GCP

Security and configuration guidance for Google Cloud resources managed with Terraform.

These 81 articles cover Google Cloud resources managed with Terraform.

Documentation

Article Path
Review GKE node image selection terraform/gcp/cos_node_image_not_used
Review contained database authentication in GCP Cloud SQL terraform/gcp/sql_db_instance_with_contained_database_authentication
Review external script execution in GCP Cloud SQL terraform/gcp/sql_db_instance_external_scripts_enabled
Review Cloud Asset Inventory API enablement terraform/gcp/cloud_asset_inventory_disabled
Review GCP Cloud DNS DNSSEC configuration terraform/gcp/cloud_dns_without_dnssec
Review public IAM grants on a Cloud Storage bucket terraform/gcp/cloud_storage_bucket_is_publicly_accessible
Review Cloud Storage bucket logging terraform/gcp/cloud_storage_bucket_logging_not_enabled
Review Cloud Storage object-version and recovery settings terraform/gcp/cloud_storage_bucket_versioning_disabled
Review GCP DNSSEC signing algorithms terraform/gcp/dnssec_using_rsasha1
Review the minimum TLS version in a GCP SSL policy terraform/gcp/google_compute_ssl_policy_weak_cipher_in_use
Review access allowed by GCP default firewall rules terraform/gcp/google_compute_network_using_default_firewall_rule
Review GCP disk encryption key management terraform/gcp/disk_encryption_disabled
GCP firewall rule allows all ports terraform/gcp/google_compute_network_using_firewall_rule_allows_all_ports
Review allowed port ranges in a Google Cloud firewall terraform/gcp/google_compute_network_using_firewall_rule_allows_port_range
Review GKE VPC-native networking terraform/gcp/ip_aliasing_disabled
Review GKE node service-account permissions terraform/gcp/gke_using_default_service_account
GKE cluster labels are not configured terraform/gcp/cluster_labels_disabled
Review GCP subnet VPC Flow Logs collection terraform/gcp/google_compute_subnetwork_logging_disabled
Review GKE node pool auto-repair settings terraform/gcp/google_container_node_pool_auto_repair_disabled
Review GCP DNS policy query logging terraform/gcp/google_dns_policy_logging_disabled
Review the Cloud KMS key rotation period terraform/gcp/high_google_kms_crypto_key_rotation_period
Review GCP project default-network creation terraform/gcp/google_project_auto_create_network_disabled
Review Google Cloud Data Access audit-log configuration terraform/gcp/iam_audit_not_properly_configured
GCP instance IP forwarding enabled terraform/gcp/ip_forwarding_enabled
Review separation of Cloud KMS administration and decryption terraform/gcp/kms_admin_and_crypto_key_roles_in_use
Legacy ABAC authorization enabled in GKE terraform/gcp/gke_legacy_authorization_enabled
Review GKE NetworkPolicy enforcement terraform/gcp/network_policy_disabled
Review GKE node auto-upgrade settings terraform/gcp/node_auto_upgrade_disabled
Review GCP project OS Login settings terraform/gcp/os_login_disabled
Review Pod security policy enforcement in GKE terraform/gcp/pod_security_policy_disabled
Review the Cloud SQL PostgreSQL error-statement logging threshold terraform/gcp/sql_db_instance_with_unrecommended_error_logging_threshold
Review the Cloud SQL PostgreSQL server-log threshold terraform/gcp/sql_db_instance_with_unrecommended_logging_threshold
Review Cloud SQL PostgreSQL pgAudit configuration terraform/gcp/sql_db_instance_without_centralized_logging
Review GKE node and control-plane access paths terraform/gcp/private_cluster_disabled
Review Private Google Access for the subnet terraform/gcp/google_compute_subnetwork_with_private_google_access_disabled
Unrestricted RDP access in a GCP firewall terraform/gcp/rdp_access_is_not_restricted
Review remote procedure execution in GCP Cloud SQL terraform/gcp/sql_db_instance_with_remote_access_enabled
Review Cloud SQL automated backup settings terraform/gcp/sql_db_instance_backup_disabled
Review Cloud SQL PostgreSQL connection logging terraform/gcp/sql_db_instance_without_connections_logging
Review Cloud SQL PostgreSQL disconnection logging terraform/gcp/sql_db_instance_without_disconnections_logging
Review Cloud SQL SQL Server session defaults terraform/gcp/sql_db_instance_with_global_user_options
Review Cloud SQL MySQL local file loading terraform/gcp/sql_db_instance_with_local_data_loading_enabled
