These 81 articles cover Google Cloud resources managed with Terraform.
Documentation
| Article | Path |
|---|---|
| Review GKE node image selection | terraform/gcp/cos_node_image_not_used |
| Review contained database authentication in GCP Cloud SQL | terraform/gcp/sql_db_instance_with_contained_database_authentication |
| Review external script execution in GCP Cloud SQL | terraform/gcp/sql_db_instance_external_scripts_enabled |
| Review Cloud Asset Inventory API enablement | terraform/gcp/cloud_asset_inventory_disabled |
| Review GCP Cloud DNS DNSSEC configuration | terraform/gcp/cloud_dns_without_dnssec |
| Review public IAM grants on a Cloud Storage bucket | terraform/gcp/cloud_storage_bucket_is_publicly_accessible |
| Review Cloud Storage bucket logging | terraform/gcp/cloud_storage_bucket_logging_not_enabled |
| Review Cloud Storage object-version and recovery settings | terraform/gcp/cloud_storage_bucket_versioning_disabled |
| Review GCP DNSSEC signing algorithms | terraform/gcp/dnssec_using_rsasha1 |
| Review the minimum TLS version in a GCP SSL policy | terraform/gcp/google_compute_ssl_policy_weak_cipher_in_use |
| Review access allowed by GCP default firewall rules | terraform/gcp/google_compute_network_using_default_firewall_rule |
| Review GCP disk encryption key management | terraform/gcp/disk_encryption_disabled |
| GCP firewall rule allows all ports | terraform/gcp/google_compute_network_using_firewall_rule_allows_all_ports |
| Review allowed port ranges in a Google Cloud firewall | terraform/gcp/google_compute_network_using_firewall_rule_allows_port_range |
| Review GKE VPC-native networking | terraform/gcp/ip_aliasing_disabled |
| Review GKE node service-account permissions | terraform/gcp/gke_using_default_service_account |
| GKE cluster labels are not configured | terraform/gcp/cluster_labels_disabled |
| Review GCP subnet VPC Flow Logs collection | terraform/gcp/google_compute_subnetwork_logging_disabled |
| Review GKE node pool auto-repair settings | terraform/gcp/google_container_node_pool_auto_repair_disabled |
| Review GCP DNS policy query logging | terraform/gcp/google_dns_policy_logging_disabled |
| Review the Cloud KMS key rotation period | terraform/gcp/high_google_kms_crypto_key_rotation_period |
| Review GCP project default-network creation | terraform/gcp/google_project_auto_create_network_disabled |
| Review Google Cloud Data Access audit-log configuration | terraform/gcp/iam_audit_not_properly_configured |
| GCP instance IP forwarding enabled | terraform/gcp/ip_forwarding_enabled |
| Review separation of Cloud KMS administration and decryption | terraform/gcp/kms_admin_and_crypto_key_roles_in_use |
| Legacy ABAC authorization enabled in GKE | terraform/gcp/gke_legacy_authorization_enabled |
| Review GKE NetworkPolicy enforcement | terraform/gcp/network_policy_disabled |
| Review GKE node auto-upgrade settings | terraform/gcp/node_auto_upgrade_disabled |
| Review GCP project OS Login settings | terraform/gcp/os_login_disabled |
| Review Pod security policy enforcement in GKE | terraform/gcp/pod_security_policy_disabled |
| Review the Cloud SQL PostgreSQL error-statement logging threshold | terraform/gcp/sql_db_instance_with_unrecommended_error_logging_threshold |
| Review the Cloud SQL PostgreSQL server-log threshold | terraform/gcp/sql_db_instance_with_unrecommended_logging_threshold |
| Review Cloud SQL PostgreSQL pgAudit configuration | terraform/gcp/sql_db_instance_without_centralized_logging |
| Review GKE node and control-plane access paths | terraform/gcp/private_cluster_disabled |
| Review Private Google Access for the subnet | terraform/gcp/google_compute_subnetwork_with_private_google_access_disabled |
| Unrestricted RDP access in a GCP firewall | terraform/gcp/rdp_access_is_not_restricted |
| Review remote procedure execution in GCP Cloud SQL | terraform/gcp/sql_db_instance_with_remote_access_enabled |
| Review Cloud SQL automated backup settings | terraform/gcp/sql_db_instance_backup_disabled |
| Review Cloud SQL PostgreSQL connection logging | terraform/gcp/sql_db_instance_without_connections_logging |
| Review Cloud SQL PostgreSQL disconnection logging | terraform/gcp/sql_db_instance_without_disconnections_logging |
| Review Cloud SQL SQL Server session defaults | terraform/gcp/sql_db_instance_with_global_user_options |
| Review Cloud SQL MySQL local file loading | terraform/gcp/sql_db_instance_with_local_data_loading_enabled |
