Skip to main content الرئيسية المنشئون oyi77 1ai-skills implementing-gcp-organization-policy-constraints
implementing-gcp-organization-policy-constraints Implement GCP Organization Policy constraints to enforce security guardrails across the entire resource hierarchy, restricting risky configurations and ensuring compliance at organization, folder, and project levels. Use when implementing gcp organization policy constraints to enforce security guardrails across.
الانتقال إلى التثبيت سوق المهارات اكتشف واستكشف مهارات الذكاء الاصطناعي التي بناها المجتمع.
التثبيت باستخدام Codex أو Claude انسخ هذا Prompt والصقه في Codex أو Claude أو مساعد آخر ليراجع صفحة Skill ويثبّتها لك.
نسخ Promptعرض تفاصيل Prompt يتجاوز الأمر المباشر Prompt المخصّص للمراجعة. افحص المصدر قبل تشغيله.
npx skills add https://github.com/oyi77/1ai-skills --skill implementing-gcp-organization-policy-constraintsيبقى الأمر في سطر واحد. مرّر أفقيًا لمراجعته كاملًا قبل النسخ.
تفضّل نسخة محلية؟ نزّل الملفات المتاحة حاليًا لدى SkillsMP.
تحميل Zip جاري التحميل... المهن ذات الصلة SOC
استنادا إلى تصنيف SOC المهني
name implementing-gcp-organization-policy-constraints description Implement GCP Organization Policy constraints to enforce security guardrails across the entire resource hierarchy, restricting risky configurations and ensuring compliance at organization, folder, and project levels. Use when implementing gcp organization policy constraints to enforce security guardrails across. domain cybersecurity subdomain cloud-security tags ["gcp","organization-policy","constraints","governance","compliance","cloud-security","resource-manager"] version 1.0 author oyi77 license Apache-2.0 nist_csf ["PR.IR-01","ID.AM-08","GV.SC-06","DE.CM-01"]
Implementing GCP Organization Policy Constraints
Overview
The GCP Organization Policy Service provides centralized and programmatic control over cloud resources. Organization policies configure constraints that restrict one or more Google Cloud services, enforced at organization, folder, or project levels. They improve security by blocking external IPs, requiring encryption, and minimizing unauthorized access. Changes can take up to 15 minutes to propagate.
When to Use
Trigger phrases:
"implementing gcp organization policy constraints"
"Implement GCP Organization Policy constraints to enforce security guardrails acr"
When deploying or configuring implementing gcp organization policy constraints capabilities in your environment
When establishing security controls aligned to compliance requirements
When building or improving security architecture for this domain
When conducting security assessments that require this implementation
Prerequisites
GCP Organization with Organization Administrator role
gcloud CLI configured and authenticated
Terraform or gcloud for policy management
Organization Policy Administrator IAM role (roles/orgpolicy.policyAdmin)
Core Concepts
This section covers core concepts for implementing gcp organization policy constraints.
Ensure all prerequisites are met before proceeding
Follow the documented workflow steps in sequence
Record results and any anomalies encountered during this phase
Constraint Types
List Constraints : Allow or deny specific values (e.g., allowed regions)
Boolean Constraints : Enable or disable a capability (e.g., disable serial port access)
Custom Constraints : User-defined rules targeting specific resource fields (Preview)
Policy Inheritance
Policies inherit from the lowest ancestor with an enforced policy. If no ancestor has a policy, Google's managed default behavior applies.
Essential Security Constraints
This section covers essential security constraints for implementing gcp organization policy constraints.
