From aeb4c014426af55701e79a9e451b806484ee50cb Mon Sep 17 00:00:00 2001 From: Tomo Suzuki Date: Mon, 31 Aug 2026 15:30:46 +0000 Subject: [PATCH 1/2] update config --- librarian.yaml | 2 -- 1 file changed, 2 deletions(-) diff --git a/librarian.yaml b/librarian.yaml index 6b0695365251..a774f721b19c 100644 --- a/librarian.yaml +++ b/librarian.yaml @@ -2701,7 +2701,6 @@ libraries: version: 1.2.1 apis: - path: google/cloud/privilegedaccessmanager/v1 - skip_generate: true ruby: wrapper_of: - v1:1.0 @@ -2709,7 +2708,6 @@ libraries: version: 1.7.1 apis: - path: google/cloud/privilegedaccessmanager/v1 - skip_generate: true - name: google-cloud-product_registry version: 0.1.1 apis: From 9a46080ee10d412eebd3a6744038d66cc6366da8 Mon Sep 17 00:00:00 2001 From: Tomo Suzuki Date: Mon, 31 Aug 2026 15:31:24 +0000 Subject: [PATCH 2/2] regen google-cloud-privileged_access_manager --- .../.OwlBot.yaml | 3 - .../.owlbot-manifest.json | 72 ------------------- .../.owlbot.rb | 22 ------ .../README.md | 48 ------------- ...cloud-privileged_access_manager-v1.gemspec | 2 +- .../.OwlBot.yaml | 3 - .../.owlbot-manifest.json | 27 ------- .../.owlbot.rb | 22 ------ .../README.md | 48 ------------- ...le-cloud-privileged_access_manager.gemspec | 2 +- 10 files changed, 2 insertions(+), 247 deletions(-) delete mode 100644 google-cloud-privileged_access_manager-v1/.OwlBot.yaml delete mode 100644 google-cloud-privileged_access_manager-v1/.owlbot-manifest.json delete mode 100644 google-cloud-privileged_access_manager-v1/.owlbot.rb delete mode 100644 google-cloud-privileged_access_manager/.OwlBot.yaml delete mode 100644 google-cloud-privileged_access_manager/.owlbot-manifest.json delete mode 100644 google-cloud-privileged_access_manager/.owlbot.rb diff --git a/google-cloud-privileged_access_manager-v1/.OwlBot.yaml b/google-cloud-privileged_access_manager-v1/.OwlBot.yaml deleted file mode 100644 index 899effa798be..000000000000 --- a/google-cloud-privileged_access_manager-v1/.OwlBot.yaml +++ /dev/null @@ -1,3 +0,0 @@ -deep-copy-regex: - - source: /google/cloud/privilegedaccessmanager/v1/[^/]+-ruby/(.*) - dest: /owl-bot-staging/google-cloud-privileged_access_manager-v1/$1 diff --git a/google-cloud-privileged_access_manager-v1/.owlbot-manifest.json b/google-cloud-privileged_access_manager-v1/.owlbot-manifest.json deleted file mode 100644 index c01c8f7a8e3d..000000000000 --- a/google-cloud-privileged_access_manager-v1/.owlbot-manifest.json +++ /dev/null @@ -1,72 +0,0 @@ -{ - "generated": [ - ".gitignore", - ".repo-metadata.json", - ".rubocop.yml", - ".toys.rb", - ".yardopts", - "AUTHENTICATION.md", - "CHANGELOG.md", - "Gemfile", - "LICENSE.md", - "README.md", - "Rakefile", - "gapic_metadata.json", - "google-cloud-privileged_access_manager-v1.gemspec", - "lib/google-cloud-privileged_access_manager-v1.rb", - "lib/google/cloud/privileged_access_manager/v1.rb", - "lib/google/cloud/privileged_access_manager/v1/bindings_override.rb", - "lib/google/cloud/privileged_access_manager/v1/privileged_access_manager.rb", - "lib/google/cloud/privileged_access_manager/v1/privileged_access_manager/client.rb", - "lib/google/cloud/privileged_access_manager/v1/privileged_access_manager/credentials.rb", - "lib/google/cloud/privileged_access_manager/v1/privileged_access_manager/operations.rb", - "lib/google/cloud/privileged_access_manager/v1/privileged_access_manager/paths.rb", - "lib/google/cloud/privileged_access_manager/v1/privileged_access_manager/rest.rb", - "lib/google/cloud/privileged_access_manager/v1/privileged_access_manager/rest/client.rb", - "lib/google/cloud/privileged_access_manager/v1/privileged_access_manager/rest/operations.rb", - "lib/google/cloud/privileged_access_manager/v1/privileged_access_manager/rest/service_stub.rb", - "lib/google/cloud/privileged_access_manager/v1/rest.rb", - "lib/google/cloud/privileged_access_manager/v1/version.rb", - "lib/google/cloud/privilegedaccessmanager/v1/privilegedaccessmanager_pb.rb", - "lib/google/cloud/privilegedaccessmanager/v1/privilegedaccessmanager_services_pb.rb", - "proto_docs/README.md", - "proto_docs/google/api/client.rb", - "proto_docs/google/api/field_behavior.rb", - "proto_docs/google/api/launch_stage.rb", - "proto_docs/google/api/resource.rb", - "proto_docs/google/cloud/privilegedaccessmanager/v1/privilegedaccessmanager.rb", - "proto_docs/google/longrunning/operations.