Skip to content

Commit c05edc6

Browse files
author
Kubernetes Prow Robot
committed
audit: update as of 2022-08-07
1 parent 3cf8552 commit c05edc6

File tree

290 files changed

+1714
-1172
lines changed

Some content is hidden

Large Commits have some content hidden by default. Use the searchbox below for content that may be hidden.

290 files changed

+1714
-1172
lines changed
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,18 @@
1+
[
2+
{
3+
"role": "WRITER",
4+
"specialGroup": "projectWriters"
5+
},
6+
{
7+
"role": "OWNER",
8+
"specialGroup": "projectOwners"
9+
},
10+
{
11+
"role": "OWNER",
12+
"userByEmail": "[email protected]"
13+
},
14+
{
15+
"role": "READER",
16+
"specialGroup": "projectReaders"
17+
}
18+
]

audit/projects/k8s-infra-ii-sandbox/services/bigquery/bigquery.datasets.json

Lines changed: 9 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -412,5 +412,14 @@
412412
"projectId": "k8s-infra-ii-sandbox"
413413
},
414414
"location": "US"
415+
},
416+
{
417+
"kind": "bigquery#dataset",
418+
"id": "k8s-infra-ii-sandbox:etl_script_generated_set_20220726",
419+
"datasetReference": {
420+
"datasetId": "etl_script_generated_set_20220726",
421+
"projectId": "k8s-infra-ii-sandbox"
422+
},
423+
"location": "US"
415424
}
416425
]

audit/projects/k8s-infra-oci-proxy-prod/services/logging/logs.json

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -1,5 +1,6 @@
11
[
22
"projects/k8s-infra-oci-proxy-prod/logs/cloudaudit.googleapis.com%2Factivity",
3+
"projects/k8s-infra-oci-proxy-prod/logs/cloudaudit.googleapis.com%2Fsystem_event",
34
"projects/k8s-infra-oci-proxy-prod/logs/requests",
45
"projects/k8s-infra-oci-proxy-prod/logs/run.googleapis.com%2Frequests",
56
"projects/k8s-infra-oci-proxy-prod/logs/run.googleapis.com%2Fstderr"
Lines changed: 10 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,10 @@
1+
{
2+
"createTime": "2022-08-02T17:43:54.580612Z",
3+
"labels": {
4+
"group": "sig-release"
5+
},
6+
"name": "projects/180382678033/secrets/registry-k8s-io-s3-writer",
7+
"replication": {
8+
"automatic": {}
9+
}
10+
}
Lines changed: 12 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,12 @@
1+
{
2+
"bindings": [
3+
{
4+
"members": [
5+
6+
7+
],
8+
"role": "roles/secretmanager.admin"
9+
}
10+
],
11+
"version": 1
12+
}
Lines changed: 32 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,32 @@
1+
[
2+
{
3+
"clientSpecifiedPayloadChecksum": true,
4+
"createTime": "2022-08-02T22:45:32.574869Z",
5+
"etag": "\"15e549dfbc2095\"",
6+
"name": "projects/180382678033/secrets/registry-k8s-io-s3-writer/versions/3",
7+
"replicationStatus": {
8+
"automatic": {}
9+
},
10+
"state": "ENABLED"
11+
},
12+
{
13+
"clientSpecifiedPayloadChecksum": true,
14+
"createTime": "2022-08-02T21:44:49.194237Z",
15+
"etag": "\"15e549dfd1b853\"",
16+
"name": "projects/180382678033/secrets/registry-k8s-io-s3-writer/versions/2",
17+
"replicationStatus": {
18+
"automatic": {}
19+
},
20+
"state": "DISABLED"
21+
},
22+
{
23+
"clientSpecifiedPayloadChecksum": true,
24+
"createTime": "2022-08-02T21:44:13.593562Z",
25+
"etag": "\"15e549dfd16c69\"",
26+
"name": "projects/180382678033/secrets/registry-k8s-io-s3-writer/versions/1",
27+
"replicationStatus": {
28+
"automatic": {}
29+
},
30+
"state": "DISABLED"
31+
}
32+
]
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,8 @@
1+
{
2+
"displayName": "write to gs://k8s-cve-feed",
3+
"email": "k8s-cve-feed@k8s-infra-prow-build-trusted.iam.gserviceaccount.com",
4+
"name": "projects/k8s-infra-prow-build-trusted/serviceAccounts/k8s-cve-feed@k8s-infra-prow-build-trusted.iam.gserviceaccount.com",
5+
"oauth2ClientId": "104220461166094006825",
6+
"projectId": "k8s-infra-prow-build-trusted",
7+
"uniqueId": "104220461166094006825"
8+
}
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,11 @@
1+
{
2+
"bindings": [
3+
{
4+
"members": [
5+
"serviceAccount:k8s-infra-prow-build-trusted.svc.id.goog[test-pods/k8s-cve-feed]"
6+
],
7+
"role": "roles/iam.workloadIdentityUser"
8+
}
9+
],
10+
"version": 1
11+
}