Ensure all prerequisites are met before proceeding
Follow the documented workflow steps in sequence
Record results and any anomalies encountered during this phase
Restrict VM External IP Addresses
gcloud resource-manager org-policies set-policy \
--organization=ORGANIZATION_ID \
policy.yaml
constraint: constraints/compute.vmExternalIpAccess
listPolicy:
allValues: DENY
Restrict Resource Locations gcloud org-policies set-policy \
--organization=ORGANIZATION_ID \
location-policy.yaml
constraint: constraints/gcp.resourceLocations
listPolicy:
allowedValues:
- "in:us-locations"
- "in:eu-locations"
Disable Default Service Account Creation constraint: constraints/iam.automaticIamGrantsForDefaultServiceAccounts
booleanPolicy:
enforced: true
Require OS Login for SSH constraint: constraints/compute.requireOsLogin
booleanPolicy:
enforced: true
Disable Serial Port Access constraint: constraints/compute.disableSerialPortAccess
booleanPolicy:
enforced: true
Enforce Uniform Bucket-Level Access constraint: constraints/storage.uniformBucketLevelAccess
booleanPolicy:
enforced: true
Restrict Public IP on Cloud SQL constraint: constraints/sql.restrictPublicIp
booleanPolicy:
enforced: true
Disable Service Account Key Creation constraint: constraints/iam.disableServiceAccountKeyCreation
booleanPolicy:
enforced: true
Terraform Implementation resource "google_organization_policy" "restrict_vm_external_ip" {
org_id = var.org_id
constraint = "constraints/compute.vmExternalIpAccess"
list_policy {
deny {
all = true
}
}
}
resource "google_organization_policy" "restrict_locations" {
org_id = var.org_id
constraint = "constraints/gcp.resourceLocations"
list_policy {
allow {
values = ["in:us-locations", "in:eu-locations"]
}
}
}
resource "google_organization_policy" "require_os_login" {
org_id = var.org_id
constraint = "constraints/compute.requireOsLogin"
boolean_policy {
enforced = true
}
}
resource "google_folder_organization_policy" "dev_folder_external_ip" {
folder = google_folder.dev.name
constraint = "constraints/compute.vmExternalIpAccess"
list_policy {
allow {
values = ["projects/dev-project/zones/us-central1-a/instances/bastion-host"]
}
}
}
Dry-Run Testing Use Policy Intelligence tools to test changes before enforcement:
gcloud org-policies set-policy \
--organization=ORGANIZATION_ID \
dry-run-policy.yaml
constraint: constraints/compute.vmExternalIpAccess
listPolicy:
allValues: DENY
dryRunSpec: true
gcloud org-policies list-custom-constraints \
--organization=ORGANIZATION_ID
Custom Constraints
name: organizations/ORGANIZATION_ID/customConstraints/custom.disableGKEAutoUpgrade
resourceTypes:
- container.googleapis.com/NodePool
methodTypes:
- CREATE
- UPDATE
condition: "resource.management.autoUpgrade == true"
actionType: DENY
displayName: Deny GKE auto-upgrade on node pools
description: Prevents enabling auto-upgrade on GKE node pools for controlled upgrades
gcloud org-policies set-custom-constraint custom-constraint.yaml
Monitoring and Compliance This section covers monitoring and compliance for implementing gcp organization policy constraints.
Ensure all prerequisites are met before proceeding
Follow the documented workflow steps in sequence
Record results and any anomalies encountered during this phase
List active policies gcloud org-policies list --organization=ORGANIZATION_ID
Describe a specific policy gcloud org-policies describe constraints/compute.vmExternalIpAccess \
--organization=ORGANIZATION_ID
Audit policy violations with Cloud Asset Inventory gcloud asset search-all-resources \
--scope=organizations/ORGANIZATION_ID \
--query="policy:constraints/compute.vmExternalIpAccess"
Recommended Baseline Policies Constraint Type Scope Purpose compute.vmExternalIpAccess List/Deny Org Prevent public VM IPs gcp.resourceLocations List/Allow Org Restrict to approved regions iam.disableServiceAccountKeyCreation Boolean Org Force Workload Identity compute.requireOsLogin Boolean Org Mandate OS Login for SSH storage.uniformBucketLevelAccess Boolean Org Enforce uniform bucket access sql.restrictPublicIp Boolean Org No public Cloud SQL compute.disableSerialPortAccess Boolean Org Disable serial port compute.disableNestedVirtualization Boolean Org No nested VMs
When NOT to Use
You need to test the implementation (use performing-* skills)
Task is about configuring existing tools (use configuring-* skills)
You need to analyze security events (use analyzing-* skills)
Task is about building detection rules (use building-* skills)
You don't have access to the target environment
Task requires vendor-specific expertise (consult vendor docs)
Red Flags
Performing actions without explicit written authorization from the asset owner
Testing against production systems without a defined scope and rules of engagement
Modifying cloud IAM policies or security groups without approval
Exposing cloud credentials or secrets in logs or reports
Running scans that generate excessive API calls and trigger billing alerts
Verification
All steps executed successfully against a test environment before production use
Output documented with screenshots or logs demonstrating expected behavior
Cloud resource changes reverted or documented as intentional
IAM policies reviewed for least-privilege compliance after testing
No residual test resources left running (cost and security check)
References
Process
Analyze the task requirements
Apply domain expertise
Verify output quality
Anti-Rationalization Table Rationalization Reality "We are too small to be targeted" Automated attacks target everyone. Size does not matter. "Security slows us down" A breach slows you down 100x more. Build security in from the start. "We will fix it after launch" Vulnerabilities in production are exploited within hours. Fix before deploy.