Review GCP project default-network creation

Check default-network policies and explicitly manage required VPCs and firewall rules.

Description

A new project’s default network and firewall rules may not match organizational requirements. Using them without review can leave unnecessary access paths.

With auto_create_network = false, the provider deletes the default network after its creation. To prevent creation itself, use the supported organization policy compute.skipDefaultNetworkCreation.

Potential impact

  • An unreviewed default network can remain in production.
  • Unnecessary default firewall rules can expand the attack surface.

Remediation

  • Where possible, restrict default-network creation with the organization policy applied to the project.
  • When using auto_create_network = false, account for creation followed by deletion and the required API and network quota.
  • Define required VPCs and firewalls separately; check dependent resources before removing existing networks.

Examples

These examples compare project-creation settings. Replace project_id and org_id with actual values. A default network can still be created briefly with false; this is not a procedure for indiscriminately deleting existing networks.

Before

hcl
resource "google_project" "project" {
  name                = "My Project"
  project_id          = "your-project-id"
  org_id              = "1234567"
  auto_create_network = true
}

After

hcl
resource "google_project" "project" {
  name                = "My Project"
  project_id          = "your-project-id"
  org_id              = "1234567"
  auto_create_network = false
}

Explanation:

  • Before: The provider is configured to retain the default network. Actual creation also depends on organization policy.
  • After: The provider is configured to delete the created default network. Prepare required networks separately.

References