GCP

Guidance on GCP access controls, networking, data protection and operations in existing Deployment Manager templates.

Documentation

Article Path
Review GKE client certificate settings googleDeploymentManager/gcp/client_certificate_disabled
Review Cloud DNS DNSSEC configuration googleDeploymentManager/gcp/cloud_dns_without_dnnsec
Review Cloud SQL automatic backup settings googleDeploymentManager/gcp/sql_db_instance_backup_disabled
Cloud Storage versioning is disabled googleDeploymentManager/gcp/cloud_storage_bucket_versioning_disabled
Review public Cloud Storage ACL principals googleDeploymentManager/gcp/cloud_storage_bucket_is_publicly_accessible
Review Compute Engine external IP access paths googleDeploymentManager/gcp/compute_instance_is_publicly_accessible
DNSSEC uses RSASHA1 googleDeploymentManager/gcp/dnssec_using_rsasha1
Legacy ABAC authorization is enabled in GKE googleDeploymentManager/gcp/gke_legacy_authorization_enabled
Review GKE control-plane authorized networks googleDeploymentManager/gcp/gke_master_authorized_networks_disabled
Review GKE node image selection googleDeploymentManager/gcp/cos_node_image_not_used
Review GKE authentication and access permissions googleDeploymentManager/gcp/cluster_master_authentication_disabled
GKE cluster labels are not configured googleDeploymentManager/gcp/cluster_labels_disabled
Review GKE Alias IP allocation googleDeploymentManager/gcp/ip_aliasing_disabled
IP forwarding is enabled googleDeploymentManager/gcp/ip_forwarding_enabled
Review GKE Network Policy enforcement googleDeploymentManager/gcp/network_policy_disabled
Review GKE private cluster settings googleDeploymentManager/gcp/private_cluster_disabled
Firewall rule permits unrestricted RDP access googleDeploymentManager/gcp/rdp_access_is_not_restricted
SSH access is not restricted googleDeploymentManager/gcp/ssh_access_is_not_restricted
Cloud SQL connection encryption settings need review googleDeploymentManager/gcp/sql_db_instance_with_ssl_disabled
Review Shielded VM protection settings googleDeploymentManager/gcp/shielded_vm_disabled
Review GKE Cloud Logging integration googleDeploymentManager/gcp/stackdriver_logging_disabled
Review GKE Cloud Monitoring collection settings googleDeploymentManager/gcp/stackdriver_monitoring_disabled
Uniform bucket-level access is disabled googleDeploymentManager/gcp/google_storage_bucket_level_access_disabled
Review VM instance OS Login settings googleDeploymentManager/gcp/os_login_is_disabled_for_vm_instance
MySQL local_infile is enabled googleDeploymentManager/gcp/mysql_instance_with_local_infile_on
Review GCP IAM user account management googleDeploymentManager/gcp/not_proper_email_account_in_use
BigQuery dataset grants access to a public group googleDeploymentManager/gcp/bigquery_database_is_public
Review GKE node auto-upgrades googleDeploymentManager/gcp/node_auto_upgrade_disabled
Review Compute Engine disk encryption key management googleDeploymentManager/gcp/disk_encryption_disabled
Bucket versioning is not configured googleDeploymentManager/gcp/bucket_without_versioning
Cloud Storage bucket ACLs need review googleDeploymentManager/gcp/cloud_storage_anonymous_or_publicly_accessible
Review VM access through project-wide SSH keys googleDeploymentManager/gcp/project_wide_ssh_keys_are_enabled_in_vm_instances

Related pages32

Review GKE client certificate settings

Use recommended authentication and least-privilege authorization for GKE access.

Review Cloud DNS DNSSEC configuration

Configure public-zone signing together with the parent DS records.

Review Cloud SQL automatic backup settings

Verify Cloud SQL automatic backups and actual restore capability against recovery objectives.

Cloud Storage versioning is disabled

Review earlier object version retention and recovery policies in Cloud Storage.

Review public Cloud Storage ACL principals

Review the permissions granted to public ACL principals and the resulting data access.

Review Compute Engine external IP access paths

Check whether Compute Engine needs an external IP and verify its effective inbound access.

DNSSEC uses RSASHA1

Review DNSSEC signing algorithms and preserve the chain of trust during key changes.

Legacy ABAC authorization is enabled in GKE

Migrate required access to RBAC before disabling legacy GKE ABAC authorization.

Review GKE control-plane authorized networks

Limit IP access to the GKE control plane to the management networks that need it.

Review GKE node image selection

Choose a supported GKE node image for the workload and maintain node updates.

Review GKE authentication and access permissions

Review supported GKE authentication and least privilege without re-enabling removed basic authentication.

GKE cluster labels are not configured

Maintain consistent labels identifying each cluster’s environment and responsible team.

Review GKE Alias IP allocation

Check GKE address allocation and pod ranges against the network design.

IP forwarding is enabled

Disable IP forwarding on Compute Engine VMs that do not need to forward packets.

Review GKE Network Policy enforcement

Check how GKE enforces network policies and which workload connections are allowed.

Review GKE private cluster settings

Review the actual network paths to GKE nodes and the control plane, and allow only required access.

Firewall rule permits unrestricted RDP access

Limit RDP administration to required administrators and controlled network paths.

SSH access is not restricted

Restrict SSH to approved management paths instead of allowing the entire internet.

Cloud SQL connection encryption settings need review

Require encrypted database connections and verify that clients validate the server certificate.

Review Shielded VM protection settings

Check effective Shielded VM protections and boot-image compatibility.

Review GKE Cloud Logging integration

Enable required GKE log collection and verify delivery and retention.

Review GKE Cloud Monitoring collection settings

Check effective GKE metric collection and alerting policies.

Uniform bucket-level access is disabled

Migrate required ACL permissions before consolidating Cloud Storage access in IAM.

Review VM instance OS Login settings

Check effective OS Login settings together with SSH access permissions.

MySQL local_infile is enabled

Restrict unnecessary file transfers on both the server and client when LOAD DATA LOCAL is not required.

Review GCP IAM user account management

Verify account ownership and access-removal procedures for users of business resources.

BigQuery dataset grants access to a public group

Grant BigQuery dataset access only to the users and groups that need it.

Review GKE node auto-upgrades

Check effective GKE node auto-upgrade settings and maintenance procedures.

Review Compute Engine disk encryption key management

Distinguish default storage encryption from customer key control and apply the required key policy.

Bucket versioning is not configured

Configure object versioning and other recovery controls to meet data retention needs.

Cloud Storage bucket ACLs need review

Review effective Cloud Storage ACL and IAM permissions and remove unnecessary public access. Omitting an ACL does not itself make a bucket public.

Review VM access through project-wide SSH keys

Restrict project-wide keys on VMs that use metadata-based SSH authentication.