audit/projects/k8s-infra-prow-build-trusted/services/container/clusters/prow-build-trusted.json

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -20,8 +20,8 @@
2020
"binaryAuthorization": {},
2121
"clusterIpv4Cidr": "10.4.0.0/14",
2222
"createTime": "2020-04-30T23:44:46+00:00",
23-
"currentMasterVersion": "1.22.8-gke.202",
24-
"currentNodeVersion": "1.22.8-gke.202",
23+
"currentMasterVersion": "1.22.10-gke.600",
24+
"currentNodeVersion": "1.22.8-gke.202 *",
2525
"databaseEncryption": {
2626
"state": "DECRYPTED"
2727
},

audit/projects/k8s-infra-prow-build/services/container/clusters/prow-build.json

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -20,8 +20,8 @@
2020
"binaryAuthorization": {},
2121
"clusterIpv4Cidr": "10.32.0.0/14",
2222
"createTime": "2020-04-30T21:31:49+00:00",
23-
"currentMasterVersion": "1.22.8-gke.202",
24-
"currentNodeVersion": "1.22.8-gke.202",
23+
"currentMasterVersion": "1.22.10-gke.600",
24+
"currentNodeVersion": "1.22.8-gke.202 *",
2525
"databaseEncryption": {
2626
"state": "DECRYPTED"
2727
},

audit/projects/k8s-infra-prow-build/services/logging/logs.json

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -2,6 +2,7 @@
22
"projects/k8s-infra-prow-build/logs/GCEGuestAgent",
33
"projects/k8s-infra-prow-build/logs/OSConfigAgent",
44
"projects/k8s-infra-prow-build/logs/cloudaudit.googleapis.com%2Factivity",
5+
"projects/k8s-infra-prow-build/logs/cloudaudit.googleapis.com%2Fdata_access",
56
"projects/k8s-infra-prow-build/logs/cloudaudit.googleapis.com%2Fsystem_event",
67
"projects/k8s-infra-prow-build/logs/compute.googleapis.com%2Fshielded_vm_integrity",
78
"projects/k8s-infra-prow-build/logs/container-runtime",
Lines changed: 3 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -1 +1,3 @@
1-
[]
1+
[
2+
"projects/k8s-infra-public-pii/logs/cloudaudit.googleapis.com%2Fsystem_event"
3+
]

audit/projects/k8s-infra-sandbox-capg/iam.json

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -40,6 +40,7 @@
4040
{
4141
"members": [
4242
43+
"serviceAccount:[email protected]",
4344
4445
],
4546
"role": "roles/owner"
Lines changed: 8 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,8 @@
1+
{
2+
"displayName": "richard-capg",
3+
"email": "[email protected]",
4+
"name": "projects/k8s-infra-sandbox-capg/serviceAccounts/[email protected]",
5+
"oauth2ClientId": "100171940266561657278",
6+
"projectId": "k8s-infra-sandbox-capg",
7+
"uniqueId": "100171940266561657278"
8+
}
Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1 @@
1+
{}

audit/projects/k8s-staging-addon-manager/buckets/artifacts.k8s-staging-addon-manager.appspot.com/metadata.txt

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -11,8 +11,8 @@ gs://artifacts.k8s-staging-addon-manager.appspot.com/ :
1111
Labels: None
1212
Default KMS key: None
1313
Time created: Wed, 30 Sep 2020 15:49:57 GMT
14-
Time updated: Mon, 13 Jun 2022 22:52:33 GMT
15-
Metageneration: 24
14+
Time updated: Tue, 02 Aug 2022 14:12:30 GMT
15+
Metageneration: 28
1616
Bucket Policy Only enabled: True
1717
Public access prevention: inherited
1818
RPO: DEFAULT

audit/projects/k8s-staging-addon-manager/buckets/k8s-staging-addon-manager/metadata.txt

