GCP

Security and configuration guidance for Google Cloud resources managed with Ansible.

Documentation

Article Path
Review Cloud SQL automatic backups ansible/gcp/sql_db_instance_backup_disabled
Cloud SQL contained database authentication is enabled ansible/gcp/cloud_sql_instance_with_contained_database_authentication_on
Cross-database ownership chaining is enabled in Cloud SQL ansible/gcp/cloud_sql_instance_with_cross_db_ownership_chaining_on
Review Cloud DNS DNSSEC settings ansible/gcp/cloud_dns_without_dnnsec
Review Cloud DNS DNSSEC signing algorithms ansible/gcp/dnssec_using_rsasha1
Review GCP firewall port ranges ansible/gcp/google_compute_network_using_firewall_allows_port_range
Review subnet Private Google Access settings ansible/gcp/google_compute_subnetwork_with_private_google_access_disabled
Review GKE VPC-native networking settings ansible/gcp/ip_aliasing_disabled
Review authorized networks for the GKE control plane ansible/gcp/gke_master_authorized_networks_disabled
GKE nodes use the default service account ansible/gcp/gke_using_default_service_account
Review legacy Basic authentication settings in GKE ansible/gcp/gke_basic_authentication_enabled
Review network policy enforcement in GKE ansible/gcp/network_policy_disabled
Review GKE node auto-upgrade settings ansible/gcp/node_auto_upgrade_disabled
Review GKE node pool auto-repair settings ansible/gcp/google_container_node_pool_auto_repair_disabled
Review GKE node image selection ansible/gcp/cos_node_image_not_used
GKE logging is disabled ansible/gcp/stackdriver_logging_disabled
GKE monitoring is disabled ansible/gcp/stackdriver_monitoring_disabled
GKE cluster labels are missing ansible/gcp/cluster_labels_disabled
Review public access to GKE nodes and the control plane ansible/gcp/private_cluster_disabled
IP forwarding is enabled on a Compute Engine VM ansible/gcp/ip_forwarding_enabled
Review Cloud KMS key rotation periods ansible/gcp/high_google_kms_crypto_key_rotation_period
GKE cluster configuration enables legacy ABAC ansible/gcp/gke_legacy_authorization_enabled
Cloud SQL MySQL permits local file loading ansible/gcp/mysql_instance_with_local_infile_on
PostgreSQL checkpoint logging is disabled ansible/gcp/postgresql_log_checkpoints_flag_not_set_to_on
Review PostgreSQL server log levels ansible/gcp/postgresql_misconfigured_log_messages_flag
Review PostgreSQL temporary-file logging coverage ansible/gcp/postgresql_logging_of_temporary_files_disabled
PostgreSQL connection logging is disabled ansible/gcp/postgresql_log_connections_disabled
Review PostgreSQL statement-duration logging thresholds ansible/gcp/postgresql_misconfigured_logging_duration_flag
GCP firewall allows unrestricted RDP access ansible/gcp/rdp_access_is_not_restricted
GCP firewall allows SSH from all IPv4 addresses ansible/gcp/ssh_access_is_not_restricted
Encrypting Cloud SQL database connections ansible/gcp/sql_db_instance_with_ssl_disabled
Review Shielded VM protection settings ansible/gcp/shielded_vm_disabled
Interactive serial console is enabled for a VM ansible/gcp/serial_ports_enabled_for_vm_instances
OS Login is disabled on a VM instance ansible/gcp/oslogin_is_disabled_for_vm_instance
Review a VM’s Cloud API scopes and IAM permissions ansible/gcp/vm_with_full_cloud_access
BigQuery access for all authenticated users ansible/gcp/bigquery_dataset_is_public
Compute Engine instance has an external IP ansible/gcp/compute_instance_is_publicly_accessible
Cloud SQL instance needs a network-access configuration review ansible/gcp/sql_db_instance_is_publicly_accessible
Review access allowed by GCP default firewall rules ansible/gcp/google_compute_network_using_default_firewall_rule
Review permissions of a VM’s default service account ansible/gcp/using_default_service_account
Review Compute Engine disk encryption key management ansible/gcp/disk_encryption_disabled
Review Cloud Storage usage logging ansible/gcp/cloud_storage_bucket_logging_not_enabled
Review GKE control plane authentication ansible/gcp/cluster_master_authentication_disabled
GCP firewall rule allows all ports ansible/gcp/google_compute_network_using_firewall_rule_allows_all_ports
Review Cloud Storage object versioning ansible/gcp/cloud_storage_bucket_versioning_disabled
Review the minimum TLS version in a Compute SSL policy ansible/gcp/google_compute_ssl_policy_weak_cipher_in_use
Cloud Storage bucket public access needs review ansible/gcp/cloud_storage_anonymous_or_publicly_accessible
Legacy client certificate authentication in GKE ansible/gcp/client_certificate_disabled
VM instance allows project-wide SSH keys ansible/gcp/project_wide_ssh_keys_are_enabled_in_vm_instances

Related pages49

Review Cloud SQL automatic backups

Configure a supported backup method and retention policy, and verify that restoration works.

Cloud SQL contained database authentication is enabled

Contained database authentication allows access to be managed within the database. Review whether it is needed and who can manage database users.

Cross-database ownership chaining is enabled in Cloud SQL

Cross-database ownership chaining affects permission checks on objects in other databases. Review existing dependencies and remove unnecessary chains.

