Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

audit: update as of 2021-07-28 #2385

Merged
merged 1 commit into from
Jul 28, 2021
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
Original file line number Diff line number Diff line change
@@ -1,5 +1,4 @@
[
"projects/k8s-gcr-audit-test-prod/logs/cip-audit-log",
"projects/k8s-gcr-audit-test-prod/logs/cloudaudit.googleapis.com%2Factivity",
"projects/k8s-gcr-audit-test-prod/logs/cloudaudit.googleapis.com%2Fsystem_event",
"projects/k8s-gcr-audit-test-prod/logs/clouderrorreporting.googleapis.com%2Finsights",
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -3,7 +3,7 @@
"items": [
{
"key": "ssh-keys",
"value": "prow:ssh-rsa AAAAB3NzaC1yc2EAAAADAQABAAABAQCmYxHh/wwcV0P1aChuFLpl28w6DFyc7G5Xrw1F8wH1Re9AdxyemM2bTZ/PhsP3u9VDnNbyOw3UN00VFdumkFLjLf1WQ7Q6rZDlPjlw7urBIvAMqUecY6ae1znqsZ0dMBxOuPXHznlnjLjM5b7O7q5WsQMCA9Szbmz6DsuSyCuX0It2osBTN+8P/Fa6BNh3W8AF60M7L8/aUzLfbXVS2LIQKAHHD8CWqvXhLPuTJ03iSwFvgtAK1/J2XJwUP+OzAFrxj6A9LW5ZZgk3R3kRKr0xT/L7hga41rB1qy8Uz+Xr/PTVMNGW+nmU4bPgFchCK0JBK7B12ZcdVVFUEdpaAiKZ prow\nprow:prow:ssh-rsa AAAAB3NzaC1yc2EAAAADAQABAAABAQCmYxHh/wwcV0P1aChuFLpl28w6DFyc7G5Xrw1F8wH1Re9AdxyemM2bTZ/PhsP3u9VDnNbyOw3UN00VFdumkFLjLf1WQ7Q6rZDlPjlw7urBIvAMqUecY6ae1znqsZ0dMBxOuPXHznlnjLjM5b7O7q5WsQMCA9Szbmz6DsuSyCuX0It2osBTN+8P/Fa6BNh3W8AF60M7L8/aUzLfbXVS2LIQKAHHD8CWqvXhLPuTJ03iSwFvgtAK1/J2XJwUP+OzAFrxj6A9LW5ZZgk3R3kRKr0xT/L7hga41rB1qy8Uz+Xr/PTVMNGW+nmU4bPgFchCK0JBK7B12ZcdVVFUEdpaAiKZ prow\n"
"value": "prow:ssh-rsa AAAAB3NzaC1yc2EAAAADAQABAAABAQCmYxHh/wwcV0P1aChuFLpl28w6DFyc7G5Xrw1F8wH1Re9AdxyemM2bTZ/PhsP3u9VDnNbyOw3UN00VFdumkFLjLf1WQ7Q6rZDlPjlw7urBIvAMqUecY6ae1znqsZ0dMBxOuPXHznlnjLjM5b7O7q5WsQMCA9Szbmz6DsuSyCuX0It2osBTN+8P/Fa6BNh3W8AF60M7L8/aUzLfbXVS2LIQKAHHD8CWqvXhLPuTJ03iSwFvgtAK1/J2XJwUP+OzAFrxj6A9LW5ZZgk3R3kRKr0xT/L7hga41rB1qy8Uz+Xr/PTVMNGW+nmU4bPgFchCK0JBK7B12ZcdVVFUEdpaAiKZ prow\nprow:prow:ssh-rsa