@@ -16,7 +16,7 @@ kind: IAMPolicyMember
1616metadata :
1717 name : security-admins-org-policy
1818 annotations :
19- cnrm.cloud.google.com/blueprint : cnrm/org-iam/v0.4 .0
19+ cnrm.cloud.google.com/blueprint : cnrm/org-iam/v0.1 .0
2020 blueprints.cloud.google.com/description : This grants permission to set organizational policy constraints.
2121 namespace : config-control
2222spec :
@@ -32,7 +32,7 @@ kind: IAMPolicyMember
3232metadata :
3333 name : security-admins-security-reviewer
3434 annotations :
35- cnrm.cloud.google.com/blueprint : cnrm/org-iam/v0.4 .0
35+ cnrm.cloud.google.com/blueprint : cnrm/org-iam/v0.1 .0
3636 blueprints.cloud.google.com/description : This grants permissions to view all resources for the organization, and to view the IAM policies that apply to them.
3737 namespace : config-control
3838spec :
@@ -48,7 +48,7 @@ kind: IAMPolicyMember
4848metadata :
4949 name : security-admins-custom-roles
5050 annotations :
51- cnrm.cloud.google.com/blueprint : cnrm/org-iam/v0.4 .0
51+ cnrm.cloud.google.com/blueprint : cnrm/org-iam/v0.1 .0
5252 blueprints.cloud.google.com/description : This grants permissions to view all custom IAM roles in the organization, and to view the projects that they apply to.
5353 namespace : config-control
5454spec :
@@ -64,7 +64,7 @@ kind: IAMPolicyMember
6464metadata :
6565 name : security-admins-scc
6666 annotations :
67- cnrm.cloud.google.com/blueprint : cnrm/org-iam/v0.4 .0
67+ cnrm.cloud.google.com/blueprint : cnrm/org-iam/v0.1 .0
6868 blueprints.cloud.google.com/description : This grants administrator access to the Security Command Center.
6969 namespace : config-control
7070spec :
@@ -80,7 +80,7 @@ kind: IAMPolicyMember
8080metadata :
8181 name : security-admins-folder-iam
8282 annotations :
83- cnrm.cloud.google.com/blueprint : cnrm/org-iam/v0.4 .0
83+ cnrm.cloud.google.com/blueprint : cnrm/org-iam/v0.1 .0
8484 blueprints.cloud.google.com/description : This grants permissions to set folder-level IAM policies.
8585 namespace : config-control
8686spec :
@@ -96,7 +96,7 @@ kind: IAMPolicyMember
9696metadata :
9797 name : security-admins-private-logs
9898 annotations :
99- cnrm.cloud.google.com/blueprint : cnrm/org-iam/v0.4 .0
99+ cnrm.cloud.google.com/blueprint : cnrm/org-iam/v0.1 .0
100100 blueprints.cloud.google.com/description : This grants read-only access to Cloud Logging features, including the ability to read private logs.
101101 namespace : config-control
102102spec :
@@ -112,7 +112,7 @@ kind: IAMPolicyMember
112112metadata :
113113 name : security-admins-log-config
114114 annotations :
115- cnrm.cloud.google.com/blueprint : cnrm/org-iam/v0.4 .0
115+ cnrm.cloud.google.com/blueprint : cnrm/org-iam/v0.1 .0
116116 blueprints.cloud.google.com/description : This grants permissions to create logs-based metrics and export sinks.
117117 namespace : config-control
118118spec :
@@ -128,7 +128,7 @@ kind: IAMPolicyMember
128128metadata :
129129 name : security-admins-gke
130130 annotations :
131- cnrm.cloud.google.com/blueprint : cnrm/org-iam/v0.4 .0
131+ cnrm.cloud.google.com/blueprint : cnrm/org-iam/v0.1 .0
132132 blueprints.cloud.google.com/description : This grants read-only access to Google Kubernetes Engine resources.
133133 namespace : config-control
134134spec :
@@ -144,7 +144,7 @@ kind: IAMPolicyMember
144144metadata :
145145 name : security-admins-gce
146146 annotations :
147- cnrm.cloud.google.com/blueprint : cnrm/org-iam/v0.4 .0
147+ cnrm.cloud.google.com/blueprint : cnrm/org-iam/v0.1 .0
148148 blueprints.cloud.google.com/description : This grants read-only access to Compute Engine resources.
149149 namespace : config-control
150150spec :
@@ -160,7 +160,7 @@ kind: IAMPolicyMember
160160metadata :
161161 name : security-admins-bq
162162 annotations :
163- cnrm.cloud.google.com/blueprint : cnrm/org-iam/v0.4 .0
163+ cnrm.cloud.google.com/blueprint : cnrm/org-iam/v0.1 .0
164164 blueprints.cloud.google.com/description : This grants read-only access to BigQuery datasets.
165165 namespace : config-control
166166spec :
0 commit comments