Google Cloud Platform Security Best Practices
assured.se
assured.se
https://cloud.google.com/blog/products/identity-security/don...
I'm a beginner so I don't want to make any elementary security mistakes.
In the setup tasks - I need to create an osLogin permission, which means my service account for terraform needs elevated permissions, is there a better way of managing this? Could I perhaps configure that account with `gcloud` and then do the rest with terraform? Is that more secure?
Additionally, I want to pull code from github to non-bastion instances. Is there a good way to get a ssh key onto each box, securely and automatically, to allow github access? Consider that I might want to spin up a new disk and instance for dev at any time.
https://cloud.google.com/iap/docs/using-tcp-forwarding#tunne...
For connecting VMs without public IPs to the outside world, Cloud NAT is the easiest answer. You could set one up yourself if you were so inclined (e.g. some forwarding rules and iptables rules on the bastion).
For ssh key distribution, there's a few options. You can store the key in Secret Manager and run your GCE VMs as a service account that has access to the key, then fetch it when pulling.
https://cloud.google.com/secret-manager/docs/
Something like:
$ ssh-add <(gcloud beta secrets versions access latest --secret=github-ssh-key)
On startup. I haven't actually tried out secret manager yet.
If you have too much time on your hands, you could rig something up with GCE vTPMs as well :)
https://cloud.google.com/blog/products/gcp/virtual-trusted-p...
As fart as managing SSH keys, I would say: don't do it. Use OS Login instead. For cases, like automation, create a service account and use it with OS Login. It gives you a centralized way to manage SSH access (and revoke access) and sudo privileges.
As a sibling has said, use IAP ssh tunneling instead of bastions. With cloudNAT enabled you can pull code from any public repo, including GitHub.
For edge traffic, use any of the gcp provided LBs... there are a bunch of them and they’re all very good. If you’re on GKE I would highly recommend datawires’ ambassador edge proxy: easy to setup and configure, and envoy is a modern, fast and reliable LB.
ed: Sorry, I see. No firewall rules means by default that outgoing connections are allowed, but no incoming ones.