-
Notifications
You must be signed in to change notification settings - Fork 828
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
audit as of 2020-02-17 #1676
Closed
Closed
audit as of 2020-02-17 #1676
Changes from 1 commit
Commits
Show all changes
18 commits
Select commit
Hold shift + click to select a range
a9efe55
audit: add psharma to org admins
spiffxp f8a9628
audit: add psharma as owner to kubernetes-public
spiffxp f0d0b63
audit: update gcp-auditor org-scoped roles
spiffxp 98667b8
audit: add XPN_SERVICE_PROJECTS quota
spiffxp a3f2812
audit: add k8s-staging-releng-test
spiffxp a25f038
audit: add k8s-staging-provider-openstack
spiffxp 619e515
audit: add k8s-staging-experimental
spiffxp acfc2fd
audit: remove windows-remote-docker secrets
spiffxp 96f3b66
audit: add cncf-ci-github-token secret
spiffxp f56650d
audit: remove k8s-staging-e2e-test
spiffxp 5552dae
audit: remove k8s-artifacts-prod-vulndash bucket
spiffxp 176f6e3
audit: setup k8s-conform for provider-openstack
spiffxp 95d847e
audit: enable GCR for e2e projects
spiffxp 0ec345d
audit: evidence of some e2e projects using GCR
spiffxp a4b8700
audit: QQ add kubernetes-staging buckets to e2e projects
spiffxp ac803bc
audit: gke cluster maintenance noise
spiffxp 2e29d26
audit: dns service appears to have dropped a quota
spiffxp b7d200f
audit: WELP I deleted a thing I shouldn't have
spiffxp File filter
Filter by extension
Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
There are no files selected for viewing
4 changes: 4 additions & 0 deletions
4
...enstack/buckets/artifacts.k8s-staging-provider-openstack.appspot.com/bucketpolicyonly.txt
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Original file line number | Diff line number | Diff line change |
---|---|---|
@@ -0,0 +1,4 @@ | ||
Bucket Policy Only setting for gs://artifacts.k8s-staging-provider-openstack.appspot.com: | ||
Enabled: True | ||
LockedTime: 2021-05-16 15:18:46.461000+00:00 | ||
|
1 change: 1 addition & 0 deletions
1
...-provider-openstack/buckets/artifacts.k8s-staging-provider-openstack.appspot.com/cors.txt
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Original file line number | Diff line number | Diff line change |
---|---|---|
@@ -0,0 +1 @@ | ||
gs://artifacts.k8s-staging-provider-openstack.appspot.com/ has no CORS configuration. |
37 changes: 37 additions & 0 deletions
37
...-provider-openstack/buckets/artifacts.k8s-staging-provider-openstack.appspot.com/iam.json
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Original file line number | Diff line number | Diff line change |
---|---|---|
@@ -0,0 +1,37 @@ | ||
{ | ||
"bindings": [ | ||
{ | ||
"members": [ | ||
"group:[email protected]", | ||
"projectEditor:k8s-staging-provider-openstack", | ||
"projectOwner:k8s-staging-provider-openstack" | ||
], | ||
"role": "roles/storage.legacyBucketOwner" | ||
}, | ||
{ | ||
"members": [ | ||
"projectViewer:k8s-staging-provider-openstack" | ||
], | ||
"role": "roles/storage.legacyBucketReader" | ||
}, | ||
{ | ||
"members": [ | ||
"group:[email protected]" | ||
], | ||
"role": "roles/storage.legacyBucketWriter" | ||
}, | ||
{ | ||
"members": [ | ||
"group:[email protected]", | ||
"group:[email protected]" | ||
], | ||
"role": "roles/storage.objectAdmin" | ||
}, | ||
{ | ||
"members": [ | ||
"allUsers" | ||
], | ||
"role": "roles/storage.objectViewer" | ||
} | ||
] | ||
} |
1 change: 1 addition & 0 deletions
1
...ovider-openstack/buckets/artifacts.k8s-staging-provider-openstack.appspot.com/logging.txt
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Original file line number | Diff line number | Diff line change |
---|---|---|
@@ -0,0 +1 @@ | ||
gs://artifacts.k8s-staging-provider-openstack.appspot.com/ has no logging configuration. |
4 changes: 4 additions & 0 deletions
4
...taging-provider-openstack/buckets/k8s-staging-provider-openstack-gcb/bucketpolicyonly.txt
