GCP Recommendation Actions

This page has moved

For up-to-date information about GCP Configuration options, go to GCP Additional Configuration.

If properly configured, InsightCloudSec can harvest GCP Recommendations as a resource (found under Identity & Management on the Resources page). Supported Recommendation subtypes (see below) can be acted upon from within InsightCloudSec, with the results/resolution being propagated to GCP for easier principal management. InsightCloudSec supports applying recommendations for both Organizations and Projects.

Currently supported Recommender subtypes are:

text
1
REMOVE_ROLE
2
REMOVE_ROLE_STORAGE_BUCKET
3
REPLACE_ROLE
4
REPLACE_ROLE_STORAGE_BUCKET
5
SERVICE_AGENT_WITH_DEFAULT_ROLE
6
SERVICE_AGENT_WITHOUT_DEFAULT_ROLE

Prerequisites

Before you can apply recommendations in InsightCloudSec, you'll need the following:

Using GCP Recommendation Actions

After the InsightCloudSec role associated with the GCP Project/Organization has appropriate permissions, you can apply recommendations from the Resources page.

  1. Login to InsightCloudSec and go to Resource > Resources.
  2. Click Identity & Management, then click Recommendation.
  3. (Optional) To open the properties for the resource, click the hyperlink in the Affected Resource Name column.
  4. Click the Resource Properties icon for the Recommendation you want to address
  5. Ensure the Subtype column contains a supported subtype.
  6. Click Actions, then click Apply recommendation.
  7. Click Submit to confirm the application.

This will propagate the change to the relevant GCP account, and the recommendation will be accepted. The relevant changes will be made based on that recommendation for that Principal.