Review Cloud Asset Inventory API enablement

Configure the API and permissions needed for asset queries and exports.

Description

When the Cloud Asset Inventory API is disabled, queries and exports through that API are restricted. Enabling it is a prerequisite for access; it does not itself schedule exports or change notifications, or guarantee that every asset is current.

Potential impact

  • Central reviews of assets and IAM policies may fail or be delayed.
  • Without another inventory system, unnoticed resources or excessive permissions can be harder to find.

Remediation

  • Enable cloudasset.googleapis.com in the required project and grant the least IAM permissions needed for the query scope. Keep other required APIs enabled.
  • Check supported asset types and update timestamps. Configure exports or feeds separately when scheduled retention or change notifications are needed, and verify the results.

Examples

These excerpts assume the project is supplied through the provider or equivalent configuration. The existing Compute API resource is retained and Asset Inventory is added as a separate resource.

Before

hcl
resource "google_project_service" "example" {
  service = "compute.googleapis.com"
}

After

hcl
resource "google_project_service" "example" {
  service = "compute.googleapis.com"
}

resource "google_project_service" "asset_inventory" {
  service = "cloudasset.googleapis.com"
}

Explanation:

  • Before: Only the Compute API is managed here. Check the actual enablement of other APIs separately.
  • After: Asset Inventory is enabled while retaining Compute. Query permissions and export schedules are separate settings.

References