Description
A Pub/Sub topic inventory documents asynchronous message-delivery paths and ownership. A topic’s presence is not itself a vulnerability.
Potential impact
Unlisted topics can make publishing permissions and subscriptions harder to trace, or leave retention policies unreviewed.
Remediation
Record each topic’s owning team, publishers, and subscriptions, then check IAM permissions, encryption keys, and retention.
Examples
The examples add labels to a topic. Labels do not change publishing permissions or subscription configuration.
Before
hcl
resource "google_pubsub_topic" "events" {
name = "events-topic"
}
After
hcl
resource "google_pubsub_topic" "events" {
name = "events-topic"
labels = {
service = "events"
env = "prod"
}
}