rb", - "proto_docs/google/protobuf/any.rb", - "proto_docs/google/protobuf/duration.rb", - "proto_docs/google/protobuf/empty.rb", - "proto_docs/google/protobuf/field_mask.rb", - "proto_docs/google/protobuf/timestamp.rb", - "proto_docs/google/rpc/status.rb", - "snippets/Gemfile", - "snippets/privileged_access_manager/approve_grant.rb", - "snippets/privileged_access_manager/check_onboarding_status.rb", - "snippets/privileged_access_manager/create_entitlement.rb", - "snippets/privileged_access_manager/create_grant.rb", - "snippets/privileged_access_manager/delete_entitlement.rb", - "snippets/privileged_access_manager/deny_grant.rb", - "snippets/privileged_access_manager/get_entitlement.rb", - "snippets/privileged_access_manager/get_grant.rb", - "snippets/privileged_access_manager/list_entitlements.rb", - "snippets/privileged_access_manager/list_grants.rb", - "snippets/privileged_access_manager/revoke_grant.rb", - "snippets/privileged_access_manager/search_entitlements.rb", - "snippets/privileged_access_manager/search_grants.rb", - "snippets/privileged_access_manager/update_entitlement.rb", - "snippets/snippet_metadata_google.cloud.privilegedaccessmanager.v1.json", - "test/google/cloud/privileged_access_manager/v1/privileged_access_manager_operations_test.rb", - "test/google/cloud/privileged_access_manager/v1/privileged_access_manager_paths_test.rb", - "test/google/cloud/privileged_access_manager/v1/privileged_access_manager_rest_test.rb", - "test/google/cloud/privileged_access_manager/v1/privileged_access_manager_test.rb", - "test/helper.rb" - ], - "static": [ - ".OwlBot.yaml", - ".owlbot.rb", - "Gemfile.lock" - ] -} diff --git a/google-cloud-privileged_access_manager-v1/.owlbot.rb b/google-cloud-privileged_access_manager-v1/.owlbot.rb deleted file mode 100644 index a0510e8304ed..000000000000 --- a/google-cloud-privileged_access_manager-v1/.owlbot.rb +++ /dev/null @@ -1,22 +0,0 @@ -# Copyright 2024 Google LLC -# -# Licensed under the Apache License, Version 2.0 (the "License"); -# you may not use this file except in compliance with the License. -# You may obtain a copy of the License at -# -# http://www.apache.org/licenses/LICENSE-2.0 -# -# Unless required by applicable law or agreed to in writing, software -# distributed under the License is distributed on an "AS IS" BASIS, -# WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. -# See the License for the specific language governing permissions and -# limitations under the License. - -# OwlBot script for google-cloud-privileged_access_manager-v1 -# Properly escape README.md files for links. -# See https://github.com/googleapis/gapic-generator-ruby/issues/1094 -OwlBot.modifier path: ["README.md"], name: "Escape README.md" do |content| - content.gsub(/resourcemanager\.\{projects\|folders\|organizations\}\.(\w+)/, '`resourcemanager.{projects|folders|organizations}.\1`') -end - -OwlBot.move_files diff --git a/google-cloud-privileged_access_manager-v1/README.md b/google-cloud-privileged_access_manager-v1/README.md index 6a833c5ef4b0..7b3099849fd6 100644 --- a/google-cloud-privileged_access_manager-v1/README.md +++ b/google-cloud-privileged_access_manager-v1/README.md @@ -2,54 +2,6 @@ Privileged Access Manager (PAM) helps you on your journey towards least privilege and helps mitigate risks tied to privileged access misuse or abuse. PAM allows you to shift from always-on standing privileges towards on-demand access with just-in-time, time-bound, and approval-based access elevations. PAM allows IAM administrators to create entitlements that can grant just-in-time, temporary access to any resource scope. Requesters can explore eligible entitlements and request the access needed for their task. Approvers are notified when approvals await their decision. Streamlined workflows facilitated by using PAM can support various use cases, including emergency access for incident responders, time-boxed access for developers for critical deployment or maintenance, temporary access for operators for data ingestion and audits, JIT access to service accounts for automated tasks, and more. -## Overview - -Privileged Access Manager (PAM) is a Google Cloud native, managed solution -to secure, manage and audit privileged access while ensuring operational -velocity and developer productivity. - -PAM enables just-in-time, time-bound, approval-based