Review Cloud SQL PostgreSQL duration-based SQL logging terraform/gcp/sql_db_instance_with_minimum_log_duration
Review Cloud SQL SQL Server cross-database ownership chaining terraform/gcp/sql_db_instance_with_ownership_chaining_enabled
Review Cloud SQL MySQL database-listing privileges terraform/gcp/sql_db_instance_with_exposed_show_privileges
Review Cloud SQL SQL Server error-information exposure terraform/gcp/sql_db_instance_with_exposed_trace_logs
Review Cloud SQL SQL Server connection limits terraform/gcp/sql_db_instance_with_limited_user_connections
Review GCP SSH ingress access scope terraform/gcp/ssh_access_is_not_restricted
Encrypted connections not enforced in GCP Cloud SQL terraform/gcp/sql_db_instance_with_ssl_disabled
Review Shielded GKE node protection terraform/gcp/shielded_gke_nodes_disabled
Review Shielded protection settings on GCP VMs terraform/gcp/shielded_vm_disabled
Review GKE Cloud Logging integration terraform/gcp/stackdriver_logging_disabled
Review GKE Cloud Monitoring integration terraform/gcp/stackdriver_monitoring_disabled
GCP Storage Bucket Uniform Bucket-Level Access needs review terraform/gcp/google_storage_bucket_level_access_disabled
Review OS Login disabling overrides on GCP VMs terraform/gcp/os_login_is_disabled_for_vm_instance
Review interactive serial console access on GCP VMs terraform/gcp/vm_serial_ports_are_enabled_for_vm_instances
Review project-wide SSH key access on GCP VMs terraform/gcp/project_wide_ssh_keys_are_enabled_in_vm_instances
Review GCP VM API scopes and IAM permissions terraform/gcp/vm_with_full_cloud_access
Review audit-configuration change logs and alerts terraform/gcp/logs_and_alerts_missing_audit_configuration_changes
Cloud Storage IAM binding permissions need review terraform/gcp/cloud_storage_anonymous_or_publicly_accessible
Broad authenticated-user access to a GCP BigQuery dataset terraform/gcp/bigquery_dataset_is_public
Public permission scope on a GCP KMS Crypto Key needs review terraform/gcp/kms_crypto_key_publicly_accessible
Google Cloud SQL network settings need review terraform/gcp/sql_db_instance_is_publicly_accessible
Review excessive IAM privileges on GCP service accounts terraform/gcp/service_account_with_improper_privileges
Review GCP VM service accounts and effective permissions terraform/gcp/using_default_service_account
Review GCP network type and subnet creation mode terraform/gcp/legacy_networks_do_not_exist_for_older_google_projects
Review legacy client certificates in GKE terraform/gcp/legacy_client_certificate_auth_enabled
Review per-user IAM access management in Google Cloud terraform/gcp/user_with_iam_role
GCP Project IAM Member service-account administration needs review terraform/gcp/google_project_iam_member_service_account_has_admin_role
GCP Project IAM Binding service-account delegation needs review terraform/gcp/google_project_iam_binding_service_account_has_token_creator_or_account_user_role
GCP Project IAM Member service-account delegation needs review terraform/gcp/google_project_iam_member_service_account_has_token_creator_or_account_user_role
Review GKE version support and updates terraform/gcp/outdated_gke_version
Review essential contacts for a Google Cloud organization terraform/gcp/ensure_essential_contacts_is_configured_for_organization
Review organizational management of Google Cloud IAM accounts terraform/gcp/not_proper_email_account_in_use
Review custom-role change logs and alerts terraform/gcp/logs_and_alerts_missing_custom_role_changes
Review project-owner change logs and alerts terraform/gcp/logs_and_alerts_missing_project_ownership_assignment_and_changes
Review GKE network policy support terraform/gcp/cluster_without_network_policy_support_enabled
Review GKE release channels and upgrade schedules terraform/gcp/ensure_gke_version_management_is_automated_using_release_channels
Review Alpha features in a production GKE cluster terraform/gcp/google_kubernetes_engine_cluster_has_alpha_features_enabled
Review legacy GKE Kubernetes Dashboard use terraform/gcp/kubernetes_web_ui_is_not_disabled
Shielded GKE node integrity monitoring disabled terraform/gcp/shielded_gke_node_do_not_have_integrity_monitoring_enabled

