Google Cloud Dataflow job inventory

Document data-processing jobs and their owners.

Description

A Dataflow job inventory identifies the data handled by batch and streaming pipelines and who operates them. The presence of a job is not itself a vulnerability.

Potential impact

Unlisted jobs may be missed in reviews of service-account permissions, networking, and temporary storage.

Remediation

Record each job’s owner and input and output data, then check its service account, network, temporary bucket, and encryption-key policy.

Examples

The examples add service and environment labels. Set template and temporary-storage URLs for the target environment; labels do not change access permissions.

Before

hcl
resource "google_dataflow_job" "stream_job" {
  name              = "stream-job"
  template_gcs_path = "gs://example/templates/job"
  temp_gcs_location = "gs://example/tmp"
}

After

hcl
resource "google_dataflow_job" "stream_job" {
  name              = "stream-job"
  template_gcs_path = "gs://example/templates/job"
  temp_gcs_location = "gs://example/tmp"

  labels = {
    service = "streaming"
    env     = "prod"
  }
}

References