifacts-prod/logs/run.googleapis.com%2Frequests",
75
"projects/k8s-artifacts-prod/logs/run.googleapis.com%2Fstderr"
Lines changed: 0 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -1,4 +1,3 @@
11
[
2-
"projects/k8s-cip-test-prod/logs/cloudaudit.googleapis.com%2Factivity",
32
"projects/k8s-cip-test-prod/logs/cloudaudit.googleapis.com%2Fsystem_event"
43
]

audit/projects/k8s-release/buckets/k8s-release-dev-asia/iam.json

Lines changed: 4 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -3,6 +3,7 @@
33
{
44
"members": [
55
6+
67
"projectEditor:k8s-release",
78
"projectOwner:k8s-release"
89
],
@@ -18,15 +19,18 @@
1819
"members": [
1920
2021
22+
"serviceAccount:[email protected]",
2123
"serviceAccount:[email protected]"
2224
],
2325
"role": "roles/storage.legacyBucketWriter"
2426
},
2527
{
2628
"members": [
2729
30+
2831
2932
33+
"serviceAccount:[email protected]",
3034
"serviceAccount:[email protected]"
3135
],
3236
"role": "roles/storage.objectAdmin"
Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1 @@
1+
{"rule": [{"action": {"type": "Delete"}, "condition": {"age": 90}}]}
Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1 @@
1+
{"logBucket": "k8s-infra-artifacts-gcslogs", "logObjectPrefix": "k8s-release-dev-asia"}

audit/projects/k8s-release/buckets/k8s-release-dev-asia/metadata.txt

Lines changed: 4 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -3,16 +3,16 @@ gs://k8s-release-dev-asia/ :
33
Location type: multi-region
44
Location constraint: US
55
Versioning enabled: None
6-
Logging configuration: None
6+
Logging configuration: Present
77
Website configuration: None
88
CORS configuration: None
9-
Lifecycle configuration: None
9+
Lifecycle configuration: Present
1010
Requester Pays enabled: None
1111
Labels: None
1212
Default KMS key: None
1313
Time created: Mon, 31 Aug 2020 23:11:19 GMT
14-
Time updated: Mon, 31 Aug 2020 23:11:44 GMT
15-
Metageneration: 11
14+
Time updated: Tue, 13 Jul 2021 23:19:28 GMT
15+
Metageneration: 17
1616
Bucket Policy Only enabled: True
1717
ACL: []
1818
Default ACL: []

audit/projects/k8s-release/buckets/k8s-release-dev-eu/iam.json

Lines changed: 4 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -3,6 +3,7 @@
33
{
44
"members": [
55
6+
67
"projectEditor:k8s-release",
78
"projectOwner:k8s-release"
89
],
@@ -18,15 +19,18 @@
1819
"members": [
1920
2021
22+
"serviceAccount:[email protected]",
2123
"serviceAccount:[email protected]"
2224
],
2325
"role": "roles/storage.legacyBucketWriter"
2426
},
2527
{
2628
"members": [
2729
30+
2831
2932
33+
"serviceAccount:[email protected]",
3034
"serviceAccount:[email protected]"
3135
],
3236
"role": "roles/storage.objectAdmin"
Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1 @@
1+
{"rule": [{"action": {"type": "Delete"}, "condition": {"age": 90}}]}
Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1 @@
1+
{"logBucket": "k8s-infra-artifacts-gcslogs", "logObjectPrefix": "k8s-release-dev-eu"}

audit/projects/k8s-release/buckets/k8s-release-dev-eu/metadata.txt

Lines changed: 4 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -3,16 +3,16 @@ gs://k8s-release-dev-eu/ :
33
Location type: multi-region
44
Location constraint: US
55
Versioning enabled: None
6-
Logging configuration: None
6+
Logging configuration: Present
77
Website configuration: None
88
CORS configuration: None
9-
Lifecycle configuration: None
9+
Lifecycle configuration: Present
1010
Requester Pays enabled: None
1111
Labels: None
1212
Default KMS key: None
1313
Time created: Mon, 31 Aug 2020 23:11:48 GMT
14-
Time updated: Mon, 31 Aug 2020 23:12:12 GMT
15-
Metageneration: 11
14+
Time updated: Tue, 13 Jul 2021 23:20:14 GMT
15+
Metageneration: 17
1616
Bucket Policy Only enabled: True
1717
ACL: []
1818
Default ACL: []