Review Cloud DNS DNSSEC settings

Configure DNSSEC and the parent trust chain so public DNS responses can be validated.

Review Cloud DNS DNSSEC signing algorithms

Use a recommended DNSSEC signing algorithm and preserve the trust chain during migration.

Review GCP firewall port ranges

Allow only the ports, sources and targets required by the service.

Review subnet Private Google Access settings

Check Private Google Access and Google API connectivity for VMs without external IP addresses.

Review GKE VPC-native networking settings

Review VPC-native networking and Pod and Service address planning in GKE.

Review authorized networks for the GKE control plane

Limit access to GKE control plane IP endpoints to required management networks.

GKE nodes use the default service account

Use a dedicated GKE node service account with only the roles the nodes require.

Review legacy Basic authentication settings in GKE

Remove obsolete Basic authentication settings and login procedures from GKE configurations.

Review network policy enforcement in GKE

Deploy required NetworkPolicies in GKE and verify that traffic restrictions take effect.

Review GKE node auto-upgrade settings

Review GKE node auto-upgrades and the schedule for security updates.

Review GKE node pool auto-repair settings

Review GKE node auto-repair together with failure monitoring.

Review GKE node image selection

Choose node images that meet workload OS requirements and support policies.

GKE logging is disabled

Verify collection of the system and workload logs needed for GKE.

GKE monitoring is disabled

Collect the GKE metrics you need and connect them to operational alerts.

GKE cluster labels are missing

Maintain consistent cluster labels identifying the environment and responsible team.

Review public access to GKE nodes and the control plane

Review external IPs on GKE nodes and access paths to the control plane separately, and permit only required administration paths.

IP forwarding is enabled on a Compute Engine VM

Disable IP forwarding on VMs that do not serve as routers or network appliances, and manage necessary exceptions.

Review Cloud KMS key rotation periods

Rotate key versions according to policy and retain versions needed to decrypt existing data.

GKE cluster configuration enables legacy ABAC

Legacy ABAC in GKE adds permissions beyond IAM and RBAC. Prepare the required permissions, disable ABAC, and verify access on the actual cluster.

Cloud SQL MySQL permits local file loading

LOAD DATA LOCAL transfers files from the client host to MySQL. Disable unnecessary imports and control client file access and server-identity verification.

PostgreSQL checkpoint logging is disabled

Use Cloud SQL for PostgreSQL checkpoint logs to investigate write load and performance.

Review PostgreSQL server log levels

Choose the PostgreSQL server message level required for operations, avoiding invalid values and excessive or insufficient logging.

Review PostgreSQL temporary-file logging coverage

Choose a PostgreSQL temporary-file logging threshold that fits operational needs, then check log volume and access controls.

PostgreSQL connection logging is disabled

Use Cloud SQL for PostgreSQL connection logs to examine account access history.

Review PostgreSQL statement-duration logging thresholds

Choose a PostgreSQL duration-logging threshold that balances diagnostic needs and log volume, and protect logs containing SQL text.

GCP firewall allows unrestricted RDP access

Allowing RDP from every address exposes reachable services to unnecessary authentication attempts and attacks. Limit access to the sources and paths needed for administration.

GCP firewall allows SSH from all IPv4 addresses

Restrict SSH administration to approved sources and target VMs, and retain strong authentication.

Encrypting Cloud SQL database connections

Protect database connections with SSL/TLS and verify the server identity. Select settings that match the Cloud SQL engine and the actual connection path.

Review Shielded VM protection settings

Configure boot-integrity protection on supported VM images.

Interactive serial console is enabled for a VM

Disable interactive serial-console access when it is unnecessary.

OS Login is disabled on a VM instance

Use OS Login on supported Linux VMs to manage SSH access through IAM and grant only required permissions.

Review a VM’s Cloud API scopes and IAM permissions

Review the VM’s OAuth scopes together with its service account’s IAM roles.

BigQuery access for all authenticated users

Granting BigQuery access to allAuthenticatedUsers can expose data to authenticated users outside your organization. Limit access to the identities and roles that are needed.

Compute Engine instance has an external IP

Confirm whether the VM needs an external IP, and restrict firewall access, administration paths, and service authentication.

Cloud SQL instance needs a network-access configuration review

Review Cloud SQL IP settings and authorized networks so only the required clients can connect.

Review access allowed by GCP default firewall rules

Review the sources, targets, and ports allowed by default firewall rules, and limit them to business needs.

Review permissions of a VM’s default service account

Configure a service account and least-privilege permissions for the VM’s purpose.

Review Compute Engine disk encryption key management

Verify default encryption and configure key permissions and recovery when customer control is required.

Review Cloud Storage usage logging

Collect logs for the audit purpose and manage their access and retention.

Review GKE control plane authentication

Review authentication and IAM and RBAC permissions for the GKE control plane.

GCP firewall rule allows all ports

Limit allowed TCP and UDP ports to required services, and review firewall sources and targets as well.

Review Cloud Storage object versioning

Configure protection for object history and deletion recovery requirements.

Review the minimum TLS version in a Compute SSL policy

Restrict older TLS connections while preserving required client compatibility.

Cloud Storage bucket public access needs review

Review public Cloud Storage permissions and limit access to the required buckets, objects and operations.

Legacy client certificate authentication in GKE

Use recommended GKE authentication and manage access granted to existing legacy client certificates.

VM instance allows project-wide SSH keys

For VMs using metadata-based SSH, review the need for project-wide keys and allow only required instance access.