Automate Google Binary Authorization
HumDay reads Google Binary Authorization’s own published API description and derives 9 operations from it. Describe the outcome you want in plain words — you get a program that is written, proven on real data, and run for you.
What Google Binary Authorization is
The management interface for Binary Authorization, a service that provides policy-based deployment validation and control for images deployed to Google Kubernetes Engine (GKE), Anthos Service Mesh, Anthos Clusters, and Cloud Run.
API host: binaryauthorization.googleapis.com
What HumDay can do in Google Binary Authorization
6 documented operations change something in Google Binary Authorization.
- POSTCreates an attestor, and returns a copy of the new attestor.
/v1beta1/{parent}/attestors - DELETEDeletes an attestor. Returns NOTFOUND if the attestor does not exist.
/v1beta1/{name} - PUTUpdates an attestor. Returns NOTFOUND if the attestor does not exist.
/v1beta1/{name} - POSTSets the access control policy on the specified resource.
/v1beta1/{resource}:setIamPolicy - POSTReturns permissions that a caller has on the specified resource.
/v1beta1/{resource}:testIamPermissions - POSTReturns whether the given Attestation for the given image URI was signed by the given Attestor
/v1beta1/{attestor}:validateAttestationOccurrence
What HumDay can read from Google Binary Authorization
These are the operations a schedule or a trigger can watch.
- GETGets the current system policy in the specified location.
/v1beta1/{name} - GETGets the access control policy for a resource.
/v1beta1/{resource}:getIamPolicy - GETLists attestors. Returns INVALIDARGUMENT if the project does not exist.
/v1beta1/{parent}/attestors
How automating Google Binary Authorization works
- Describe the outcome. Say what you want to happen, in your own words. No node graphs, no field mapping.
- Approve the contract. HumDay writes down exactly what it will do, what it will touch, and what it will never do. You approve it before anything is built.
- See it proven. The program runs and shows you the result before it is allowed near your live Google Binary Authorization account.
- Grant access, then go live. You approve the specific Google Binary Authorization operations it may use — and only those.
Automate Google Binary Authorization with these
- Gmail79 operations
- Google+9 operations
- Google Abusive Experience Report2 operations
- Google Accelerated Mobile Pages (AMP) URL1 operations
- Google Access Approval7 operations
- Google Access Context Manager9 operations
- Google ACME DNS2 operations
- Google Ad Exchange Buyer38 operations
- Google Ad Exchange Buyer II50 operations
- Google Ad Experience Report2 operations
- Google Admin SDK122 operations
- Google AdMob7 operations
Categories
Questions about Google Binary Authorization automation
- Can HumDay connect to Google Binary Authorization?
- Yes. HumDay reads Google Binary Authorization's own published API description and derives the operations from it, so there is no hand-built connector to wait for. 9 operations are documented.
- Do I need to write code to automate Google Binary Authorization?
- No. You describe the outcome you want in plain words. HumDay agrees a contract with you, writes the program, and shows you a test run before anything touches your Google Binary Authorization account.
- What can HumDay do in Google Binary Authorization?
- 6 of the 9 documented operations change something in Google Binary Authorization, and 3 read from it. HumDay only ever uses the specific operations your approved contract needs.
- Is my Google Binary Authorization account safe?
- Your credentials are stored encrypted and are never shown in chat, code, or logs. Every run is limited to the operations you explicitly approved, and anything that writes to Google Binary Authorization is held behind that approval.
Where this came from
The operations above are read from a published API description for Google Binary Authorization at binaryauthorization.googleapis.com/$discovery/rest?version=v1beta1. Descriptions are the provider’s own words, not ours. Last published 2023-04-21.