AAAAB3NzaC1yc2EAAAADAQABAAABAQCmYxHh/wwcV0P1aChuFLpl28w6DFyc7G5Xrw1F8wH1Re9AdxyemM2bTZ/PhsP3u9VDnNbyOw3UN00VFdumkFLjLf1WQ7Q6rZDlPjlw7urBIvAMqUecY6ae1znqsZ0dMBxOuPXHznlnjLjM5b7O7q5WsQMCA9Szbmz6DsuSyCuX0It2osBTN+8P/Fa6BNh3W8AF60M7L8/aUzLfbXVS2LIQKAHHD8CWqvXhLPuTJ03iSwFvgtAK1/J2XJwUP+OzAFrxj6A9LW5ZZgk3R3kRKr0xT/L7hga41rB1qy8Uz+Xr/PTVMNGW+nmU4bPgFchCK0JBK7B12ZcdVVFUEdpaAiKZ prow\nameukam:ssh-rsa AAAAB3NzaC1yc2EAAAADAQABAAABgQDIQxCxqIeW9zArVuqZ7WhkURWkcQdj+PVqzTdUb65joIxS0hWnYR6gpKtKOUlLw+YUUuAAvoUjl2MBNHU8R1ctJ7V0ISf6IEQuFZa7aS68bYy92gzH1QDpgHeyHlFbOrzZbLFWjebnKlT2wQL+29JB/5oYwY6RW1a+vas0rI6GiHLUu5rEUuLr38lGni9rhoQcidcDtEG7rG/nfa64ZrhDVeiUt0udmZaViXgrlLLTaJjnZTQ1sI5IuG42EEBpGDhHRkDwhAiLNjjVVkoBWDtPMyT/WbraoqShPzBMKhJz6NtS61cF2yMWIN+xZbJoPDJCcwzvQ9sYlcYrt2LEn75UEN+554lrBeQHjdwumiKjAzR/4m+kUHR9nm+a0li5TJUAmQ5K3pKD6ju2xcyrtzaQQ48FJm0y7fIET5dl4fQgLPj8hD9p/UwETF+9lV/XMH0EEyh0AoFWt/X/oDzH9/eBo7bn03Lugj3eYlvM1griu3OB8Iz5HA3oRw0H6JtdX7U= ameukam@barbatos\narnaudm:ssh-rsa AAAAB3NzaC1yc2EAAAADAQABAAABgQDIQxCxqIeW9zArVuqZ7WhkURWkcQdj+PVqzTdUb65joIxS0hWnYR6gpKtKOUlLw+YUUuAAvoUjl2MBNHU8R1ctJ7V0ISf6IEQuFZa7aS68bYy92gzH1QDpgHeyHlFbOrzZbLFWjebnKlT2wQL+29JB/5oYwY6RW1a+vas0rI6GiHLUu5rEUuLr38lGni9rhoQcidcDtEG7rG/nfa64ZrhDVeiUt0udmZaViXgrlLLTaJjnZTQ1sI5IuG42EEBpGDhHRkDwhAiLNjjVVkoBWDtPMyT/WbraoqShPzBMKhJz6NtS61cF2yMWIN+xZbJoPDJCcwzvQ9sYlcYrt2LEn75UEN+554lrBeQHjdwumiKjAzR/4m+kUHR9nm+a0li5TJUAmQ5K3pKD6ju2xcyrtzaQQ48FJm0y7fIET5dl4fQgLPj8hD9p/UwETF+9lV/XMH0EEyh0AoFWt/X/oDzH9/eBo7bn03Lugj3eYlvM1griu3OB8Iz5HA3oRw0H6JtdX7U= ameukam@barbatos\na.meukam:ssh-rsa AAAAB3NzaC1yc2EAAAADAQABAAABgQCdE4V5qmAAK8S9EqpuWIO3ZRXLPNOnLkgJboKOXvsgvUuE/96oaYTUZjo8tdovBsyx40q0quliylZB2X0yQ+LlbdnU9NUx/MrE6J98+05WYeJK/a+EjXwZv0lyTzl6ooDHZ+jEqUKaZ/rGaupFQU5pyFm1JZtJSdUrqQ2LLjbpcK3HGbWlt/TSjO//cJSx0J3aaf+PwqZBP3nAvcOQvnB+6hwmNha6FHvJPapiAb60/6QIrlWffrtVmGB+y2qBVaYdWZAP4iEKZKervFw/2x3+SyfTxwgp54kSok0ls1+xacQquTZR8Pj2wHwILE/9UkiUA7tZYK3nLguJGNs0Tqjzj1yykZdq3cJWq5XWtKBVtrghFboxtIJirlnD6wu3DqxfZwiqEOhRpEef0gH00rXCpMsuPur9rNSSeWHvRahqXIy5Ltq/Nl87WL3aJeUjlPk1ASRkKX+3WXZk6t6T+Lr4kJIzxWfFDxSXNKMRyMXi8hICLT9g5YLu42XLYmYI/bk= a.meukam@parprpmc012593a"
}
],
"kind": "compute#metadata"
Expand Down

