Review custom-role change logs and alerts

Track creation, modification, deletion and restoration of custom IAM roles.

Description

Custom IAM roles support permissions tailored to an organization, but incorrect changes can introduce excessive access. Without logs and alerts for role creation, modification, deletion and restoration, these changes can be missed.

Potential impact

  • Excessive permissions or removal of required roles may be discovered late.
  • Investigating access-control changes and verifying approval can take longer.

Remediation

  • Configure a metric filter covering the actual iam_role resource type and the CreateRole, DeleteRole, UpdateRole and UndeleteRole events.
  • Set an alert condition referencing that metric and configure notification_channels. Verify receipt with an authorized test change. Alerts alone do not block role changes.

Examples

These excerpts compare part of the configuration; the initial alert configuration is incomplete. For the revised example, supply var.audit_monitored_resource_type with a monitored resource type actually present in the metric, and configure the channel and project separately. Adjust the evaluation window for ingestion delay and operational needs.

Before

hcl
resource "google_logging_metric" "custom_role_change" {
  name        = "custom_role_change"
  description = "Detects custom role changes"
  filter = <<-FILTER
    resource.type="Wrong_type"
    AND (protoPayload.methodName = "google.iam.admin.v1.CreateRole" OR
    protoPayload.methodName="google.iam.admin.v1.DeleteRole" OR
    protoPayload.methodName="google.iam.admin.v1.UpdateRole" OR
    protoPayload.methodName="google.iam.admin.v1.UndeleteRole")
  FILTER
}

resource "google_monitoring_alert_policy" "custom_role_alert" {
  display_name = "Custom Role Change Alert"
  combiner     = "OR"
}

After

hcl
resource "google_logging_metric" "custom_role_change" {
  name        = "custom_role_change"
  description = "Detects custom role changes"
  filter = <<-FILTER
    resource.type="iam_role"
    AND (protoPayload.methodName = "google.iam.admin.v1.CreateRole" OR
    protoPayload.methodName="google.iam.admin.v1.DeleteRole" OR
    protoPayload.methodName="google.iam.admin.v1.UpdateRole" OR
    protoPayload.methodName="google.iam.admin.v1.UndeleteRole")
  FILTER
}

resource "google_monitoring_alert_policy" "custom_role_alert" {
  display_name          = "Custom Role Change Alert"
  combiner              = "OR"
  notification_channels = [google_monitoring_notification_channel.security_ops.name]

  conditions {
    display_name = "Matching audit events"
    condition_threshold {
      filter = "metric.type=\"logging.googleapis.com/user/${google_logging_metric.custom_role_change.name}\" AND resource.type=\"${var.audit_monitored_resource_type}\""
      comparison      = "COMPARISON_GT"
      threshold_value = 0
      duration        = "0s"
      aggregations {
        alignment_period   = "600s"
        per_series_aligner = "ALIGN_SUM"
      }
    }
  }
}

Explanation:

  • Before: The incorrect resource type can exclude role changes, and the alert has no condition.
  • After: A metric condition and notification channel are configured for role changes. Verify that logs from the required project or organization are collected.

References