blob: e2c3659040cc0ef448299df7d82acc49fabdcf6d [file] [log] [blame]
# Licensed to the Apache Software Foundation (ASF) under one or more
# contributor license agreements. See the NOTICE file distributed with
# this work for additional information regarding copyright ownership.
# The ASF licenses this file to You under the Apache License, Version 2.0
# (the "License"); you may not use this file except in compliance with
# the License. You may obtain a copy of the License at
#
# http://www.apache.org/licenses/LICENSE-2.0
#
# Unless required by applicable law or agreed to in writing, software
# distributed under the License is distributed on an "AS IS" BASIS,
# WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
# See the License for the specific language governing permissions and
# limitations under the License.
project_id: apache-beam-testing
# Logging
logging:
level: DEBUG
format: "[%(asctime)s] %(levelname)s: %(message)s"
# gcloud storage bucket
bucket_name: "beam-sec-analytics-and-logging"
# GCP Log sinks
sinks:
- name: iam-policy-changes
description: Monitors changes to IAM policies, excluding approved CI/CD service accounts.
filter_methods:
- "SetIamPolicy"
excluded_principals:
- beam-github-actions@apache-beam-testing.iam.gserviceaccount.com
- github-self-hosted-runners@apache-beam-testing.iam.gserviceaccount.com
- name: sa-key-management
description: Monitors creation and deletion of service account keys.
filter_methods:
- "google.iam.admin.v1.IAM.CreateServiceAccountKey"
- "google.iam.admin.v1.IAM.DeleteServiceAccountKey"
excluded_principals:
- beam-github-actions@apache-beam-testing.iam.gserviceaccount.com
- github-self-hosted-runners@apache-beam-testing.iam.gserviceaccount.com