audit/projects/k8s-release/buckets/k8s-release-dev/iam.json

Lines changed: 4 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -3,6 +3,7 @@
33
{
44
"members": [
55
6+
67
"projectEditor:k8s-release",
78
"projectOwner:k8s-release"
89
],
@@ -18,15 +19,18 @@
1819
"members": [
1920
2021
22+
"serviceAccount:[email protected]",
2123
"serviceAccount:[email protected]"
2224
],
2325
"role": "roles/storage.legacyBucketWriter"
2426
},
2527
{
2628
"members": [
2729
30+
2831
2932
33+
"serviceAccount:[email protected]",
3034
"serviceAccount:[email protected]"
3135
],
3236
"role": "roles/storage.objectAdmin"
Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1 @@
1+
{"logBucket": "k8s-infra-artifacts-gcslogs", "logObjectPrefix": "k8s-release-dev"}

audit/projects/k8s-release/buckets/k8s-release-dev/metadata.txt

Lines changed: 3 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -3,16 +3,16 @@ gs://k8s-release-dev/ :
33
Location type: multi-region
44
Location constraint: US
55
Versioning enabled: None
6-
Logging configuration: None
6+
Logging configuration: Present
77
Website configuration: None
88
CORS configuration: None
99
Lifecycle configuration: Present
1010
Requester Pays enabled: None
1111
Labels: None
1212
Default KMS key: None
1313
Time created: Tue, 04 Aug 2020 20:14:09 GMT
14-
Time updated: Mon, 31 Aug 2020 23:12:43 GMT
15-
Metageneration: 14
14+
Time updated: Tue, 13 Jul 2021 23:18:45 GMT
15+
Metageneration: 19
1616
Bucket Policy Only enabled: True
1717
ACL: []
1818
Default ACL: []

audit/projects/k8s-release/buckets/k8s-release-pull/iam.json

Lines changed: 4 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -3,6 +3,7 @@
33
{
44
"members": [
55
6+
67
"projectEditor:k8s-release",
78
"projectOwner:k8s-release"
89
],
@@ -19,15 +20,18 @@
1920
"members": [
2021
2122
23+
"serviceAccount:[email protected]",
2224
"serviceAccount:[email protected]"
2325
],
2426
"role": "roles/storage.legacyBucketWriter"
2527
},
2628
{
2729
"members": [
2830
31+
2932
3033
34+
"serviceAccount:[email protected]",
3135
"serviceAccount:project-304687256732@storage-transfer-service.iam.gserviceaccount.com",
3236
"serviceAccount:[email protected]"
3337
],
Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1 @@
1+
{"logBucket": "k8s-infra-artifacts-gcslogs", "logObjectPrefix": "k8s-release-pull"}

audit/projects/k8s-release/buckets/k8s-release-pull/metadata.txt

Lines changed: 3 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -3,16 +3,16 @@ gs://k8s-release-pull/ :
33
Location type: multi-region
44
Location constraint: US
55
Versioning enabled: None
6-
Logging configuration: None
6+
Logging configuration: Present
77
Website configuration: None
88
CORS configuration: None
99
Lifecycle configuration: Present
1010
Requester Pays enabled: None
1111
Labels: None
1212
Default KMS key: None
1313
Time created: Tue, 04 Aug 2020 20:14:16 GMT
14-
Time updated: Fri, 08 Jan 2021 21:10:11 GMT
15-
Metageneration: 15
14+
Time updated: Tue, 13 Jul 2021 23:20:59 GMT
15+
Metageneration: 20
1616
Bucket Policy Only enabled: True
1717
ACL: []
1818
Default ACL: []

audit/projects/k8s-release/buckets/k8s-release/iam.json

Lines changed: 4 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -10,7 +10,8 @@
1010
},
1111
{
1212
"members": [
13-
"projectViewer:k8s-release"
13+
"projectViewer:k8s-release",
14+
"serviceAccount:project-304687256732@storage-transfer-service.iam.gserviceaccount.com"
1415
],
1516
"role": "roles/storage.legacyBucketReader"
1617
},
@@ -25,7 +26,8 @@
2526
"members": [
2627
2728
28-
29+
30+
"serviceAccount:project-304687256732@storage-transfer-service.iam.gserviceaccount.com"
2931
],
3032
"role": "roles/storage.objectAdmin"
3133
},

