本文档介绍了 Design Center 的审核日志记录。 Google Cloud 服务会生成审核日志,以记录 Google Cloud 资源中的管理和访问活动。如需详细了解 Cloud Audit Logs,请参阅以下内容:
服务名称
Design Center 审核日志使用服务名称 designcenter.googleapis.com。针对此服务的过滤条件:
protoPayload.serviceName="designcenter.googleapis.com"
方法(按权限类型)
每个 IAM 权限都有一个 type 属性,该属性的值是一个枚举,可以是以下四个值之一:ADMIN_READ、ADMIN_WRITE、DATA_READ 或 DATA_WRITE。在您调用某个方法时,Design Center 会生成一个审核日志,其类别取决于执行该方法所需权限的 type 属性。需要 IAM 权限且 type 属性值为 DATA_READ、DATA_WRITE 或 ADMIN_READ 的方法会生成数据访问审核日志。需要 IAM 权限且 type 属性值为 ADMIN_WRITE 的方法会生成管理员活动审核日志。
| 权限类型 | 方法 |
|---|---|
ADMIN_READ |
google.cloud.designcenter.v1alpha.DesignCenter.DeployApplication (LRO)google.cloud.designcenter.v1alpha.DesignCenter.GenerateApplicationIaCgoogle.cloud.designcenter.v1alpha.DesignCenter.GenerateApplicationTemplateIaCgoogle.cloud.designcenter.v1alpha.DesignCenter.GetApplicationgoogle.cloud.designcenter.v1alpha.DesignCenter.GetApplicationTemplategoogle.cloud.designcenter.v1alpha.DesignCenter.GetApplicationTemplateRevisiongoogle.cloud.designcenter.v1alpha.DesignCenter.GetCataloggoogle.cloud.designcenter.v1alpha.DesignCenter.GetCatalogTemplategoogle.cloud.designcenter.v1alpha.DesignCenter.GetCatalogTemplateRevisiongoogle.cloud.designcenter.v1alpha.DesignCenter.GetSpacegoogle.cloud.designcenter.v1alpha.DesignCenter.ListApplicationTemplatesgoogle.cloud.designcenter.v1alpha.DesignCenter.ListApplicationsgoogle.cloud.designcenter.v1alpha.DesignCenter.ListCatalogsgoogle.cloud.designcenter.v1alpha.DesignCenter.PreviewApplication (LRO) |
ADMIN_WRITE |
google.cloud.designcenter.v1alpha.DesignCenter.CommitApplicationTemplategoogle.cloud.designcenter.v1alpha.DesignCenter.CreateApplicationgoogle.cloud.designcenter.v1alpha.DesignCenter.CreateApplicationTemplategoogle.cloud.designcenter.v1alpha.DesignCenter.CreateCatalogTemplategoogle.cloud.designcenter.v1alpha.DesignCenter.CreateCatalogTemplateRevision (LRO)google.cloud.designcenter.v1alpha.DesignCenter.CreateComponentgoogle.cloud.designcenter.v1alpha.DesignCenter.CreateConnectiongoogle.cloud.designcenter.v1alpha.DesignCenter.DeleteApplication (LRO)google.cloud.designcenter.v1alpha.DesignCenter.DeleteApplicationTemplategoogle.cloud.designcenter.v1alpha.DesignCenter.DeleteCatalogTemplate (LRO)google.cloud.designcenter.v1alpha.DesignCenter.DeleteComponentgoogle.cloud.designcenter.v1alpha.DesignCenter.DeleteConnectiongoogle.cloud.designcenter.v1alpha.DesignCenter.ImportApplicationTemplategoogle.cloud.designcenter.v1alpha.DesignCenter.UpdateApplicationgoogle.cloud.designcenter.v1alpha.DesignCenter.UpdateComponent |
API 接口审核日志
如需了解如何评估每种方法的权限以及评估哪些权限,请参阅 Design Center 的 Identity and Access Management 文档。
