Overview
A GCP Resource represents a Google Cloud API, such as Cloud Storage atstorage.googleapis.com. The Connector proxies it with its HTTP engine. It adds the Google API service, method, and custom action to policy input and logs.
A GCP Resource is different from a
GCP Cloud Account, which lets Formal
discover Resources and write logs in your Google Cloud project.
Create a GCP Resource
- Control Plane
- Terraform
Go to Resources and click Create Resource. Set Technology to GCP. Set Hostname to the API hostname, such as
storage.googleapis.com. The Port defaults to 443.Authentication
By default, clients send their own Google credentials, such as an OAuth access token in theAuthorization header. The Connector forwards them unchanged.
To inject a credential instead, add a Native User with one of the HTTP credential types: HTTP Bearer, HTTP Basic, API Key (Header), or API Key (Query). See HTTP authentication.
Connect to a GCP Resource
- Formal Endpoint
- Connector hostname
With Transparent Mode, the Formal Endpoint recognizes Google API traffic. Add a network rule that forwards traffic for your Formal Resources to the Connector:Clients keep calling
*.googleapis.com. They must trust the Endpoint’s certificate authority, so tools that ship their own CA bundle need it added to their configuration.resource.technology:gcp.
Policy Evaluation
GCP Resources support the same stages and actions as HTTP Resources. Policies also receiveinput.gcp.api:
Logs record the same values under
request.http.gcp.api.
host and service come from the request’s Host header. When a client
calls the Connector hostname, or the Endpoint forwards the request to the
Connector, host is the Connector address and service is empty. In those
cases, match on input.http.hostname or input.resource.name, which hold
the Resource’s upstream hostname and name.Example: Block IAM Policy Changes
Next Steps
HTTP
Learn how HTTP-based Resources work
Network Rules
Choose which traffic the Endpoint intercepts