Google Cloud Filestore inventory

Record the users and owners of file shares.

Description

A Filestore instance inventory documents shared file servers, the workloads using them, and their owners. The presence of an instance alone does not indicate a security problem.

Potential impact

Unlisted file shares may be missed in network-access and recovery-policy reviews, and their storage costs can be harder to track.

Remediation

Record each instance’s owner and workloads, then check networking, NFS export options, backups, and encryption-key policy.

Examples

These excerpts show label additions and omit the required file-share and network blocks. Labels alone do not configure access controls.

Before

hcl
resource "google_filestore_instance" "shared" {
  name     = "shared-storage"
  location = "us-central1-b"
  tier     = "BASIC_SSD"
}

After

hcl
resource "google_filestore_instance" "shared" {
  name     = "shared-storage"
  location = "us-central1-b"
  tier     = "BASIC_SSD"

  labels = {
    service = "shared-storage"
    env     = "prod"
  }
}

References