google.cloud.designcenter.v1alpha.DesignCenter
以下审核日志与属于 google.cloud.designcenter.v1alpha.DesignCenter 的方法相关联。
CommitApplicationTemplate
- 方法:
google.cloud.designcenter.v1alpha.DesignCenter.CommitApplicationTemplate - 审核日志类型:管理员活动
- 权限:
designcenter.applicationTemplates.update - ADMIN_WRITE
- 方法是长时间运行的操作或流式传输操作:否。
- 此方法的过滤条件:
protoPayload.methodName="google.cloud.designcenter.v1alpha.DesignCenter.CommitApplicationTemplate"
CreateApplication
- 方法:
google.cloud.designcenter.v1alpha.DesignCenter.CreateApplication - 审核日志类型:管理员活动
- 权限:
designcenter.applications.create - ADMIN_WRITE
- 方法是长时间运行的操作或流式传输操作:否。
- 此方法的过滤条件:
protoPayload.methodName="google.cloud.designcenter.v1alpha.DesignCenter.CreateApplication"
CreateApplicationTemplate
- 方法:
google.cloud.designcenter.v1alpha.DesignCenter.CreateApplicationTemplate - 审核日志类型:管理员活动
- 权限:
designcenter.applicationTemplates.create - ADMIN_WRITE
- 方法是长时间运行的操作或流式传输操作:否。
- 此方法的过滤条件:
protoPayload.methodName="google.cloud.designcenter.v1alpha.DesignCenter.CreateApplicationTemplate"
CreateCatalogTemplate
- 方法:
google.cloud.designcenter.v1alpha.DesignCenter.CreateCatalogTemplate - 审核日志类型:管理员活动
- 权限:
designcenter.catalogTemplates.create - ADMIN_WRITE
- 方法是长时间运行的操作或流式传输操作:否。
- 此方法的过滤条件:
protoPayload.methodName="google.cloud.designcenter.v1alpha.DesignCenter.CreateCatalogTemplate"
CreateCatalogTemplateRevision
- 方法:
google.cloud.designcenter.v1alpha.DesignCenter.CreateCatalogTemplateRevision - 审核日志类型:管理员活动
- 权限:
designcenter.catalogTemplateRevisions.create - ADMIN_WRITE
- 方法是长时间运行的操作或流式传输操作:长时间运行的操作
- 此方法的过滤条件:
protoPayload.methodName="google.cloud.designcenter.v1alpha.DesignCenter.CreateCatalogTemplateRevision"
CreateComponent
- 方法:
google.cloud.designcenter.v1alpha.DesignCenter.CreateComponent - 审核日志类型:管理员活动
- 权限:
designcenter.components.create - ADMIN_WRITE
- 方法是长时间运行的操作或流式传输操作:否。
- 此方法的过滤条件:
protoPayload.methodName="google.cloud.designcenter.v1alpha.DesignCenter.CreateComponent"
CreateConnection
- 方法:
google.cloud.designcenter.v1alpha.DesignCenter.CreateConnection - 审核日志类型:管理员活动
- 权限:
designcenter.connections.create - ADMIN_WRITE
- 方法是长时间运行的操作或流式传输操作:否。
- 此方法的过滤条件:
protoPayload.methodName="google.cloud.designcenter.v1alpha.DesignCenter.CreateConnection"
DeleteApplication
- 方法:
google.cloud.designcenter.v1alpha.DesignCenter.DeleteApplication - 审核日志类型:管理员活动
- 权限:
designcenter.applications.delete - ADMIN_WRITE
- 方法是长时间运行的操作或流式传输操作:长时间运行的操作
- 此方法的过滤条件:
protoPayload.methodName="google.cloud.designcenter.v1alpha.DesignCenter.DeleteApplication"
DeleteApplicationTemplate
- 方法:
