Description
A Filestore instance inventory documents shared file servers, the workloads using them, and their owners. The presence of an instance alone does not indicate a security problem.
Potential impact
Unlisted file shares may be missed in network-access and recovery-policy reviews, and their storage costs can be harder to track.
Remediation
Record each instance’s owner and workloads, then check networking, NFS export options, backups, and encryption-key policy.
Examples
These excerpts show label additions and omit the required file-share and network blocks. Labels alone do not configure access controls.
Before
hcl
resource "google_filestore_instance" "shared" {
name = "shared-storage"
location = "us-central1-b"
tier = "BASIC_SSD"
}
After
hcl
resource "google_filestore_instance" "shared" {
name = "shared-storage"
location = "us-central1-b"
tier = "BASIC_SSD"
labels = {
service = "shared-storage"
env = "prod"
}
}