access elevations, -and auditing of privileged access elevations and activity. PAM lets you -define the rules of who can request access, what they can request access -to, and if they should be granted access with or without approvals based -on the sensitivity of the access and emergency of the situation. - -## Concepts - -### Entitlement - -An entitlement is an eligibility or license that allows specified users -(requesters) to request and obtain access to specified resources subject -to a set of conditions such as duration, etc. entitlements can be granted -to both human and non-human principals. - -### Grant - -A grant is an instance of active usage against the entitlement. A user can -place a request for a grant against an entitlement. The request may be -forwarded to an approver for their decision. Once approved, the grant is -activated, ultimately giving the user access (roles/permissions) on a -resource per the criteria specified in entitlement. - -### How does PAM work - -PAM creates and uses a service agent (Google-managed service account) to -perform the required IAM policy changes for granting access at a -specific -resource/access scope. The service agent requires getIAMPolicy and -setIAMPolicy permissions at the appropriate (or higher) access scope -- -Organization/Folder/Project to make policy changes on the resources listed -in PAM entitlements. - -When enabling PAM for a resource scope, the user/ principal performing -that action should have the appropriate permissions at that resource -scope -(resourcemanager.\\{projects|folders|organizations}.setIamPolicy, -resourcemanager.\\{projects|folders|organizations}.getIamPolicy, and -resourcemanager.\\{projects|folders|organizations}.get) to list and grant -the service agent/account the required access to perform IAM policy -changes. https://github.com/googleapis/google-cloud-ruby diff --git a/google-cloud-privileged_access_manager-v1/google-cloud-privileged_access_manager-v1.gemspec b/google-cloud-privileged_access_manager-v1/google-cloud-privileged_access_manager-v1.gemspec index 00310526c065..e6649a00dc6b 100644 --- a/google-cloud-privileged_access_manager-v1/google-cloud-privileged_access_manager-v1.gemspec +++ b/google-cloud-privileged_access_manager-v1/google-cloud-privileged_access_manager-v1.gemspec @@ -9,7 +9,7 @@ Gem::Specification.new do |gem| gem.authors = ["Google LLC"] gem.email = "googleapis-packages@google.com" - gem.description = "## Overview Privileged Access Manager (PAM) is a Google Cloud native, managed solution to secure, manage and audit privileged access while ensuring operational velocity and developer productivity. PAM enables just-in-time, time-bound, approval-based access elevations, and auditing of privileged access elevations and activity. PAM lets you define the rules of who can request access, what they can request access to, and if they should be granted access with or without approvals based on the sensitivity of the access and emergency of the situation. ## Concepts ### Entitlement An entitlement is an eligibility or license that allows specified users (requesters) to request and obtain access to specified resources subject to a set of conditions such as duration, etc. entitlements can be granted to both human and non-human principals. ### Grant A grant is an instance of active usage against the entitlement. A user can place a request for a grant against an entitlement. The request may be forwarded to an approver for their decision. Once approved, the grant is activated, ultimately giving the user access (roles/permissions) on a resource per the criteria specified in entitlement. ### How does PAM work PAM creates and uses a service agent (Google-managed service account) to perform the required IAM policy changes for granting access at a specific resource/access scope. The service agent requires getIAMPolicy and setIAMPolicy permissions at the appropriate (or higher) access scope - Organization/Folder/Project to make policy changes on the resources listed in PAM entitlements. When enabling PAM for a resource scope, the user/ principal performing that action should have the appropriate permissions at that resource scope (resourcemanager.{projects|folders|organizations}.setIamPolicy, resourcemanager.{projects|folders|organizations}.getIamPolicy, and resourcemanager.