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -11,8 +11,8 @@ gs://k8s-staging-addon-manager/ :
1111
Labels: None
1212
Default KMS key: None
1313
Time created: Wed, 30 Sep 2020 15:50:33 GMT
14-
Time updated: Mon, 13 Jun 2022 22:52:54 GMT
15-
Metageneration: 25
14+
Time updated: Tue, 02 Aug 2022 14:12:51 GMT
15+
Metageneration: 29
1616
Bucket Policy Only enabled: True
1717
Public access prevention: inherited
1818
RPO: DEFAULT
Lines changed: 14 additions & 10 deletions
Original file line numberDiff line numberDiff line change
@@ -1,10 +1,14 @@
1-
NAME TITLE
2-
cloudbuild.googleapis.com Cloud Build API
3-
cloudkms.googleapis.com Cloud Key Management Service (KMS) API
4-
containerregistry.googleapis.com Container Registry API
5-
iamcredentials.googleapis.com IAM Service Account Credentials API
6-
logging.googleapis.com Cloud Logging API
7-
pubsub.googleapis.com Cloud Pub/Sub API
8-
secretmanager.googleapis.com Secret Manager API
9-
storage-api.googleapis.com Google Cloud Storage JSON API
10-
storage-component.googleapis.com Cloud Storage
1+
NAME TITLE
2+
artifactregistry.googleapis.com Artifact Registry API
3+
cloudasset.googleapis.com Cloud Asset API
4+
cloudbuild.googleapis.com Cloud Build API
5+
cloudkms.googleapis.com Cloud Key Management Service (KMS) API
6+
containerregistry.googleapis.com Container Registry API
7+
iam.googleapis.com Identity and Access Management (IAM) API
8+
iamcredentials.googleapis.com IAM Service Account Credentials API
9+
logging.googleapis.com Cloud Logging API
10+
policytroubleshooter.googleapis.com Policy Troubleshooter API
11+
pubsub.googleapis.com Cloud Pub/Sub API
12+
secretmanager.googleapis.com Secret Manager API
13+
storage-api.googleapis.com Google Cloud Storage JSON API
14+
storage-component.googleapis.com Cloud Storage
Lines changed: 3 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -1 +1,3 @@
1-
[]
1+
[
2+
"projects/k8s-staging-addon-manager/logs/cloudaudit.googleapis.com%2Factivity"
3+
]

audit/projects/k8s-staging-apisnoop/buckets/artifacts.k8s-staging-apisnoop.appspot.com/metadata.txt

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -11,8 +11,8 @@ gs://artifacts.k8s-staging-apisnoop.appspot.com/ :
1111
Labels: None
1212
Default KMS key: None
1313
Time created: Tue, 21 Jan 2020 18:12:15 GMT
14-
Time updated: Mon, 13 Jun 2022 22:53:48 GMT
15-
Metageneration: 28
14+
Time updated: Tue, 02 Aug 2022 14:14:08 GMT
15+
Metageneration: 32
1616
Bucket Policy Only enabled: True
1717
Public access prevention: inherited
1818
RPO: DEFAULT