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Original file line number | Diff line number | Diff line change |
---|---|---|
@@ -0,0 +1,4 @@ | ||
Bucket Policy Only setting for gs://k8s-staging-provider-openstack-gcb: | ||
Enabled: True | ||
LockedTime: 2021-05-16 15:19:21.741000+00:00 | ||
|
1 change: 1 addition & 0 deletions
1
...ojects/k8s-staging-provider-openstack/buckets/k8s-staging-provider-openstack-gcb/cors.txt
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Original file line number | Diff line number | Diff line change |
---|---|---|
@@ -0,0 +1 @@ | ||
gs://k8s-staging-provider-openstack-gcb/ has no CORS configuration. |
46 changes: 46 additions & 0 deletions
46
...ojects/k8s-staging-provider-openstack/buckets/k8s-staging-provider-openstack-gcb/iam.json
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Original file line number | Diff line number | Diff line change |
---|---|---|
@@ -0,0 +1,46 @@ | ||
{ | ||
"bindings": [ | ||
{ | ||
"members": [ | ||
"group:[email protected]", | ||
"projectEditor:k8s-staging-provider-openstack", | ||
"projectOwner:k8s-staging-provider-openstack" | ||
], | ||
"role": "roles/storage.legacyBucketOwner" | ||
}, | ||
{ | ||
"members": [ | ||
"projectViewer:k8s-staging-provider-openstack" | ||
], | ||
"role": "roles/storage.legacyBucketReader" | ||
}, | ||
{ | ||
"members": [ | ||
"group:[email protected]" | ||
], | ||
"role": "roles/storage.legacyBucketWriter" | ||
}, | ||
{ | ||
"members": [ | ||
"group:[email protected]", | ||
"group:[email protected]" | ||
], | ||
"role": "roles/storage.objectAdmin" | ||
}, | ||
{ | ||
"members": [ | ||
"serviceAccount:[email protected]", | ||
"serviceAccount:[email protected]" | ||
], | ||
"role": "roles/storage.objectCreator" | ||
}, | ||
{ | ||
"members": [ | ||
"allUsers", | ||
"serviceAccount:[email protected]", | ||
"serviceAccount:[email protected]" | ||
], | ||
"role": "roles/storage.objectViewer" | ||
} | ||
] | ||
} |
1 change: 1 addition & 0 deletions
1
...cts/k8s-staging-provider-openstack/buckets/k8s-staging-provider-openstack-gcb/logging.txt
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Original file line number | Diff line number | Diff line change |
---|---|---|
@@ -0,0 +1 @@ | ||
gs://k8s-staging-provider-openstack-gcb/ has no logging configuration. |
4 changes: 4 additions & 0 deletions
4
...8s-staging-provider-openstack/buckets/k8s-staging-provider-openstack/bucketpolicyonly.txt
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Original file line number | Diff line number | Diff line change |
---|---|---|
@@ -0,0 +1,4 @@ | ||
Bucket Policy Only setting for gs://k8s-staging-provider-openstack: | ||
Enabled: True | ||
LockedTime: 2021-05-16 15:19:04.941000+00:00 | ||
|
1 change: 1 addition & 0 deletions
1
...t/projects/k8s-staging-provider-openstack/buckets/k8s-staging-provider-openstack/cors.txt
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Original file line number | Diff line number | Diff line change |
---|---|---|
@@ -0,0 +1 @@ | ||
gs://k8s-staging-provider-openstack/ has no CORS configuration. |
37 changes: 37 additions & 0 deletions
37
...t/projects/k8s-staging-provider-openstack/buckets/k8s-staging-provider-openstack/iam.json
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Original file line number | Diff line number | Diff line change |
---|---|---|
@@ -0,0 +1,37 @@ | ||
{ | ||
"bindings": [ | ||
{ | ||
"members": [ | ||
"group:[email protected]", | ||
"projectEditor:k8s-staging-provider-openstack", | ||
"projectOwner:k8s-staging-provider-openstack" | ||
], | ||
"role": "roles/storage.legacyBucketOwner" | ||
}, | ||
{ | ||
"members": [ | ||
"projectViewer:k8s-staging-provider-openstack" | ||
], | ||
"role": "roles/storage.legacyBucketReader" | ||
}, | ||
{ | ||
"members": [ | ||
"group:[email protected]" | ||
], | ||
"role": "roles/storage.legacyBucketWriter" | ||
