Google Cloud Pub/Sub topic inventory

Record topics and their publishing and subscription relationships.

Description

A Pub/Sub topic inventory documents asynchronous message-delivery paths and ownership. A topic’s presence is not itself a vulnerability.

Potential impact

Unlisted topics can make publishing permissions and subscriptions harder to trace, or leave retention policies unreviewed.

Remediation

Record each topic’s owning team, publishers, and subscriptions, then check IAM permissions, encryption keys, and retention.

Examples

The examples add labels to a topic. Labels do not change publishing permissions or subscription configuration.

Before

hcl
resource "google_pubsub_topic" "events" {
  name = "events-topic"
}

After

hcl
resource "google_pubsub_topic" "events" {
  name = "events-topic"

  labels = {
    service = "events"
    env     = "prod"
  }
}

References