GoogleCloudPlatform / GoogleCloudPlatform/pubsec-declarative-toolkit
Validate access context manager scoped policies for folders/projects is also CC/CRM supported as it is in the GCP API
- Dominant language
- Shell
- Stars
- 36
- Forks
- 26
- PR merge metrics
- No merged PRs in 30d
Description
The GCP API supports folders/projects under VPC-SC/perimeters
https://cloud.google.com/access-context-manager/docs/create-access-policy#scoped-access-policy
https://cloud.google.com/vpc-service-controls/docs/overview
We need to verify that the Config Controller CRM does as well
https://cloud.google.com.mcas.ms/config-connector/docs/reference/resource-docs/accesscontextmanager/accesscontextmanageraccesspolicy
Validate a non KCC gcloud version first
detail in https://github.com/GoogleCloudPlatform/pubsec-declarative-toolkit/blob/dev/solutions/landing-zone/architecture.md#di-39-enable-security-command-center-reporting-of-gke-kcc-and-workload-clusters
Contributor guide
Assessment
This issue has not been assessed yet.