This file was deleted.

This file was deleted.

This file was deleted.

This file was deleted.

Original file line number Diff line number Diff line change
@@ -1,22 +1,4 @@
[
{
"kind": "bigquery#dataset",
"id": "k8s-infra-ii-sandbox:etl_script_generated_set",
Copy link
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Manual suppression by @Riaankl : #1968 (comment)

"datasetReference": {
"datasetId": "etl_script_generated_set",
"projectId": "k8s-infra-ii-sandbox"
},
"location": "US"
},
{
"kind": "bigquery#dataset",
"id": "k8s-infra-ii-sandbox:etl_script_generated_set_1",
"datasetReference": {
"datasetId": "etl_script_generated_set_1",
"projectId": "k8s-infra-ii-sandbox"
},
"location": "US"
},
{
"kind": "bigquery#dataset",
"id": "k8s-infra-ii-sandbox:etl_script_generated_set_prod",
Expand All @@ -26,54 +8,6 @@
},
"location": "US"
},
{
"kind": "bigquery#dataset",
"id": "k8s-infra-ii-sandbox:etl_staging",
Copy link
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Manual suppression by @Riaankl : #1968 (comment)

"datasetReference": {
"datasetId": "etl_staging",
"projectId": "k8s-infra-ii-sandbox"
},
"location": "US"
},
{
"kind": "bigquery#dataset",
"id": "k8s-infra-ii-sandbox:hh",
"datasetReference": {
"datasetId": "hh",
"projectId": "k8s-infra-ii-sandbox"
},
"location": "US"
},
{
"kind": "bigquery#dataset",
"id": "k8s-infra-ii-sandbox:k8s_artifacts_dataset_bb_test",
Copy link
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Same here.

"datasetReference": {
"datasetId": "k8s_artifacts_dataset_bb_test",
"projectId": "k8s-infra-ii-sandbox"
},
"labels": {
"managed-by-cnrm": "true"
},
"location": "US"
},
{
"kind": "bigquery#dataset",
"id": "k8s-infra-ii-sandbox:k8s_artifacts_gcslogs_appspot",
Copy link
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Same here

"datasetReference": {
"datasetId": "k8s_artifacts_gcslogs_appspot",
"projectId": "k8s-infra-ii-sandbox"
},
"location": "US"
},
{
"kind": "bigquery#dataset",
"id": "k8s-infra-ii-sandbox:kubernetes_public_logs",
Copy link
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Same here

"datasetReference": {
"datasetId": "kubernetes_public_logs",
"projectId": "k8s-infra-ii-sandbox"
},
"location": "US"
},
{
"kind": "bigquery#dataset",
"id": "k8s-infra-ii-sandbox:riaan_data_store",
Expand Down

This file was deleted.

This file was deleted.

This file was deleted.

