Documentation
| Article | Path |
|---|---|
| Review GKE client certificate settings | googleDeploymentManager/gcp/client_certificate_disabled |
| Review Cloud DNS DNSSEC configuration | googleDeploymentManager/gcp/cloud_dns_without_dnnsec |
| Review Cloud SQL automatic backup settings | googleDeploymentManager/gcp/sql_db_instance_backup_disabled |
| Cloud Storage versioning is disabled | googleDeploymentManager/gcp/cloud_storage_bucket_versioning_disabled |
| Review public Cloud Storage ACL principals | googleDeploymentManager/gcp/cloud_storage_bucket_is_publicly_accessible |
| Review Compute Engine external IP access paths | googleDeploymentManager/gcp/compute_instance_is_publicly_accessible |
| DNSSEC uses RSASHA1 | googleDeploymentManager/gcp/dnssec_using_rsasha1 |
| Legacy ABAC authorization is enabled in GKE | googleDeploymentManager/gcp/gke_legacy_authorization_enabled |
| Review GKE control-plane authorized networks | googleDeploymentManager/gcp/gke_master_authorized_networks_disabled |
| Review GKE node image selection | googleDeploymentManager/gcp/cos_node_image_not_used |
| Review GKE authentication and access permissions | googleDeploymentManager/gcp/cluster_master_authentication_disabled |
| GKE cluster labels are not configured | googleDeploymentManager/gcp/cluster_labels_disabled |
| Review GKE Alias IP allocation | googleDeploymentManager/gcp/ip_aliasing_disabled |
| IP forwarding is enabled | googleDeploymentManager/gcp/ip_forwarding_enabled |
| Review GKE Network Policy enforcement | googleDeploymentManager/gcp/network_policy_disabled |
| Review GKE private cluster settings | googleDeploymentManager/gcp/private_cluster_disabled |
| Firewall rule permits unrestricted RDP access | googleDeploymentManager/gcp/rdp_access_is_not_restricted |
| SSH access is not restricted | googleDeploymentManager/gcp/ssh_access_is_not_restricted |
| Cloud SQL connection encryption settings need review | googleDeploymentManager/gcp/sql_db_instance_with_ssl_disabled |
| Review Shielded VM protection settings | googleDeploymentManager/gcp/shielded_vm_disabled |
| Review GKE Cloud Logging integration | googleDeploymentManager/gcp/stackdriver_logging_disabled |
| Review GKE Cloud Monitoring collection settings | googleDeploymentManager/gcp/stackdriver_monitoring_disabled |
| Uniform bucket-level access is disabled | googleDeploymentManager/gcp/google_storage_bucket_level_access_disabled |
| Review VM instance OS Login settings | googleDeploymentManager/gcp/os_login_is_disabled_for_vm_instance |
| MySQL local_infile is enabled | googleDeploymentManager/gcp/mysql_instance_with_local_infile_on |
| Review GCP IAM user account management | googleDeploymentManager/gcp/not_proper_email_account_in_use |
| BigQuery dataset grants access to a public group | googleDeploymentManager/gcp/bigquery_database_is_public |
| Review GKE node auto-upgrades | googleDeploymentManager/gcp/node_auto_upgrade_disabled |
| Review Compute Engine disk encryption key management | googleDeploymentManager/gcp/disk_encryption_disabled |
| Bucket versioning is not configured | googleDeploymentManager/gcp/bucket_without_versioning |
| Cloud Storage bucket ACLs need review | googleDeploymentManager/gcp/cloud_storage_anonymous_or_publicly_accessible |
| Review VM access through project-wide SSH keys | googleDeploymentManager/gcp/project_wide_ssh_keys_are_enabled_in_vm_instances |