Documentation
| Article | Path |
|---|---|
| Review Cloud SQL automatic backups | ansible/gcp/sql_db_instance_backup_disabled |
| Cloud SQL contained database authentication is enabled | ansible/gcp/cloud_sql_instance_with_contained_database_authentication_on |
| Cross-database ownership chaining is enabled in Cloud SQL | ansible/gcp/cloud_sql_instance_with_cross_db_ownership_chaining_on |
| Review Cloud DNS DNSSEC settings | ansible/gcp/cloud_dns_without_dnnsec |
| Review Cloud DNS DNSSEC signing algorithms | ansible/gcp/dnssec_using_rsasha1 |
| Review GCP firewall port ranges | ansible/gcp/google_compute_network_using_firewall_allows_port_range |
| Review subnet Private Google Access settings | ansible/gcp/google_compute_subnetwork_with_private_google_access_disabled |
| Review GKE VPC-native networking settings | ansible/gcp/ip_aliasing_disabled |
| Review authorized networks for the GKE control plane | ansible/gcp/gke_master_authorized_networks_disabled |
| GKE nodes use the default service account | ansible/gcp/gke_using_default_service_account |
| Review legacy Basic authentication settings in GKE | ansible/gcp/gke_basic_authentication_enabled |
| Review network policy enforcement in GKE | ansible/gcp/network_policy_disabled |
| Review GKE node auto-upgrade settings | ansible/gcp/node_auto_upgrade_disabled |
| Review GKE node pool auto-repair settings | ansible/gcp/google_container_node_pool_auto_repair_disabled |
| Review GKE node image selection | ansible/gcp/cos_node_image_not_used |
| GKE logging is disabled | ansible/gcp/stackdriver_logging_disabled |
| GKE monitoring is disabled | ansible/gcp/stackdriver_monitoring_disabled |
| GKE cluster labels are missing | ansible/gcp/cluster_labels_disabled |
| Review public access to GKE nodes and the control plane | ansible/gcp/private_cluster_disabled |
| IP forwarding is enabled on a Compute Engine VM | ansible/gcp/ip_forwarding_enabled |
| Review Cloud KMS key rotation periods | ansible/gcp/high_google_kms_crypto_key_rotation_period |
| GKE cluster configuration enables legacy ABAC | ansible/gcp/gke_legacy_authorization_enabled |
| Cloud SQL MySQL permits local file loading | ansible/gcp/mysql_instance_with_local_infile_on |
| PostgreSQL checkpoint logging is disabled | ansible/gcp/postgresql_log_checkpoints_flag_not_set_to_on |
| Review PostgreSQL server log levels | ansible/gcp/postgresql_misconfigured_log_messages_flag |
| Review PostgreSQL temporary-file logging coverage | ansible/gcp/postgresql_logging_of_temporary_files_disabled |
| PostgreSQL connection logging is disabled | ansible/gcp/postgresql_log_connections_disabled |
| Review PostgreSQL statement-duration logging thresholds | ansible/gcp/postgresql_misconfigured_logging_duration_flag |
| GCP firewall allows unrestricted RDP access | ansible/gcp/rdp_access_is_not_restricted |
| GCP firewall allows SSH from all IPv4 addresses | ansible/gcp/ssh_access_is_not_restricted |
| Encrypting Cloud SQL database connections | ansible/gcp/sql_db_instance_with_ssl_disabled |
| Review Shielded VM protection settings | ansible/gcp/shielded_vm_disabled |
| Interactive serial console is enabled for a VM | ansible/gcp/serial_ports_enabled_for_vm_instances |
| OS Login is disabled on a VM instance | ansible/gcp/oslogin_is_disabled_for_vm_instance |
| Review a VM’s Cloud API scopes and IAM permissions | ansible/gcp/vm_with_full_cloud_access |
| BigQuery access for all authenticated users | ansible/gcp/bigquery_dataset_is_public |
| Compute Engine instance has an external IP | ansible/gcp/compute_instance_is_publicly_accessible |
| Cloud SQL instance needs a network-access configuration review | ansible/gcp/sql_db_instance_is_publicly_accessible |
| Review access allowed by GCP default firewall rules | ansible/gcp/google_compute_network_using_default_firewall_rule |
| Review permissions of a VM’s default service account | ansible/gcp/using_default_service_account |
| Review Compute Engine disk encryption key management | ansible/gcp/disk_encryption_disabled |
| Review Cloud Storage usage logging | ansible/gcp/cloud_storage_bucket_logging_not_enabled |
| Review GKE control plane authentication | ansible/gcp/cluster_master_authentication_disabled |
| GCP firewall rule allows all ports | ansible/gcp/google_compute_network_using_firewall_rule_allows_all_ports |
| Review Cloud Storage object versioning | ansible/gcp/cloud_storage_bucket_versioning_disabled |
| Review the minimum TLS version in a Compute SSL policy | ansible/gcp/google_compute_ssl_policy_weak_cipher_in_use |
| Cloud Storage bucket public access needs review | ansible/gcp/cloud_storage_anonymous_or_publicly_accessible |
| Legacy client certificate authentication in GKE | ansible/gcp/client_certificate_disabled |
| VM instance allows project-wide SSH keys | ansible/gcp/project_wide_ssh_keys_are_enabled_in_vm_instances |