{projects|folders|organizations}.get) to list and grant the service agent/account the required access to perform IAM policy changes. Note that google-cloud-privileged_access_manager-v1 is a version-specific client library. For most uses, we recommend installing the main client library google-cloud-privileged_access_manager instead. See the readme for more details." + gem.description = "Privileged Access Manager (PAM) helps you on your journey towards least privilege and helps mitigate risks tied to privileged access misuse or abuse. PAM allows you to shift from always-on standing privileges towards on-demand access with just-in-time, time-bound, and approval-based access elevations. PAM allows IAM administrators to create entitlements that can grant just-in-time, temporary access to any resource scope. Requesters can explore eligible entitlements and request the access needed for their task. Approvers are notified when approvals await their decision. Streamlined workflows facilitated by using PAM can support various use cases, including emergency access for incident responders, time-boxed access for developers for critical deployment or maintenance, temporary access for operators for data ingestion and audits, JIT access to service accounts for automated tasks, and more. Note that google-cloud-privileged_access_manager-v1 is a version-specific client library. For most uses, we recommend installing the main client library google-cloud-privileged_access_manager instead. See the readme for more details." gem.summary = "Privileged Access Manager (PAM) helps you on your journey towards least privilege and helps mitigate risks tied to privileged access misuse or abuse. PAM allows you to shift from always-on standing privileges towards on-demand access with just-in-time, time-bound, and approval-based access elevations. PAM allows IAM administrators to create entitlements that can grant just-in-time, temporary access to any resource scope. Requesters can explore eligible entitlements and request the access needed for their task. Approvers are notified when approvals await their decision. Streamlined workflows facilitated by using PAM can support various use cases, including emergency access for incident responders, time-boxed access for developers for critical deployment or maintenance, temporary access for operators for data ingestion and audits, JIT access to service accounts for automated tasks, and more." gem.homepage = "https://github.com/googleapis/google-cloud-ruby" gem.license = "Apache-2.0" diff --git a/google-cloud-privileged_access_manager/.OwlBot.yaml b/google-cloud-privileged_access_manager/.OwlBot.yaml deleted file mode 100644 index 1322fe586aa5..000000000000 --- a/google-cloud-privileged_access_manager/.OwlBot.yaml +++ /dev/null @@ -1,3 +0,0 @@ -deep-copy-regex: - - source: /google/cloud/privilegedaccessmanager/[^/]+-ruby/(.*) - dest: /owl-bot-staging/google-cloud-privileged_access_manager/$1 diff --git a/google-cloud-privileged_access_manager/.owlbot-manifest.json b/google-cloud-privileged_access_manager/.owlbot-manifest.json deleted file mode 100644 index 1c7c356c4226..000000000000 --- a/google-cloud-privileged_access_manager/.owlbot-manifest.json +++ /dev/null @@ -1,27 +0,0 @@ -{ - "generated": [ - ".gitignore", - ".repo-metadata.json", - ".rubocop.yml", - ".toys.rb", - ".yardopts", - "AUTHENTICATION.md", - "CHANGELOG.md", - "Gemfile", - "LICENSE.md", - "README.md", - "Rakefile", - "google-cloud-privileged_access_manager.gemspec", - "lib/google-cloud-privileged_access_manager.rb", - "lib/google/cloud/privileged_access_manager.rb", - "lib/google/cloud/privileged_access_manager/version.rb", - "test/google/cloud/privileged_access_manager/client_test.rb", - "test/google/cloud/privileged_access_manager/version_test.rb", - "test/helper.rb" - ], - "static": [ - ".OwlBot.yaml", - ".owlbot.rb", - "Gemfile.lock" - ] -} diff --git a/google-cloud-privileged_access_manager/.owlbot.rb b/google-cloud-privileged_access_manager/.owlbot.rb deleted file mode 100644 index 04736a8b33b5..000000000000 --- a/google-cloud-privileged_access_manager/.owlbot.rb +++ /dev/null @@ -1,22 +0,0 @@ -# Copyright 2024 Google LLC -# -# Licensed under the Apache License, Version 2.0 (the "License"); -# you may not use this file except in compliance with the License. -# You may obtain a copy of the License at -# -# http://www.apache.org/licenses/LICENSE-2.0 -# -# Unless required by applicable law or agreed to in writing, software -# distributed under the License is distributed on an "AS IS" BASIS, -# WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. -# See the License for the specific language governing permissions and -# limitations under the License. - -# OwlBot script for google-cloud-privileged_access_manager -# Properly escape README.md files for links. -# See https://github.com/googleapis/gapic-generator-ruby/issues/1094 -OwlBot.modifier path: ["README.md"], name: "Escape README.md" do |content| - content.gsub(/resourcemanager\.