Original file line number Diff line number Diff line change
@@ -0,0 +1,10 @@
{
"createTime": "2021-07-22T15:22:42.229306Z",
"labels": {
"group": "sig-contributor-experience"
},
"name": "projects/180382678033/secrets/k8s-triage-robot-github-token",
Copy link
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

As expected by #2389

"replication": {
"automatic": {}
}
}
Original file line number Diff line number Diff line change
@@ -0,0 +1,12 @@
{
"bindings": [
{
"members": [
"group:[email protected]",
"group:[email protected]"
],
Comment on lines +4 to +7
Copy link
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

As expected by #2389

"role": "roles/secretmanager.admin"
}
],
"version": 1
}
Original file line number Diff line number Diff line change
@@ -0,0 +1,29 @@
[
{
"createTime": "2021-07-23T03:18:11.506633Z",
"etag": "\"15c7c1da789dc9\"",
"name": "projects/180382678033/secrets/k8s-triage-robot-github-token/versions/3",
Copy link
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

As expected by #2389. Only one version is used.

"replicationStatus": {
"automatic": {}
},
"state": "ENABLED"
},
{
"createTime": "2021-07-22T22:02:20.507249Z",
"etag": "\"15c7bd70e75071\"",
"name": "projects/180382678033/secrets/k8s-triage-robot-github-token/versions/2",
"replicationStatus": {
"automatic": {}
},
"state": "ENABLED"
},
{
"createTime": "2021-07-22T17:11:33.029513Z",
"etag": "\"15c7c1db001f02\"",
"name": "projects/180382678033/secrets/k8s-triage-robot-github-token/versions/1",
"replicationStatus": {
"automatic": {}
},
"state": "DISABLED"
}
]
17 changes: 17 additions & 0 deletions audit/projects/k8s-release/buckets/k8s-release-asia/iam.json
Original file line number Diff line number Diff line change
@@ -0,0 +1,17 @@
{
"bindings": [
{
"members": [
"projectEditor:k8s-release",
"projectOwner:k8s-release"
],
"role": "roles/storage.legacyBucketOwner"
},
{
"members": [
"projectViewer:k8s-release"
],
"role": "roles/storage.legacyBucketReader"
}
]
}
70 changes: 70 additions & 0 deletions audit/projects/k8s-release/buckets/k8s-release-asia/metadata.txt
Original file line number Diff line number Diff line change
@@ -0,0 +1,70 @@
gs://k8s-release-asia/ :
Copy link
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This was me claiming the bucket name by manually creating the bucket for #2396

Storage class: STANDARD
Location type: multi-region
Location constraint: US
Versioning enabled: None
Logging configuration: None
Website configuration: None
CORS configuration: None
Lifecycle configuration: None
Requester Pays enabled: None
Labels: None
Default KMS key: None
Time created: Mon, 26 Jul 2021 22:12:46 GMT
Time updated: Mon, 26 Jul 2021 22:12:46 GMT
Metageneration: 1
Bucket Policy Only enabled: False
ACL:
[
{
"entity": "project-owners-304687256732",
"projectTeam": {
"projectNumber": "304687256732",
"team": "owners"
},
"role": "OWNER"
},
{
"entity": "project-editors-304687256732",
"projectTeam": {
"projectNumber": "304687256732",
"team": "editors"
},
"role": "OWNER"
},
{
"entity": "project-viewers-304687256732",
"projectTeam": {
"projectNumber": "304687256732",
"team": "viewers"
},
"role": "READER"
}
]
Default ACL:
[
{
"entity": "project-owners-304687256732",
"projectTeam": {
"projectNumber": "304687256732",
"team": "owners"
},
"role": "OWNER"
},
{
"entity": "project-editors-304687256732",
"projectTeam": {
"projectNumber": "304687256732",
"team": "editors"
},
"role": "OWNER"
},
{
"entity": "project-viewers-304687256732",
"projectTeam": {
"projectNumber": "304687256732",
"team": "viewers"
},
"role": "READER"
}
]
17 changes: 17 additions & 0 deletions audit/projects/k8s-release/buckets/k8s-release-eu/iam.json
Original file line number Diff line number Diff line change
@@ -0,0 +1,17 @@
{
"bindings": [
{
"members": [
"projectEditor:k8s-release",
"projectOwner:k8s-release"
],
"role": "roles/storage.legacyBucketOwner"
},
{
"members": [
"projectViewer:k8s-release"
],
"role": "roles/storage.legacyBucketReader"
}
]
}
Loading