Related pages81

Review GKE node image selection

Choose a supported image for the workload and manage node operating-system updates.

Review contained database authentication in GCP Cloud SQL

Disable SQL Server database-level authentication when it is unnecessary

Review external script execution in GCP Cloud SQL

Disable unused SQL Server external script execution

Review Cloud Asset Inventory API enablement

Configure the API and permissions needed for asset queries and exports.

Review GCP Cloud DNS DNSSEC configuration

Configure public-zone signing and parent DS records together.

Review public IAM grants on a Cloud Storage bucket

Expose only the data and operations intended for public use, and separate internal content.

Review Cloud Storage bucket logging

Choose the operation records and usage logs needed for investigations and verify receipt.

Review Cloud Storage object-version and recovery settings

Configure Object Versioning and soft delete to meet recovery requirements.

Review GCP DNSSEC signing algorithms

Migrate to a recommended DNSSEC algorithm while preserving the trust chain.

Review the minimum TLS version in a GCP SSL policy

Review minimum TLS versions and cipher suites together, and associate the policy with the actual proxy.

Review access allowed by GCP default firewall rules

Review actual sources, targets, protocols and ports rather than relying on a rule name.

Review GCP disk encryption key management

Distinguish default encryption from customer-controlled keys and check organizational requirements.

GCP firewall rule allows all ports

Limit ingress rules to required ports and approved source ranges.

Review allowed port ranges in a Google Cloud firewall

Allow only the ports, sources and targets required by the service.

Review GKE VPC-native networking

Plan Pod and Service address ranges and check the cluster’s actual networking mode.

Review GKE node service-account permissions

Grant a dedicated node service account only the IAM roles the nodes require.

GKE cluster labels are not configured

Without labels, GKE clusters can be harder to classify, allocate costs for and manage through automation.

Review GCP subnet VPC Flow Logs collection

Verify that the required network flow records are actually collected.

Review GKE node pool auto-repair settings

Combine node auto-repair with failure monitoring to reduce prolonged outages.

Review GCP DNS policy query logging

Associate the DNS logging policy with its VPC and verify actual query records.

Review the Cloud KMS key rotation period

Rotate keys according to policy and plan how to handle earlier versions and data.

Review GCP project default-network creation

Check default-network policies and explicitly manage required VPCs and firewall rules.

Review Google Cloud Data Access audit-log configuration

Enable required data-access records and remove unnecessary audit exemptions.

GCP instance IP forwarding enabled

Allow IP forwarding only on VMs that require routing.

Review separation of Cloud KMS administration and decryption

Separate key administrators from principals that decrypt data.

Legacy ABAC authorization enabled in GKE

Disable legacy ABAC and use fine-grained access control in GKE

Review GKE NetworkPolicy enforcement

Configure both network policy enforcement and the policies defining permitted traffic.

Review GKE node auto-upgrade settings

Check node upgrade policies so security patches and supported versions are maintained.

Review GCP project OS Login settings

Manage SSH access to supported VMs through IAM and check instance overrides.

Review Pod security policy enforcement in GKE

Use supported policy features to restrict risky Pod settings and verify enforcement.

Review the Cloud SQL PostgreSQL error-statement logging threshold

Record SQL needed for error investigations while managing sensitive content and log volume.

Review the Cloud SQL PostgreSQL server-log threshold

Retain required server messages while reducing unnecessary log volume.

Review Cloud SQL PostgreSQL pgAudit configuration

Audit required database operations and verify that logs are received.

Review GKE node and control-plane access paths

Restrict node external IPs and control-plane access paths separately to the required scope.

Review Private Google Access for the subnet

Provide the required Google API path for VMs without external IP addresses.

Unrestricted RDP access in a GCP firewall

RDP port 3389 is open to the entire internet

Review remote procedure execution in GCP Cloud SQL

Disable unused SQL Server procedure execution between servers

Review Cloud SQL automated backup settings

Enable backups suited to recovery objectives and verify that restoration works.

Review Cloud SQL PostgreSQL connection logging

Collect required connection history and verify delivery and retention.

Review Cloud SQL PostgreSQL disconnection logging

Record required session termination history and session duration.

Review Cloud SQL SQL Server session defaults

Compare user options with application requirements and test changes.

Review Cloud SQL MySQL local file loading

Disable unneeded LOAD DATA LOCAL use and limit client file access.

Review Cloud SQL PostgreSQL duration-based SQL logging

Balance diagnostic needs with the sensitivity of SQL content.

Review Cloud SQL SQL Server cross-database ownership chaining

Disable unnecessary cross-database ownership chaining and use explicit permissions.

Review Cloud SQL MySQL database-listing privileges

Limit database-name visibility to accounts that need it.

Review Cloud SQL SQL Server error-information exposure

Reduce unnecessary error details returned to ordinary users.

Review Cloud SQL SQL Server connection limits

Set connection limits suited to expected load and instance capacity.

Review GCP SSH ingress access scope

Restrict SSH administration to approved sources and target VMs.

Encrypted connections not enforced in GCP Cloud SQL

Require SSL/TLS encryption for direct Cloud SQL connections

Review Shielded GKE node protection

Enable node identity protection and check separate boot-protection settings.