\{projects\|folders\|organizations\}\.(\w+)/, '`resourcemanager.{projects|folders|organizations}.\1`') -end - -OwlBot.move_files diff --git a/google-cloud-privileged_access_manager/README.md b/google-cloud-privileged_access_manager/README.md index e8c98fe201e4..f78daa15cb03 100644 --- a/google-cloud-privileged_access_manager/README.md +++ b/google-cloud-privileged_access_manager/README.md @@ -2,54 +2,6 @@ Privileged Access Manager (PAM) helps you on your journey towards least privilege and helps mitigate risks tied to privileged access misuse or abuse. PAM allows you to shift from always-on standing privileges towards on-demand access with just-in-time, time-bound, and approval-based access elevations. PAM allows IAM administrators to create entitlements that can grant just-in-time, temporary access to any resource scope. Requesters can explore eligible entitlements and request the access needed for their task. Approvers are notified when approvals await their decision. Streamlined workflows facilitated by using PAM can support various use cases, including emergency access for incident responders, time-boxed access for developers for critical deployment or maintenance, temporary access for operators for data ingestion and audits, JIT access to service accounts for automated tasks, and more. -## Overview - -Privileged Access Manager (PAM) is a Google Cloud native, managed solution -to secure, manage and audit privileged access while ensuring operational -velocity and developer productivity. - -PAM enables just-in-time, time-bound, approval-based access elevations, -and auditing of privileged access elevations and activity. PAM lets you -define the rules of who can request access, what they can request access -to, and if they should be granted access with or without approvals based -on the sensitivity of the access and emergency of the situation. - -## Concepts - -### Entitlement - -An entitlement is an eligibility or license that allows specified users -(requesters) to request and obtain access to specified resources subject -to a set of conditions such as duration, etc. entitlements can be granted -to both human and non-human principals. - -### Grant - -A grant is an instance of active usage against the entitlement. A user can -place a request for a grant against an entitlement. The request may be -forwarded to an approver for their decision. Once approved, the grant is -activated, ultimately giving the user access (roles/permissions) on a -resource per the criteria specified in entitlement. - -### How does PAM work - -PAM creates and uses a service agent (Google-managed service account) to -perform the required IAM policy changes for granting access at a -specific -resource/access scope. The service agent requires getIAMPolicy and -setIAMPolicy permissions at the appropriate (or higher) access scope -- -Organization/Folder/Project to make policy changes on the resources listed -in PAM entitlements. - -When enabling PAM for a resource scope, the user/ principal performing -that action should have the appropriate permissions at that resource -scope -(resourcemanager.\\{projects|folders|organizations}.setIamPolicy, -resourcemanager.\\{projects|folders|organizations}.getIamPolicy, and -resourcemanager.