audit/projects/k8s-staging-apisnoop/buckets/k8s-staging-apisnoop/metadata.txt

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -11,8 +11,8 @@ gs://k8s-staging-apisnoop/ :
1111
Labels: None
1212
Default KMS key: None
1313
Time created: Tue, 21 Jan 2020 18:13:00 GMT
14-
Time updated: Mon, 13 Jun 2022 22:54:09 GMT
15-
Metageneration: 40
14+
Time updated: Tue, 02 Aug 2022 14:14:29 GMT
15+
Metageneration: 44
1616
Bucket Policy Only enabled: True
1717
Public access prevention: inherited
1818
RPO: DEFAULT
Lines changed: 14 additions & 10 deletions
Original file line numberDiff line numberDiff line change
@@ -1,10 +1,14 @@
1-
NAME TITLE
2-
cloudbuild.googleapis.com Cloud Build API
3-
cloudkms.googleapis.com Cloud Key Management Service (KMS) API
4-
containerregistry.googleapis.com Container Registry API
5-
iamcredentials.googleapis.com IAM Service Account Credentials API
6-
logging.googleapis.com Cloud Logging API
7-
pubsub.googleapis.com Cloud Pub/Sub API
8-
secretmanager.googleapis.com Secret Manager API
9-
storage-api.googleapis.com Google Cloud Storage JSON API
10-
storage-component.googleapis.com Cloud Storage
1+
NAME TITLE
2+
artifactregistry.googleapis.com Artifact Registry API
3+
cloudasset.googleapis.com Cloud Asset API
4+
cloudbuild.googleapis.com Cloud Build API
5+
cloudkms.googleapis.com Cloud Key Management Service (KMS) API
6+
containerregistry.googleapis.com Container Registry API
7+
iam.googleapis.com Identity and Access Management (IAM) API
8+
iamcredentials.googleapis.com IAM Service Account Credentials API
9+
logging.googleapis.com Cloud Logging API
10+
policytroubleshooter.googleapis.com Policy Troubleshooter API
11+
pubsub.googleapis.com Cloud Pub/Sub API
12+
secretmanager.googleapis.com Secret Manager API
13+
storage-api.googleapis.com Google Cloud Storage JSON API
14+
storage-component.googleapis.com Cloud Storage

audit/projects/k8s-staging-artifact-promoter/buckets/artifacts.k8s-staging-artifact-promoter.appspot.com/metadata.txt

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -11,8 +11,8 @@ gs://artifacts.k8s-staging-artifact-promoter.appspot.com/ :
1111
Labels: None
1212
Default KMS key: None
1313
Time created: Tue, 20 Aug 2019 00:06:52 GMT
14-
Time updated: Mon, 13 Jun 2022 22:55:03 GMT
15-
Metageneration: 28
14+
Time updated: Tue, 02 Aug 2022 14:15:46 GMT
15+
Metageneration: 32
1616
Bucket Policy Only enabled: True
1717
Public access prevention: inherited
1818
RPO: DEFAULT

audit/projects/k8s-staging-artifact-promoter/buckets/k8s-staging-artifact-promoter/metadata.txt

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -11,8 +11,8 @@ gs://k8s-staging-artifact-promoter/ :
1111
Labels: None
1212
Default KMS key: None
1313
Time created: Tue, 20 Aug 2019 00:07:32 GMT
14-
Time updated: Mon, 13 Jun 2022 22:55:24 GMT
15-
Metageneration: 43
14+
Time updated: Tue, 02 Aug 2022 14:16:10 GMT
15+
Metageneration: 47
1616
Bucket Policy Only enabled: True
1717
Public access prevention: inherited
1818
RPO: DEFAULT
Lines changed: 14 additions & 11 deletions
Original file line numberDiff line numberDiff line change
@@ -1,11 +1,14 @@
1-
NAME TITLE
2-
artifactregistry.googleapis.com Artifact Registry API
3-
cloudbuild.googleapis.com Cloud Build API
4-
cloudkms.googleapis.com Cloud Key Management Service (KMS) API
5-
containerregistry.googleapis.com Container Registry API
6-
iamcredentials.googleapis.com IAM Service Account Credentials API
7-
logging.googleapis.com Cloud Logging API
8-
pubsub.googleapis.com Cloud Pub/Sub API
9-
secretmanager.googleapis.com Secret Manager API
10-
storage-api.googleapis.com Google Cloud Storage JSON API
11-
storage-component.googleapis.com Cloud Storage
1+
NAME TITLE
2+
artifactregistry.googleapis.com Artifact Registry API
3+
cloudasset.googleapis.com Cloud Asset API
4+
cloudbuild.googleapis.com Cloud Build API
5+
cloudkms.googleapis.com Cloud Key Management Service (KMS) API
6+
containerregistry.googleapis.com Container Registry API
7+
iam.googleapis.com Identity and Access Management (IAM) API
8+
iamcredentials.googleapis.com IAM Service Account Credentials API
9+
logging.googleapis.com Cloud Logging API
10+
policytroubleshooter.googleapis.com Policy Troubleshooter API
11+
pubsub.googleapis.com Cloud Pub/Sub API
12+
secretmanager.googleapis.com Secret Manager API
13+
storage-api.googleapis.com Google Cloud Storage JSON API
14+
storage-component.googleapis.com Cloud Storage

audit/projects/k8s-staging-autoscaling/buckets/artifacts.k8s-staging-autoscaling.appspot.com/metadata.txt

