Skip to main content 首页 创作者 oyi77 1ai-skills implementing-gcp-organization-policy-constraints
implementing-gcp-organization-policy-constraints Implement GCP Organization Policy constraints to enforce security guardrails across the entire resource hierarchy, restricting risky configurations and ensuring compliance at organization, folder, and project levels. Use when implementing gcp organization policy constraints to enforce security guardrails across.
跳到安装 Skills Marketplace 发现并探索由社区构建的 Agent Skills
用 Codex 或 Claude 帮你安装 复制这段 Prompt,粘贴到 Codex、Claude 或其他助手里,让它检查 Skill 页面并帮你完成安装。
直接命令不会经过审查 Prompt;运行前请先检查来源。
npx skills add https://github.com/oyi77/1ai-skills --skill implementing-gcp-organization-policy-constraints命令会保持在同一行。复制前请横向滚动并检查完整内容。
想先保存到本地?可下载 SkillsMP 当前能够提供的文件。
下载 Zip 下载中... name implementing-gcp-organization-policy-constraints description Implement GCP Organization Policy constraints to enforce security guardrails across the entire resource hierarchy, restricting risky configurations and ensuring compliance at organization, folder, and project levels. Use when implementing gcp organization policy constraints to enforce security guardrails across. domain cybersecurity subdomain cloud-security tags ["gcp","organization-policy","constraints","governance","compliance","cloud-security","resource-manager"] version 1.0 author oyi77 license Apache-2.0 nist_csf ["PR.IR-01","ID.AM-08","GV.SC-06","DE.CM-01"]
Implementing GCP Organization Policy Constraints
Overview
The GCP Organization Policy Service provides centralized and programmatic control over cloud resources. Organization policies configure constraints that restrict one or more Google Cloud services, enforced at organization, folder, or project levels. They improve security by blocking external IPs, requiring encryption, and minimizing unauthorized access. Changes can take up to 15 minutes to propagate.
When to Use
Trigger phrases:
"implementing gcp organization policy constraints"
"Implement GCP Organization Policy constraints to enforce security guardrails acr"
When deploying or configuring implementing gcp organization policy constraints capabilities in your environment
When establishing security controls aligned to compliance requirements
When building or improving security architecture for this domain
When conducting security assessments that require this implementation
Prerequisites
GCP Organization with Organization Administrator role
gcloud CLI configured and authenticated
Terraform or gcloud for policy management
Organization Policy Administrator IAM role (roles/orgpolicy.policyAdmin)
Core Concepts
This section covers core concepts for implementing gcp organization policy constraints.
Ensure all prerequisites are met before proceeding
Follow the documented workflow steps in sequence
Record results and any anomalies encountered during this phase
Constraint Types
List Constraints : Allow or deny specific values (e.g., allowed regions)
Boolean Constraints : Enable or disable a capability (e.g., disable serial port access)
Custom Constraints : User-defined rules targeting specific resource fields (Preview)
Policy Inheritance
Policies inherit from the lowest ancestor with an enforced policy. If no ancestor has a policy, Google's managed default behavior applies.
Essential Security Constraints
This section covers essential security constraints for implementing gcp organization policy constraints.
