Skip to main content

Overview

A GCP Resource represents a Google Cloud API, such as Cloud Storage at storage.googleapis.com. The Connector proxies it with its HTTP engine. It adds the Google API service, method, and custom action to policy input and logs.
A GCP Resource is different from a GCP Cloud Account, which lets Formal discover Resources and write logs in your Google Cloud project.

Create a GCP Resource

Go to Resources and click Create Resource. Set Technology to GCP. Set Hostname to the API hostname, such as storage.googleapis.com. The Port defaults to 443.
Create one Resource for each Google API hostname you want to govern.

Authentication

By default, clients send their own Google credentials, such as an OAuth access token in the Authorization header. The Connector forwards them unchanged. To inject a credential instead, add a Native User with one of the HTTP credential types: HTTP Bearer, HTTP Basic, API Key (Header), or API Key (Query). See HTTP authentication.
The Control Plane also lists GCP IAM for GCP Resources. Connectors don’t support that credential type for this technology yet, and requests that select it fail.

Connect to a GCP Resource

With Transparent Mode, the Formal Endpoint recognizes Google API traffic. Add a network rule that forwards traffic for your Formal Resources to the Connector:
Clients keep calling *.googleapis.com. They must trust the Endpoint’s certificate authority, so tools that ship their own CA bundle need it added to their configuration.
Verify: Make a request, then open Logs and filter on resource.technology:gcp.

Policy Evaluation

GCP Resources support the same stages and actions as HTTP Resources. Policies also receive input.gcp.api: Logs record the same values under request.http.gcp.api.
host and service come from the request’s Host header. When a client calls the Connector hostname, or the Endpoint forwards the request to the Connector, host is the Connector address and service is empty. In those cases, match on input.http.hostname or input.resource.name, which hold the Resource’s upstream hostname and name.

Example: Block IAM Policy Changes

Next Steps

HTTP

Learn how HTTP-based Resources work

Network Rules

Choose which traffic the Endpoint intercepts