GoogleCloudPlatform / GoogleCloudPlatform/pubsec-declarative-toolkit
Prototype firewall policy sets for workload flow ids - at the fortigate, armor or VPC firewall level
- Dominant language
- Shell
- Stars
- 36
- Forks
- 26
- PR merge metrics
- No merged PRs in 30d
Description
Via quick firewall chat with Uday.
https://github.com/GoogleCloudPlatform/pubsec-declarative-toolkit/blob/dev/solutions/landing-zone/architecture.md#di-29-firewall-polices
We just have FW rules at this point, did not run into policies, there are acm access context manager perimeters we can setup. Need to check the kcc side as opposed to the TF side. We will have policies in the fortigate appliances. Which we could augment with cloud armor policies. Definitely we need to attach these FG and armor policies as rule sets based on app flow ids
https://github.com/GoogleCloudPlatform/pubsec-declarative-toolkit/tree/dev/solutions/landing-zone/environments/common/firewall
https://github.com/GoogleCloudPlatform/pubsec-declarative-toolkit/issues/158
Contributor guide
Assessment
This issue has not been assessed yet.