Description
Custom IAM roles support permissions tailored to an organization, but incorrect changes can introduce excessive access. Without logs and alerts for role creation, modification, deletion and restoration, these changes can be missed.
Potential impact
- Excessive permissions or removal of required roles may be discovered late.
- Investigating access-control changes and verifying approval can take longer.
Remediation
- Configure a metric filter covering the actual
iam_roleresource type and theCreateRole,DeleteRole,UpdateRoleandUndeleteRoleevents. - Set an alert condition referencing that metric and configure
notification_channels. Verify receipt with an authorized test change. Alerts alone do not block role changes.
Examples
These excerpts compare part of the configuration; the initial alert configuration is incomplete. For the revised example, supply var.audit_monitored_resource_type with a monitored resource type actually present in the metric, and configure the channel and project separately. Adjust the evaluation window for ingestion delay and operational needs.
Before
hcl
resource "google_logging_metric" "custom_role_change" {
name = "custom_role_change"
description = "Detects custom role changes"
filter = <<-FILTER
resource.type="Wrong_type"
AND (protoPayload.methodName = "google.iam.admin.v1.CreateRole" OR
protoPayload.methodName="google.iam.admin.v1.DeleteRole" OR
protoPayload.methodName="google.iam.admin.v1.UpdateRole" OR
protoPayload.methodName="google.iam.admin.v1.UndeleteRole")
FILTER
}
resource "google_monitoring_alert_policy" "custom_role_alert" {
display_name = "Custom Role Change Alert"
combiner = "OR"
}
After
hcl
resource "google_logging_metric" "custom_role_change" {
name = "custom_role_change"
description = "Detects custom role changes"
filter = <<-FILTER
resource.type="iam_role"
AND (protoPayload.methodName = "google.iam.admin.v1.CreateRole" OR
protoPayload.methodName="google.iam.admin.v1.DeleteRole" OR
protoPayload.methodName="google.iam.admin.v1.UpdateRole" OR
protoPayload.methodName="google.iam.admin.v1.UndeleteRole")
FILTER
}
resource "google_monitoring_alert_policy" "custom_role_alert" {
display_name = "Custom Role Change Alert"
combiner = "OR"
notification_channels = [google_monitoring_notification_channel.security_ops.name]
conditions {
display_name = "Matching audit events"
condition_threshold {
filter = "metric.type=\"logging.googleapis.com/user/${google_logging_metric.custom_role_change.name}\" AND resource.type=\"${var.audit_monitored_resource_type}\""
comparison = "COMPARISON_GT"
threshold_value = 0
duration = "0s"
aggregations {
alignment_period = "600s"
per_series_aligner = "ALIGN_SUM"
}
}
}
}
Explanation:
- Before: The incorrect resource type can exclude role changes, and the alert has no condition.
- After: A metric condition and notification channel are configured for role changes. Verify that logs from the required project or organization are collected.