Description
A Dataflow job inventory identifies the data handled by batch and streaming pipelines and who operates them. The presence of a job is not itself a vulnerability.
Potential impact
Unlisted jobs may be missed in reviews of service-account permissions, networking, and temporary storage.
Remediation
Record each job’s owner and input and output data, then check its service account, network, temporary bucket, and encryption-key policy.
Examples
The examples add service and environment labels. Set template and temporary-storage URLs for the target environment; labels do not change access permissions.
Before
hcl
resource "google_dataflow_job" "stream_job" {
name = "stream-job"
template_gcs_path = "gs://example/templates/job"
temp_gcs_location = "gs://example/tmp"
}
After
hcl
resource "google_dataflow_job" "stream_job" {
name = "stream-job"
template_gcs_path = "gs://example/templates/job"
temp_gcs_location = "gs://example/tmp"
labels = {
service = "streaming"
env = "prod"
}
}