Permissões e papéis do Artifact Guard

A proteção de artefatos usa papéis e permissões do Identity and Access Management (IAM) para gerenciar o acesso aos recursos. É possível conceder papéis do IAM a usuários, grupos ou contas de serviço. Para saber mais sobre a concessão de papéis, consulte Gerenciar o acesso a projetos, pastas e organizações.

Papéis de proteção de artefatos

Os seguintes papéis do IAM estão disponíveis para a proteção de artefatos.

Papel Permissões
Administrador do Artifact Scan Guard
(roles/artifactscanguard.admin)

Acesso total aos recursos de proteção de artefatos. Crie políticas, avalie e visualize a performance delas.
artifactscanguard.artifactEvaluations.create
artifactscanguard.artifactEvaluations.get
artifactscanguard.artifactPoliciesEvaluations.create
artifactscanguard.artifactPoliciesEvaluations.get
artifactscanguard.connectors.create
artifactscanguard.connectors.delete
artifactscanguard.connectors.get
artifactscanguard.connectors.list
artifactscanguard.connectors.update
artifactscanguard.locations.get
artifactscanguard.locations.list
artifactscanguard.operations.delete
artifactscanguard.operations.get
artifactscanguard.operations.list
artifactscanguard.policies.create
artifactscanguard.policies.delete
artifactscanguard.policies.get
artifactscanguard.policies.list
artifactscanguard.policies.update
artifactscanguard.reports.listConnectorEvaluations
artifactscanguard.reports.listPolicyEvaluationSummaries
monitoring.timeSeries.create
orgpolicy.policy.get
resourcemanager.organizations.get
resourcemanager.projects.get
resourcemanager.projects.list
storage.folders.create
storage.folders.delete
storage.folders.get
storage.folders.list
{10ancers.rename
storage.managedFolders.create
storage.managedFolders.delete
storage.managedFolders.get
storage.managedFolders.list
storage.multipartUploads.abort
storage.multipartUploads.create
storage.multipartUploads.list
storage.multipartUploads.listParts
storage.objects.create
storage.objects.createContext
storage.objects.delete
storage.objects.deleteContext
storage.objects.get
storage.objects.list
storage.objects.move
storage.objects.restore
storage.objects.update
storage.objects.updateContext
Administrador de avaliação do Artifact Scan Guard
(roles/artifactscanguard.policyEvaluator)

Acesso total aos recursos de avaliação de artefatos.
artifactscanguard.artifactEvaluations.create
artifactscanguard.artifactEvaluations.get
artifactscanguard.artifactPoliciesEvaluations.create
artifactscanguard.artifactPoliciesEvaluations.get
artifactscanguard.locations.get
artifactscanguard.locations.list
artifactscanguard.operations.get
monitoring.timeSeries.create
orgpolicy.policy.get
resourcemanager.organizations.get
resourcemanager.projects.get
resourcemanager.projects.list
storage.folders.create
storage.folders.delete
storage.folders.get
storage.folders.list
storage.folders.rename
storage.managedFolders.create
storage.managedFolders.delete
storage.managedFolders.get
storage.managedFolders.list
storage.multipartUploads.abort
storage.multipartUploads.create
storage.multipartUploads.list
storage.multipartUploads.listParts
storage.objects.create
storage.objects.createContext
storage.objects.delete
storage.objects.deleteContext
storage.objects.get
storage.objects.list
storage.objects.move
storage.objects.restore
storage.objects.update
storage.objects.updateContext
Administrador do conector do Artifact Scan Guard
(roles/artifactscanguard.connectorAdmin)

Acesso total aos recursos do conector.
artifactscanguard.connectors.create
artifactscanguard.connectors.delete
artifactscanguard.connectors.get
artifactscanguard.connectors.list
artifactscanguard.connectors.update
artifactscanguard.locations.get
artifactscanguard.locations.list
artifactscanguard.operations.get
resourcemanager.organizations.get
resourcemanager.projects.get
Administrador de políticas do Artifact Scan Guard
(roles/artifactscanguard.policyAdmin)