google.cloud.designcenter.v1alpha.DesignCenter.DeleteApplicationTemplate - 审核日志类型:管理员活动
- 权限:
designcenter.applicationTemplates.delete - ADMIN_WRITE
- 方法是长时间运行的操作或流式传输操作:否。
- 此方法的过滤条件:
protoPayload.methodName="google.cloud.designcenter.v1alpha.DesignCenter.DeleteApplicationTemplate"
DeleteCatalogTemplate
- 方法:
google.cloud.designcenter.v1alpha.DesignCenter.DeleteCatalogTemplate - 审核日志类型:管理员活动
- 权限:
designcenter.catalogTemplates.delete - ADMIN_WRITE
- 方法是长时间运行的操作或流式传输操作:长时间运行的操作
- 此方法的过滤条件:
protoPayload.methodName="google.cloud.designcenter.v1alpha.DesignCenter.DeleteCatalogTemplate"
DeleteComponent
- 方法:
google.cloud.designcenter.v1alpha.DesignCenter.DeleteComponent - 审核日志类型:管理员活动
- 权限:
designcenter.components.delete - ADMIN_WRITE
- 方法是长时间运行的操作或流式传输操作:否。
- 此方法的过滤条件:
protoPayload.methodName="google.cloud.designcenter.v1alpha.DesignCenter.DeleteComponent"
DeleteConnection
- 方法:
google.cloud.designcenter.v1alpha.DesignCenter.DeleteConnection - 审核日志类型:管理员活动
- 权限:
designcenter.connections.delete - ADMIN_WRITE
- 方法是长时间运行的操作或流式传输操作:否。
- 此方法的过滤条件:
protoPayload.methodName="google.cloud.designcenter.v1alpha.DesignCenter.DeleteConnection"
DeployApplication
- 方法:
google.cloud.designcenter.v1alpha.DesignCenter.DeployApplication - 审核日志类型:数据访问
- 权限:
designcenter.applications.get - ADMIN_READ
- 方法是长时间运行的操作或流式传输操作:长时间运行的操作
- 此方法的过滤条件:
protoPayload.methodName="google.cloud.designcenter.v1alpha.DesignCenter.DeployApplication"
GenerateApplicationIaC
- 方法:
google.cloud.designcenter.v1alpha.DesignCenter.GenerateApplicationIaC - 审核日志类型:数据访问
- 权限:
designcenter.applications.get - ADMIN_READ
- 方法是长时间运行的操作或流式传输操作:否。
- 此方法的过滤条件:
protoPayload.methodName="google.cloud.designcenter.v1alpha.DesignCenter.GenerateApplicationIaC"
GenerateApplicationTemplateIaC
- 方法:
google.cloud.designcenter.v1alpha.DesignCenter.GenerateApplicationTemplateIaC - 审核日志类型:数据访问
- 权限:
designcenter.applicationTemplates.get - ADMIN_READ
- 方法是长时间运行的操作或流式传输操作:否。
- 此方法的过滤条件:
protoPayload.methodName="google.cloud.designcenter.v1alpha.DesignCenter.GenerateApplicationTemplateIaC"
GetApplication
- 方法:
google.cloud.designcenter.v1alpha.DesignCenter.GetApplication - 审核日志类型:数据访问
- 权限:
designcenter.applications.get - ADMIN_READ
- 方法是长时间运行的操作或流式传输操作:否。
- 此方法的过滤条件:
protoPayload.methodName="google.cloud.designcenter.v1alpha.DesignCenter.GetApplication"
GetApplicationTemplate
- 方法:
google.cloud.designcenter.v1alpha.DesignCenter.GetApplicationTemplate - 审核日志类型:数据访问
- 权限:
designcenter.applicationTemplates.get - ADMIN_READ
- 方法是长时间运行的操作或流式传输操作:否。
- 此方法的过滤条件:
protoPayload.methodName="google.cloud.designcenter.v1alpha.DesignCenter.GetApplicationTemplate"
