// Copyright 2019 Google LLC. // // Licensed under the Apache License, Version 2.0 (the "License"); // you may not use this file except in compliance with the License. // You may obtain a copy of the License at // // http://www.apache.org/licenses/LICENSE-2.0 // // Unless required by applicable law or agreed to in writing, software // distributed under the License is distributed on an "AS IS" BASIS, // WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. // See the License for the specific language governing permissions and // limitations under the License. // syntax = "proto3"; package google.cloud.securitycenter.v1p1beta1; import "google/api/annotations.proto"; import "google/api/resource.proto"; import "google/cloud/securitycenter/v1p1beta1/security_marks.proto"; import "google/protobuf/struct.proto"; import "google/protobuf/timestamp.proto"; option csharp_namespace = "Google.Cloud.SecurityCenter.V1P1Beta1"; option go_package = "google.golang.org/genproto/googleapis/cloud/securitycenter/v1p1beta1;securitycenter"; option java_multiple_files = true; option java_package = "com.google.cloud.securitycenter.v1p1beta1"; option php_namespace = "Google\\Cloud\\SecurityCenter\\V1p1beta1"; option ruby_package = "Google::Cloud::SecurityCenter::V1p1beta1"; // Cloud Security Command Center's (Cloud SCC) representation of a Google Cloud // Platform (GCP) resource. // // The Asset is a Cloud SCC resource that captures information about a single // GCP resource. All modifications to an Asset are only within the context of // Cloud SCC and don't affect the referenced GCP resource. message Asset { option (google.api.resource) = { type: "securitycenter.googleapis.com/Asset" pattern: "organizations/{organization}/assets/{asset}" }; // Cloud SCC managed properties. These properties are managed by Cloud SCC and // cannot be modified by the user. message SecurityCenterProperties { // The full resource name of the GCP resource this asset // represents. This field is immutable after create time. See: // https://cloud.google.com/apis/design/resource_names#full_resource_name string resource_name = 1; // The type of the GCP resource. Examples include: APPLICATION, // PROJECT, and ORGANIZATION. This is a case insensitive field defined by // Cloud SCC and/or the producer of the resource and is immutable // after create time. string resource_type = 2; // The full resource name of the immediate parent of the resource. See: // https://cloud.google.com/apis/design/resource_names#full_resource_name string resource_parent = 3; // The full resource name of the project the resource belongs to. See: // https://cloud.google.com/apis/design/resource_names#full_resource_name string resource_project = 4; // Owners of the Google Cloud resource. repeated string resource_owners = 5; // The user defined display name for this resource. string resource_display_name = 6; // The user defined display name for the parent of this resource. string resource_parent_display_name = 7; // The user defined display name for the project of this resource. string resource_project_display_name = 8; } // IAM Policy information associated with the GCP resource described by the // Cloud SCC asset. This information is managed and defined by the GCP // resource and cannot be modified by the user. message IamPolicy { // The JSON representation of the Policy associated with the asset. // See https://cloud.google.com/iam/reference/rest/v1/Policy for // format details. string policy_blob = 1; } // The relative resource name of this asset. See: // https://cloud.google.com/apis/design/resource_names#relative_resource_name // Example: // "organizations/{organization_id}/assets/{asset_id}". string name = 1; // Cloud SCC managed properties. These properties are managed by // Cloud SCC and cannot be modified by the user. SecurityCenterProperties security_center_properties = 2; // Resource managed properties. These properties are managed and defined by // the GCP resource and cannot be modified by the user. map resource_properties = 7; // User specified security marks. These marks are entirely managed by the user // and come from the SecurityMarks resource that belongs to the asset. SecurityMarks security_marks = 8; // The time at which the asset was created in Cloud SCC. google.protobuf.Timestamp create_time = 9; // The time at which the asset was last updated, added, or deleted in Cloud // SCC. google.protobuf.Timestamp update_time = 10; // IAM Policy information associated with the GCP resource described by the // Cloud SCC asset. This information is managed and defined by the GCP // resource and cannot be modified by the user. IamPolicy iam_policy = 11; }