\\{projects|folders|organizations}.get) to list and grant -the service agent/account the required access to perform IAM policy -changes. Actual client classes for the various versions of this API are defined in _versioned_ client gems, with names of the form `google-cloud-privileged_access_manager-v*`. diff --git a/google-cloud-privileged_access_manager/google-cloud-privileged_access_manager.gemspec b/google-cloud-privileged_access_manager/google-cloud-privileged_access_manager.gemspec index bbc718c6f2e3..a166d9a7e4f2 100644 --- a/google-cloud-privileged_access_manager/google-cloud-privileged_access_manager.gemspec +++ b/google-cloud-privileged_access_manager/google-cloud-privileged_access_manager.gemspec @@ -9,7 +9,7 @@ Gem::Specification.new do |gem| gem.authors = ["Google LLC"] gem.email = "googleapis-packages@google.com" - gem.description = "## Overview Privileged Access Manager (PAM) is a Google Cloud native, managed solution to secure, manage and audit privileged access while ensuring operational velocity and developer productivity. PAM enables just-in-time, time-bound, approval-based access elevations, and auditing of privileged access elevations and activity. PAM lets you define the rules of who can request access, what they can request access to, and if they should be granted access with or without approvals based on the sensitivity of the access and emergency of the situation. ## Concepts ### Entitlement An entitlement is an eligibility or license that allows specified users (requesters) to request and obtain access to specified resources subject to a set of conditions such as duration, etc. entitlements can be granted to both human and non-human principals. ### Grant A grant is an instance of active usage against the entitlement. A user can place a request for a grant against an entitlement. The request may be forwarded to an approver for their decision. Once approved, the grant is activated, ultimately giving the user access (roles/permissions) on a resource per the criteria specified in entitlement. ### How does PAM work PAM creates and uses a service agent (Google-managed service account) to perform the required IAM policy changes for granting access at a specific resource/access scope. The service agent requires getIAMPolicy and setIAMPolicy permissions at the appropriate (or higher) access scope - Organization/Folder/Project to make policy changes on the resources listed in PAM entitlements. When enabling PAM for a resource scope, the user/ principal performing that action should have the appropriate permissions at that resource scope (resourcemanager.{projects|folders|organizations}.setIamPolicy, resourcemanager.{projects|folders|organizations}.getIamPolicy, and resourcemanager.{projects|folders|organizations}.get) to list and grant the service agent/account the required access to perform IAM policy changes." + gem.description = "Privileged Access Manager (PAM) helps you on your journey towards least privilege and helps mitigate risks tied to privileged access misuse or abuse. PAM allows you to shift from always-on standing privileges towards on-demand access with just-in-time, time-bound, and approval-based access elevations. PAM allows IAM administrators to create entitlements that can grant just-in-time, temporary access to any resource scope. Requesters can explore eligible entitlements and request the access needed for their task. Approvers are notified when approvals await their decision. Streamlined workflows facilitated by using PAM can support various use cases, including emergency access for incident responders, time-boxed access for developers for critical deployment or maintenance, temporary access for operators for data ingestion and audits, JIT access to service accounts for automated tasks, and more." gem.summary = "Privileged Access Manager (PAM) helps you on your journey towards least privilege and helps mitigate risks tied to privileged access misuse or abuse. PAM allows you to shift from always-on standing privileges towards on-demand access with just-in-time, time-bound, and approval-based access elevations. PAM allows IAM administrators to create entitlements that can grant just-in-time, temporary access to any resource scope. Requesters can explore eligible entitlements and request the access needed for their task. Approvers are notified when approvals await their decision. Streamlined workflows facilitated by using PAM can support various use cases, including emergency access for incident responders, time-boxed access for developers for critical deployment or maintenance, temporary access for operators for data ingestion and audits, JIT access to service accounts for automated tasks, and more." gem.homepage = "https://github.com/googleapis/google-cloud-ruby" gem.license = "Apache-2.0"