GetApplicationTemplateRevision
- 方法:
google.cloud.designcenter.v1alpha.DesignCenter.GetApplicationTemplateRevision - 审核日志类型:数据访问
- 权限:
designcenter.applicationTemplateRevisions.get - ADMIN_READ
- 方法是长时间运行的操作或流式传输操作:否。
- 此方法的过滤条件:
protoPayload.methodName="google.cloud.designcenter.v1alpha.DesignCenter.GetApplicationTemplateRevision"
GetCatalog
- 方法:
google.cloud.designcenter.v1alpha.DesignCenter.GetCatalog - 审核日志类型:数据访问
- 权限:
designcenter.catalogs.get - ADMIN_READ
- 方法是长时间运行的操作或流式传输操作:否。
- 此方法的过滤条件:
protoPayload.methodName="google.cloud.designcenter.v1alpha.DesignCenter.GetCatalog"
GetCatalogTemplate
- 方法:
google.cloud.designcenter.v1alpha.DesignCenter.GetCatalogTemplate - 审核日志类型:数据访问
- 权限:
designcenter.catalogTemplates.get - ADMIN_READ
- 方法是长时间运行的操作或流式传输操作:否。
- 此方法的过滤条件:
protoPayload.methodName="google.cloud.designcenter.v1alpha.DesignCenter.GetCatalogTemplate"
GetCatalogTemplateRevision
- 方法:
google.cloud.designcenter.v1alpha.DesignCenter.GetCatalogTemplateRevision - 审核日志类型:数据访问
- 权限:
designcenter.catalogTemplateRevisions.get - ADMIN_READ
- 方法是长时间运行的操作或流式传输操作:否。
- 此方法的过滤条件:
protoPayload.methodName="google.cloud.designcenter.v1alpha.DesignCenter.GetCatalogTemplateRevision"
GetSpace
- 方法:
google.cloud.designcenter.v1alpha.DesignCenter.GetSpace - 审核日志类型:数据访问
- 权限:
designcenter.spaces.get - ADMIN_READ
- 方法是长时间运行的操作或流式传输操作:否。
- 此方法的过滤条件:
protoPayload.methodName="google.cloud.designcenter.v1alpha.DesignCenter.GetSpace"
ImportApplicationTemplate
- 方法:
google.cloud.designcenter.v1alpha.DesignCenter.ImportApplicationTemplate - 审核日志类型:管理员活动
- 权限:
designcenter.applicationTemplates.update - ADMIN_WRITE
- 方法是长时间运行的操作或流式传输操作:否。
- 此方法的过滤条件:
protoPayload.methodName="google.cloud.designcenter.v1alpha.DesignCenter.ImportApplicationTemplate"
ListApplicationTemplates
- 方法:
google.cloud.designcenter.v1alpha.DesignCenter.ListApplicationTemplates - 审核日志类型:数据访问
- 权限:
designcenter.applicationTemplates.list - ADMIN_READ
- 方法是长时间运行的操作或流式传输操作:否。
- 此方法的过滤条件:
protoPayload.methodName="google.cloud.designcenter.v1alpha.DesignCenter.ListApplicationTemplates"
ListApplications
- 方法:
google.cloud.designcenter.v1alpha.DesignCenter.ListApplications - 审核日志类型:数据访问
- 权限:
designcenter.applications.list - ADMIN_READ
- 方法是长时间运行的操作或流式传输操作:否。
- 此方法的过滤条件:
protoPayload.methodName="google.cloud.designcenter.v1alpha.DesignCenter.ListApplications"
ListCatalogs
- 方法:
google.cloud.designcenter.v1alpha.DesignCenter.ListCatalogs - 审核日志类型:数据访问
- 权限:
designcenter.catalogs.list - ADMIN_READ
- 方法是长时间运行的操作或流式传输操作:否。
- 此方法的过滤条件:
protoPayload.methodName="google.cloud.designcenter.v1alpha.DesignCenter.ListCatalogs"