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -11,8 +11,8 @@ gs://artifacts.k8s-staging-autoscaling.appspot.com/ :
1111
Labels: None
1212
Default KMS key: None
1313
Time created: Fri, 20 Mar 2020 19:00:58 GMT
14-
Time updated: Mon, 13 Jun 2022 22:56:19 GMT
15-
Metageneration: 26
14+
Time updated: Tue, 02 Aug 2022 14:17:28 GMT
15+
Metageneration: 30
1616
Bucket Policy Only enabled: True
1717
Public access prevention: inherited
1818
RPO: DEFAULT

audit/projects/k8s-staging-autoscaling/buckets/k8s-staging-autoscaling/metadata.txt

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -11,8 +11,8 @@ gs://k8s-staging-autoscaling/ :
1111
Labels: None
1212
Default KMS key: None
1313
Time created: Fri, 20 Mar 2020 19:01:48 GMT
14-
Time updated: Mon, 13 Jun 2022 22:56:40 GMT
15-
Metageneration: 37
14+
Time updated: Tue, 02 Aug 2022 14:17:49 GMT
15+
Metageneration: 41
1616
Bucket Policy Only enabled: True
1717
Public access prevention: inherited
1818
RPO: DEFAULT
Lines changed: 14 additions & 10 deletions
Original file line numberDiff line numberDiff line change
@@ -1,10 +1,14 @@
1-
NAME TITLE
2-
cloudbuild.googleapis.com Cloud Build API
3-
cloudkms.googleapis.com Cloud Key Management Service (KMS) API
4-
containerregistry.googleapis.com Container Registry API
5-
iamcredentials.googleapis.com IAM Service Account Credentials API
6-
logging.googleapis.com Cloud Logging API
7-
pubsub.googleapis.com Cloud Pub/Sub API
8-
secretmanager.googleapis.com Secret Manager API
9-
storage-api.googleapis.com Google Cloud Storage JSON API
10-
storage-component.googleapis.com Cloud Storage
1+
NAME TITLE
2+
artifactregistry.googleapis.com Artifact Registry API
3+
cloudasset.googleapis.com Cloud Asset API
4+
cloudbuild.googleapis.com Cloud Build API
5+
cloudkms.googleapis.com Cloud Key Management Service (KMS) API
6+
containerregistry.googleapis.com Container Registry API
7+
iam.googleapis.com Identity and Access Management (IAM) API
8+
iamcredentials.googleapis.com IAM Service Account Credentials API
9+
logging.googleapis.com Cloud Logging API
10+
policytroubleshooter.googleapis.com Policy Troubleshooter API
11+
pubsub.googleapis.com Cloud Pub/Sub API
12+
secretmanager.googleapis.com Secret Manager API
13+
storage-api.googleapis.com Google Cloud Storage JSON API
14+
storage-component.googleapis.com Cloud Storage
Lines changed: 3 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -1 +1,3 @@
1-
[]
1+
[
2+
"projects/k8s-staging-autoscaling/logs/cloudaudit.googleapis.com%2Factivity"
3+
]

audit/projects/k8s-staging-bom/buckets/artifacts.k8s-staging-bom.appspot.com/metadata.txt

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -11,8 +11,8 @@ gs://artifacts.k8s-staging-bom.appspot.com/ :
1111
Labels: None
1212
Default KMS key: None
1313
Time created: Wed, 09 Feb 2022 10:25:24 GMT
14-
Time updated: Mon, 13 Jun 2022 22:57:34 GMT
15-
Metageneration: 12
14+
Time updated: Tue, 02 Aug 2022 14:19:07 GMT
15+
Metageneration: 16
1616
Bucket Policy Only enabled: True
1717
Public access prevention: inherited
1818
RPO: DEFAULT

audit/projects/k8s-staging-bom/buckets/k8s-staging-bom/metadata.txt

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -11,8 +11,8 @@ gs://k8s-staging-bom/ :
1111
Labels: None
1212
Default KMS key: None
1313
Time created: Wed, 09 Feb 2022 10:26:20 GMT
14-
Time updated: Mon, 13 Jun 2022 22:57:55 GMT
15-
Metageneration: 13
14+
Time updated: Tue, 02 Aug 2022 14:19:28 GMT
15+
Metageneration: 17
1616
Bucket Policy Only enabled: True
1717
Public access prevention: inherited
1818
RPO: DEFAULT

0 commit comments

Comments
 (0)