audit/projects/k8s-release/buckets/k8s-release/metadata.txt

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -11,8 +11,8 @@ gs://k8s-release/ :
1111
Labels: None
1212
Default KMS key: None
1313
Time created: Fri, 07 Aug 2020 20:50:17 GMT
14-
Time updated: Fri, 07 Aug 2020 20:50:37 GMT
15-
Metageneration: 9
14+
Time updated: Fri, 09 Jul 2021 20:06:14 GMT
15+
Metageneration: 10
1616
Bucket Policy Only enabled: True
1717
ACL: []
1818
Default ACL: []

audit/projects/k8s-release/iam.json

Lines changed: 6 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -50,6 +50,12 @@
5050
],
5151
"role": "roles/editor"
5252
},
53+
{
54+
"members": [
55+
"serviceAccount:[email protected]"
56+
],
57+
"role": "roles/pubsub.editor"
58+
},
5359
{
5460
"members": [
5561
Lines changed: 3 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -1 +1,3 @@
1-
[]
1+
[
2+
"projects/k8s-release/logs/cloudaudit.googleapis.com%2Factivity"
3+
]
Lines changed: 39 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,39 @@
1+
{
2+
"bindings": [
3+
{
4+
"members": [
5+
6+
"projectEditor:k8s-releng-prod",
7+
"projectOwner:k8s-releng-prod"
8+
],
9+
"role": "roles/storage.legacyBucketOwner"
10+
},
11+
{
12+
"members": [
13+
"projectViewer:k8s-releng-prod"
14+
],
15+
"role": "roles/storage.legacyBucketReader"
16+
},
17+
{
18+
"members": [
19+
20+
21+
],
22+
"role": "roles/storage.legacyBucketWriter"
23+
},
24+
{
25+
"members": [
26+
27+
28+
29+
],
30+
"role": "roles/storage.objectAdmin"
31+
},
32+
{
33+
"members": [
34+
"allUsers"
35+
],
36+
"role": "roles/storage.objectViewer"
37+
}
38+
]
39+
}
Lines changed: 18 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,18 @@
1+
gs://artifacts.k8s-releng-prod.appspot.com/ :
2+
Storage class: STANDARD
3+
Location type: multi-region
4+
Location constraint: US
5+
Versioning enabled: None
6+
Logging configuration: None
7+
Website configuration: None
8+
CORS configuration: None
9+
Lifecycle configuration: None
10+
Requester Pays enabled: None
11+
Labels: None
12+
Default KMS key: None
13+
Time created: Tue, 13 Jul 2021 23:05:15 GMT
14+
Time updated: Tue, 13 Jul 2021 23:05:58 GMT
15+
Metageneration: 9
16+
Bucket Policy Only enabled: True
17+
ACL: []
18+
Default ACL: []
Lines changed: 46 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,46 @@
1+
{
2+
"bindings": [
3+
{
4+
"members": [
5+
6+
"projectEditor:k8s-releng-prod",
7+
"projectOwner:k8s-releng-prod"
8+
],
9+
"role": "roles/storage.legacyBucketOwner"
10+
},
11+
{
12+
"members": [
13+
"projectViewer:k8s-releng-prod"
14+
],
15+
"role": "roles/storage.legacyBucketReader"
16+
},
17+
{
18+
"members": [
19+
20+
21+
],
22+
"role": "roles/storage.legacyBucketWriter"
23+
},
24+
{
25+
"members": [
26+
27+
28+
29+
],
30+
"role": "roles/storage.objectAdmin"
31+
},
32+
{
33+
"members": [
34+
"serviceAccount:[email protected]"
35+
],
36+
"role": "roles/storage.objectCreator"
37+
},
38+
{
39+
"members": [
40+
"allUsers",
41+
"serviceAccount:[email protected]"
42+
],
43+
"role": "roles/storage.objectViewer"
44+
}
45+
]
46+
}
Lines changed: 18 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,18 @@
1+
gs://k8s-releng-prod-gcb/ :
2+
Storage class: STANDARD
3+
Location type: multi-region
4+
Location constraint: US
5+
Versioning enabled: None
6+
Logging configuration: None
7+
Website configuration: None
8+
CORS configuration: None
9+
Lifecycle configuration: None
10+
Requester Pays enabled: None
11+
Labels: None
12+
Default KMS key: None
13+
Time created: Tue, 13 Jul 2021 23:06:37 GMT
14+
Time updated: Tue, 13 Jul 2021 23:07:33 GMT
15+
Metageneration: 11
16+
Bucket Policy Only enabled: True
17+
ACL: []
18+
Default ACL: []

0 commit comments

Comments
 (0)