PreviewApplication
- 方法:
google.cloud.designcenter.v1alpha.DesignCenter.PreviewApplication - 审核日志类型:数据访问
- 权限:
designcenter.applications.get - ADMIN_READ
- 方法是长时间运行的操作或流式传输操作:长时间运行的操作
- 此方法的过滤条件:
protoPayload.methodName="google.cloud.designcenter.v1alpha.DesignCenter.PreviewApplication"
UpdateApplication
- 方法:
google.cloud.designcenter.v1alpha.DesignCenter.UpdateApplication - 审核日志类型:管理员活动
- 权限:
designcenter.applications.update - ADMIN_WRITE
- 方法是长时间运行的操作或流式传输操作:否。
- 此方法的过滤条件:
protoPayload.methodName="google.cloud.designcenter.v1alpha.DesignCenter.UpdateApplication"
UpdateComponent
- 方法:
google.cloud.designcenter.v1alpha.DesignCenter.UpdateComponent - 审核日志类型:管理员活动
- 权限:
designcenter.components.update - ADMIN_WRITE
- 方法是长时间运行的操作或流式传输操作:否。
- 此方法的过滤条件:
protoPayload.methodName="google.cloud.designcenter.v1alpha.DesignCenter.UpdateComponent"
不会生成审核日志的方法
由于以下一个或多个原因,方法可能不会生成审核日志:
- 这是一种会产生大量日志的方法,日志生成和存储的费用高昂。
- 它的审核价值较低。
- 其他审核或平台日志已提供方法覆盖功能。
以下方法不会生成审核日志:
google.cloud.designcenter.v1alpha.DesignCenter.CreateCataloggoogle.cloud.designcenter.v1alpha.DesignCenter.CreateSpacegoogle.cloud.designcenter.v1alpha.DesignCenter.DeleteCataloggoogle.cloud.designcenter.v1alpha.DesignCenter.DeleteCatalogTemplateRevisiongoogle.cloud.designcenter.v1alpha.DesignCenter.DeleteSharegoogle.cloud.designcenter.v1alpha.DesignCenter.DeleteSpacegoogle.cloud.designcenter.v1alpha.DesignCenter.GetComponentgoogle.cloud.designcenter.v1alpha.DesignCenter.GetConnectiongoogle.cloud.designcenter.v1alpha.DesignCenter.GetSharegoogle.cloud.designcenter.v1alpha.DesignCenter.GetSharedTemplategoogle.cloud.designcenter.v1alpha.DesignCenter.ListApplicationTemplateRevisionsgoogle.cloud.designcenter.v1alpha.DesignCenter.ListCatalogTemplateRevisionsgoogle.cloud.designcenter.v1alpha.DesignCenter.ListCatalogTemplatesgoogle.cloud.designcenter.v1alpha.DesignCenter.ListComponentsgoogle.cloud.designcenter.v1alpha.DesignCenter.ListConnectionsgoogle.cloud.designcenter.v1alpha.DesignCenter.ListSharedTemplatesgoogle.cloud.designcenter.v1alpha.DesignCenter.ListSharesgoogle.cloud.designcenter.v1alpha.DesignCenter.ListSpacesgoogle.cloud.designcenter.v1alpha.DesignCenter.SyncSharegoogle.cloud.designcenter.v1alpha.DesignCenter.UpdateApplicationTemplategoogle.cloud.designcenter.v1alpha.DesignCenter.UpdateCataloggoogle.cloud.designcenter.v1alpha.DesignCenter.UpdateCatalogTemplategoogle.cloud.designcenter.v1alpha.DesignCenter.UpdateConnectiongoogle.cloud.designcenter.v1alpha.DesignCenter.UpdateSpacegoogle.cloud.designcenter.v1alpha.DesignCenterInternal.ImportSerializedApplicationTemplategoogle.longrunning.Operations.WaitOperation