}, | ||
{ | ||
"members": [ | ||
"group:[email protected]", | ||
"group:[email protected]" | ||
], | ||
"role": "roles/storage.objectAdmin" | ||
}, | ||
{ | ||
"members": [ | ||
"allUsers" | ||
], | ||
"role": "roles/storage.objectViewer" | ||
} | ||
] | ||
} |
1 change: 1 addition & 0 deletions
1
...rojects/k8s-staging-provider-openstack/buckets/k8s-staging-provider-openstack/logging.txt
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Original file line number | Diff line number | Diff line change |
---|---|---|
@@ -0,0 +1 @@ | ||
gs://k8s-staging-provider-openstack/ has no logging configuration. |
11 changes: 11 additions & 0 deletions
11
audit/projects/k8s-staging-provider-openstack/description.json
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Original file line number | Diff line number | Diff line change |
---|---|---|
@@ -0,0 +1,11 @@ | ||
{ | ||
"createTime": "2021-02-15T15:12:50.913Z", | ||
"lifecycleState": "ACTIVE", | ||
"name": "k8s-staging-provider-openstack", | ||
"parent": { | ||
"id": "758905017065", | ||
"type": "organization" | ||
}, | ||
"projectId": "k8s-staging-provider-openstack", | ||
"projectNumber": "625174557286" | ||
} |
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Original file line number | Diff line number | Diff line change |
---|---|---|
@@ -0,0 +1,68 @@ | ||
{ | ||
"bindings": [ | ||
{ | ||
"members": [ | ||
"serviceAccount:[email protected]", | ||
"serviceAccount:[email protected]", | ||
"serviceAccount:[email protected]" | ||
], | ||
"role": "roles/cloudbuild.builds.builder" | ||
}, | ||
{ | ||
"members": [ | ||
"group:[email protected]" | ||
], | ||
"role": "roles/cloudbuild.builds.editor" | ||
}, | ||
{ | ||
"members": [ | ||
"serviceAccount:[email protected]" | ||
], | ||
"role": "roles/cloudbuild.serviceAgent" | ||
}, | ||
{ | ||
"members": [ | ||
"serviceAccount:[email protected]" | ||
], | ||
"role": "roles/containeranalysis.ServiceAgent" | ||
}, | ||
{ | ||
"members": [ | ||
"serviceAccount:k8s-infra-gcr-vuln-scanning@k8s-artifacts-prod.iam.gserviceaccount.com" | ||
], | ||
"role": "roles/containeranalysis.occurrences.viewer" | ||
}, | ||
{ | ||
"members": [ | ||
"serviceAccount:[email protected]" | ||
], | ||
"role": "roles/containerregistry.ServiceAgent" | ||
}, | ||
{ | ||
"members": [ | ||
"serviceAccount:service-625174557286@gcp-sa-containerscanning.iam.gserviceaccount.com" | ||
], | ||
"role": "roles/containerscanning.ServiceAgent" | ||
}, | ||
{ | ||
"members": [ | ||
"user:[email protected]" | ||
], | ||
"role": "roles/owner" | ||
}, | ||
{ | ||
"members": [ | ||
"group:[email protected]" | ||
], | ||
"role": "roles/serviceusage.serviceUsageConsumer" | ||
}, | ||
{ | ||
"members": [ | ||
"group:[email protected]", | ||
"group:[email protected]" | ||
], | ||
"role": "roles/viewer" | ||
} | ||
], | ||
"version": 1 | ||
} |
11 changes: 11 additions & 0 deletions
11
audit/projects/k8s-staging-provider-openstack/services/enabled.txt
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Original file line number | Diff line number | Diff line change |
---|---|---|
@@ -0,0 +1,11 @@ | ||
NAME TITLE | ||
cloudbuild.googleapis.com Cloud Build API | ||
cloudkms.googleapis.com Cloud Key Management Service (KMS) API | ||
containeranalysis.googleapis.com Container Analysis API | ||
containerregistry.googleapis.com Container Registry API | ||
containerscanning.googleapis.com Container Scanning API | ||
logging.googleapis.com Cloud Logging API | ||
pubsub.googleapis.com Cloud Pub/Sub API | ||
secretmanager.googleapis.com Secret Manager API | ||
storage-api.googleapis.com Google Cloud Storage JSON API | ||
storage-component.googleapis.com Cloud Storage |
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
I see no trace of this in the codebase? Why does it exist?
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
@dims 2/15/21
Explain?