Acesso total aos recursos de políticas. Crie políticas e visualize a performance delas.
artifactscanguard.locations.get
artifactscanguard.locations.list
artifactscanguard.operations.get
artifactscanguard.policies.create
artifactscanguard.policies.delete
artifactscanguard.policies.get
artifactscanguard.policies.list
artifactscanguard.policies.update
resourcemanager.organizations.get
resourcemanager.projects.get
Administrador de avaliação de políticas do Artifact Scan Guard
(roles/artifactscanguard.policyEvaluationAdmin)

Acesso total aos recursos de avaliação de políticas.
artifactscanguard.artifactPoliciesEvaluations.create
artifactscanguard.artifactPoliciesEvaluations.get
artifactscanguard.locations.get
artifactscanguard.locations.list
artifactscanguard.operations.get
monitoring.timeSeries.create
orgpolicy.policy.get
resourcemanager.organizations.get
resourcemanager.projects.get
resourcemanager.projects.list
storage.folders.create
storage.folders.delete
storage.folders.get
storage.folders.list
storage.folders.rename
storage.managedFolders.create
storage.managedFolders.delete
storage.managedFolders.get
storage.managedFolders.list
storage.multipartUploads.abort
storage.multipartUploads.create
storage.multipartUploads.list
storage.multipartUploads.listParts
storage.objects.create
storage.objects.createContext
storage.objects.delete
storage.objects.deleteContext
storage.objects.get
storage.objects.list
storage.objects.move
storage.objects.restore
storage.objects.update
storage.objects.updateContext
Administrador de relatórios do Artifact Scan Guard
(roles/artifactscanguard.reportAdmin)

Acesso total aos recursos de relatórios.
artifactscanguard.locations.get
artifactscanguard.locations.list
artifactscanguard.operations.get
artifactscanguard.reports.listConnectorEvaluations
artifactscanguard.reports.listPolicyEvaluationSummaries
resourcemanager.organizations.get
resourcemanager.projects.get
Leitor do Artifact Scan Guard
(roles/artifactscanguard.viewer)

Acesso somente leitura aos recursos de proteção de artefatos.
artifactscanguard.artifactPoliciesEvaluations.get
artifactscanguard.connectors.get
artifactscanguard.connectors.list
artifactscanguard.locations.get
artifactscanguard.locations.list
artifactscanguard.operations.get
artifactscanguard.policies.get
artifactscanguard.policies.list
artifactscanguard.reports.listConnectorEvaluations
artifactscanguard.reports.listPolicyEvaluationSummaries
resourcemanager.organizations.get
resourcemanager.projects.get
Leitor do conector do Artifact Scan Guard
(roles/artifactscanguard.connectorViewer)

Acesso somente leitura aos recursos do conector.
artifactscanguard.connectors.get
artifactscanguard.connectors.list
artifactscanguard.locations.get
artifactscanguard.locations.list
artifactscanguard.operations.get
resourcemanager.organizations.get
resourcemanager.projects.get
Leitor da política do Artifact Scan Guard
(roles/artifactscanguard.policyViewer)

Acesso somente leitura aos recursos de políticas.
artifactscanguard.locations.get
artifactscanguard.locations.list
artifactscanguard.operations.get
artifactscanguard.policies.get
artifactscanguard.policies.list
resourcemanager.organizations.get
resourcemanager.projects.get
Leitor de avaliação de políticas do Artifact Scan Guard
(roles/artifactscanguard.policyEvaluationViewer)

Acesso somente leitura aos recursos de avaliação de políticas.
artifactscanguard.artifactPoliciesEvaluations.get
artifactscanguard.locations.get
artifactscanguard.locations.list
artifactscanguard.operations.get
resourcemanager.organizations.get
resourcemanager.projects.get
Leitor de relatórios do Artifact Scan Guard
(roles/artifactscanguard.reportViewer)

Acesso somente leitura aos recursos de relatórios.
artifactscanguard.locations.get
artifactscanguard.locations.list
artifactscanguard.operations.get
artifactscanguard.reports.listConnectorEvaluations
artifactscanguard.reports.listPolicyEvaluationSummaries
resourcemanager.organizations.get
resourcemanager.projects.get