GCP Pub/Sub Topic resource inventory

Maintain Pub/Sub topic and subscription relationships, permissions and message-protection policies.

Description

Including Pub/Sub topics in the asset inventory helps trace messaging paths and review encryption keys and publishing or subscription permissions. A topic's presence is not itself a vulnerability.

Pub/Sub encrypts stored messages by default; the absence of customer-managed encryption keys (CMEK) does not mean encryption is disabled. Manage permission to publish to a topic separately from permission to consume messages from a subscription.

Potential impact

  • Missing messaging assets can escape access and message-retention policy reviews.
  • Asynchronous message paths can become harder to trace during audits or incident response.

Remediation

Record topics, connected subscriptions and responsible teams in the asset inventory. Review publisher and subscriber permissions and retention policies. If CMEK is required, manage the service agent's key permissions and key availability.

Examples

These excerpts use the historical Deployment Manager format, whose support has ended. Both encrypt stored messages; the after example specifies a customer-managed key. Replace the illustrative key with an actual usable key.

Before

yaml
resources:
  - type: pubsub.v1.topic
    name: topic-1
    properties:
      topic: classified-topic

After

yaml
resources:
  - type: pubsub.v1.topic
    name: topic-1
    properties:
      topic: classified-topic
      kmsKeyName: projects/example/locations/global/keyRings/ring/cryptoKeys/key

Explanation:

  • Before: The topic uses default encryption.
  • After: CMEK is specified. This does not configure publishing or subscription permissions or message retention.

References