Ensure all prerequisites are met before proceeding
Follow the documented workflow steps in sequence
Record results and any anomalies encountered during this phase
Restrict VM External IP Addresses
gcloud resource-manager org-policies set-policy \
--organization=ORGANIZATION_ID \
policy.yaml
constraint: constraints/compute.vmExternalIpAccess
listPolicy:
allValues: DENY
Restrict Resource Locations gcloud org-policies set-policy \
--organization=ORGANIZATION_ID \
location-policy.yaml
constraint: constraints/gcp.resourceLocations
listPolicy:
allowedValues:
- "in:us-locations"
- "in:eu-locations"
Disable Default Service Account Creation constraint: constraints/iam.automaticIamGrantsForDefaultServiceAccounts
booleanPolicy:
enforced: true
Require OS Login for SSH constraint: constraints/compute.requireOsLogin
booleanPolicy:
enforced: true
Disable Serial Port Access constraint: constraints/compute.disableSerialPortAccess
booleanPolicy:
enforced: true
Enforce Uniform Bucket-Level Access constraint: constraints/storage.uniformBucketLevelAccess
booleanPolicy:
enforced: true
Restrict Public IP on Cloud SQL constraint: constraints/sql.restrictPublicIp
booleanPolicy:
enforced: true
Disable Service Account Key Creation constraint: constraints/iam.disableServiceAccountKeyCreation
booleanPolicy:
enforced: true
Terraform Implementation resource "google_organization_policy" "restrict_vm_external_ip" {
org_id = var.org_id
constraint = "constraints/compute.vmExternalIpAccess"
list_policy {
deny {
all = true
}
}
}
resource "google_organization_policy" "restrict_locations" {
org_id = var.org_id
constraint = "constraints/gcp.resourceLocations"
list_policy {
allow {
values = ["in:us-locations", "in:eu-locations"]
}
}
}
resource "google_organization_policy" "require_os_login" {
org_id = var.org_id
constraint = "constraints/compute.requireOsLogin"
boolean_policy {
enforced = true
}
}
resource "google_folder_organization_policy" "dev_folder_external_ip" {
folder = google_folder.dev.name
constraint = "constraints/compute.vmExternalIpAccess"
list_policy {
allow {
values = ["projects/dev-project/zones/us-central1-a/instances/bastion-host"]
}
}
}
Dry-Run Testing Use Policy Intelligence tools to test changes before enforcement:
gcloud org-policies set-policy \
--organization=ORGANIZATION_ID \
dry-run-policy.yaml
constraint: constraints/compute.vmExternalIpAccess
listPolicy:
allValues: DENY
dryRunSpec: true
gcloud org-policies list-custom-constraints \
--organization=ORGANIZATION_ID
Custom Constraints
name: organizations/ORGANIZATION_ID/customConstraints/custom.disableGKEAutoUpgrade
resourceTypes:
- container.googleapis.com/NodePool
methodTypes:
- CREATE
- UPDATE
condition: "resource.management.autoUpgrade == true"
actionType: DENY
displayName: Deny GKE auto-upgrade on node pools
description: Prevents enabling auto-upgrade on GKE node pools for controlled upgrades
gcloud org-policies set-custom-constraint custom-constraint.yaml
Monitoring and Compliance This section covers monitoring and compliance for implementing gcp organization policy constraints.
Ensure all prerequisites are met before proceeding
Follow the documented workflow steps in sequence
Record results and any anomalies encountered during this phase
List active policies gcloud org-policies list --organization=ORGANIZATION_ID
Describe a specific policy gcloud org-policies describe constraints/compute.vmExternalIpAccess \
--organization=ORGANIZATION_ID
Audit policy violations with Cloud Asset Inventory gcloud asset search-all-resources \
--scope=organizations/ORGANIZATION_ID \
--query="policy:constraints/compute.vmExternalIpAccess"
Recommended Baseline Policies Constraint Type Scope Purpose compute.vmExternalIpAccess List/Deny Org Prevent public VM IPs gcp.resourceLocations List/Allow Org Restrict to approved regions iam.disableServiceAccountKeyCreation Boolean Org Force Workload Identity compute.requireOsLogin Boolean Org Mandate OS Login for SSH storage.uniformBucketLevelAccess Boolean Org Enforce uniform bucket access sql.restrictPublicIp Boolean Org No public Cloud SQL compute.disableSerialPortAccess Boolean Org Disable serial port compute.disableNestedVirtualization Boolean Org No nested VMs
When NOT to Use
You need to test the implementation (use performing-* skills)
Task is about configuring existing tools (use configuring-* skills)
You need to analyze security events (use analyzing-* skills)
Task is about building detection rules (use building-* skills)
You don't have access to the target environment
Task requires vendor-specific expertise (consult vendor docs)
Red Flags
Performing actions without explicit written authorization from the asset owner
Testing against production systems without a defined scope and rules of engagement
Modifying cloud IAM policies or security groups without approval
Exposing cloud credentials or secrets in logs or reports
Running scans that generate excessive API calls and trigger billing alerts
Verification
All steps executed successfully against a test environment before production use
Output documented with screenshots or logs demonstrating expected behavior
Cloud resource changes reverted or documented as intentional
IAM policies reviewed for least-privilege compliance after testing
No residual test resources left running (cost and security check)
References
Process
Analyze the task requirements
Apply domain expertise
Verify output quality
Anti-Rationalization Table Rationalization Reality "We are too small to be targeted" Automated attacks target everyone. Size does not matter. "Security slows us down" A breach slows you down 100x more. Build security in from the start. "We will fix it after launch" Vulnerabilities in production are exploited within hours. Fix before deploy.