| Review Cloud SQL PostgreSQL duration-based SQL logging | terraform/gcp/sql_db_instance_with_minimum_log_duration |
| Review Cloud SQL SQL Server cross-database ownership chaining | terraform/gcp/sql_db_instance_with_ownership_chaining_enabled |
| Review Cloud SQL MySQL database-listing privileges | terraform/gcp/sql_db_instance_with_exposed_show_privileges |
| Review Cloud SQL SQL Server error-information exposure | terraform/gcp/sql_db_instance_with_exposed_trace_logs |
| Review Cloud SQL SQL Server connection limits | terraform/gcp/sql_db_instance_with_limited_user_connections |
| Review GCP SSH ingress access scope | terraform/gcp/ssh_access_is_not_restricted |
| Encrypted connections not enforced in GCP Cloud SQL | terraform/gcp/sql_db_instance_with_ssl_disabled |
| Review Shielded GKE node protection | terraform/gcp/shielded_gke_nodes_disabled |
| Review Shielded protection settings on GCP VMs | terraform/gcp/shielded_vm_disabled |
| Review GKE Cloud Logging integration | terraform/gcp/stackdriver_logging_disabled |
| Review GKE Cloud Monitoring integration | terraform/gcp/stackdriver_monitoring_disabled |
| GCP Storage Bucket Uniform Bucket-Level Access needs review | terraform/gcp/google_storage_bucket_level_access_disabled |
| Review OS Login disabling overrides on GCP VMs | terraform/gcp/os_login_is_disabled_for_vm_instance |
| Review interactive serial console access on GCP VMs | terraform/gcp/vm_serial_ports_are_enabled_for_vm_instances |
| Review project-wide SSH key access on GCP VMs | terraform/gcp/project_wide_ssh_keys_are_enabled_in_vm_instances |
| Review GCP VM API scopes and IAM permissions | terraform/gcp/vm_with_full_cloud_access |
| Review audit-configuration change logs and alerts | terraform/gcp/logs_and_alerts_missing_audit_configuration_changes |
| Cloud Storage IAM binding permissions need review | terraform/gcp/cloud_storage_anonymous_or_publicly_accessible |
| Broad authenticated-user access to a GCP BigQuery dataset | terraform/gcp/bigquery_dataset_is_public |
| Public permission scope on a GCP KMS Crypto Key needs review | terraform/gcp/kms_crypto_key_publicly_accessible |
| Google Cloud SQL network settings need review | terraform/gcp/sql_db_instance_is_publicly_accessible |
| Review excessive IAM privileges on GCP service accounts | terraform/gcp/service_account_with_improper_privileges |
| Review GCP VM service accounts and effective permissions | terraform/gcp/using_default_service_account |
| Review GCP network type and subnet creation mode | terraform/gcp/legacy_networks_do_not_exist_for_older_google_projects |
| Review legacy client certificates in GKE | terraform/gcp/legacy_client_certificate_auth_enabled |
| Review per-user IAM access management in Google Cloud | terraform/gcp/user_with_iam_role |
| GCP Project IAM Member service-account administration needs review | terraform/gcp/google_project_iam_member_service_account_has_admin_role |
| GCP Project IAM Binding service-account delegation needs review | terraform/gcp/google_project_iam_binding_service_account_has_token_creator_or_account_user_role |
| GCP Project IAM Member service-account delegation needs review | terraform/gcp/google_project_iam_member_service_account_has_token_creator_or_account_user_role |
| Review GKE version support and updates | terraform/gcp/outdated_gke_version |
| Review essential contacts for a Google Cloud organization | terraform/gcp/ensure_essential_contacts_is_configured_for_organization |
| Review organizational management of Google Cloud IAM accounts | terraform/gcp/not_proper_email_account_in_use |
| Review custom-role change logs and alerts | terraform/gcp/logs_and_alerts_missing_custom_role_changes |
| Review project-owner change logs and alerts | terraform/gcp/logs_and_alerts_missing_project_ownership_assignment_and_changes |
| Review GKE network policy support | terraform/gcp/cluster_without_network_policy_support_enabled |
| Review GKE release channels and upgrade schedules | terraform/gcp/ensure_gke_version_management_is_automated_using_release_channels |
| Review Alpha features in a production GKE cluster | terraform/gcp/google_kubernetes_engine_cluster_has_alpha_features_enabled |
| Review legacy GKE Kubernetes Dashboard use | terraform/gcp/kubernetes_web_ui_is_not_disabled |
| Shielded GKE node integrity monitoring disabled | terraform/gcp/shielded_gke_node_do_not_have_integrity_monitoring_enabled |