blob: 7efb81229364cecb93b22e68e3f14a2f971deba9 [file]
# Licensed to the Apache Software Foundation (ASF) under one
# or more contributor license agreements. See the NOTICE file
# distributed with this work for additional information
# regarding copyright ownership. The ASF licenses this file
# to you under the Apache License, Version 2.0 (the
# "License"); you may not use this file except in compliance
# with the License. You may obtain a copy of the License at
#
# http://www.apache.org/licenses/LICENSE-2.0
#
# Unless required by applicable law or agreed to in writing,
# software distributed under the License is distributed on an
# "AS IS" BASIS, WITHOUT WARRANTIES OR CONDITIONS OF ANY
# KIND, either express or implied. See the License for the
# specific language governing permissions and limitations
# under the License.
# This workflow works with the GCP security log analyzer to
# generate weekly security reports and initialize log sinks
name: Unmanaged Service Accounts Keys Audit
on:
workflow_dispatch:
schedule:
# Every day at 00:00 UTC
- cron: '0 0 * * *'
concurrency:
group: ${{ github.workflow }}
cancel-in-progress: false
permissions:
contents: read
issues: write
id-token: write
jobs:
beam_UnmanagedKeysAudit:
name: Audit Unmanaged Service Account Keys
runs-on: [self-hosted, ubuntu-24.04, main]
timeout-minutes: 30
steps:
- uses: actions/checkout@v7
- name: Setup gcloud
uses: google-github-actions/setup-gcloud@aa5489c8933f4cc7a4f7d45035b3b1440c9c10db
- name: Setup Python
uses: actions/setup-python@v4
with:
python-version: '3.13'
- name: Install Python dependencies
working-directory: ./infra/enforcement
run: |
python -m pip install --upgrade pip
pip install -r requirements.txt
- name: Run Unmanaged Service Account Keys Audit
working-directory: ./infra/enforcement
env:
GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
GITHUB_REPOSITORY: ${{ github.repository }}
run: python account_keys.py --action announce