Description
A new project’s default network and firewall rules may not match organizational requirements. Using them without review can leave unnecessary access paths.
With auto_create_network = false, the provider deletes the default network after its creation. To prevent creation itself, use the supported organization policy compute.skipDefaultNetworkCreation.
Potential impact
- An unreviewed default network can remain in production.
- Unnecessary default firewall rules can expand the attack surface.
Remediation
- Where possible, restrict default-network creation with the organization policy applied to the project.
- When using
auto_create_network = false, account for creation followed by deletion and the required API and network quota. - Define required VPCs and firewalls separately; check dependent resources before removing existing networks.
Examples
These examples compare project-creation settings. Replace project_id and org_id with actual values. A default network can still be created briefly with false; this is not a procedure for indiscriminately deleting existing networks.
Before
hcl
resource "google_project" "project" {
name = "My Project"
project_id = "your-project-id"
org_id = "1234567"
auto_create_network = true
}
After
hcl
resource "google_project" "project" {
name = "My Project"
project_id = "your-project-id"
org_id = "1234567"
auto_create_network = false
}
Explanation:
- Before: The provider is configured to retain the default network. Actual creation also depends on organization policy.
- After: The provider is configured to delete the created default network. Prepare required networks separately.