A Google Cloud security architecture demonstrating Zero Trust principles, least-privilege IAM, network segmentation, deny-by-default access controls, Identity-Aware Proxy administration, firewall audit logging, Infrastructure as Code, and automated security validation.
Internet
|
v
Public Entry Layer
|
v
Public Subnet 10.10.10.0/24
|
Explicit Access
|
v
Private Subnet 10.10.20.0/24
|
v
Protected Services
Administrative Access
|
v
Google Identity-Aware Proxy
|
v
Restricted SSH
|
v
Authorized Resources
This project follows several core Zero Trust concepts:
- Deny access by default
- Verify access explicitly
- Apply least privilege
- Segment cloud networks
- Restrict administrative access
- Protect sensitive configuration
- Log security-relevant network activity
- Continuously validate security controls
The architecture uses a custom Google Cloud VPC:
zonedaccuracy-security-lab-vpc
Automatic subnet creation is disabled.
Two isolated network segments are configured:
| Network | CIDR | Purpose |
|---|---|---|
| Public Subnet | 10.10.10.0/24 |
Public-facing workloads |
| Private Subnet | 10.10.20.0/24 |
Protected internal workloads |
Internal ingress traffic is denied by default unless explicitly permitted by a higher-priority security rule.
A dedicated service account provides workload identity:
za-zero-trust-service
Only the required telemetry permissions are assigned:
roles/logging.logWriter
roles/monitoring.metricWriter
Broad administrative roles such as Owner and Editor are intentionally excluded.
SSH is not exposed unrestricted to the Internet.
Administrative SSH access is restricted to Google Cloud Identity-Aware Proxy:
35.235.240.0/20
This avoids exposing administrative access through a 0.0.0.0/0 SSH rule.
The Terraform configuration implements:
- Deny-by-default internal ingress
- Restricted Google Cloud health-check access
- IAP-restricted SSH
- Targeted firewall tags
- Firewall audit logging
Health-check traffic is limited to Google Cloud health-check ranges and TCP ports 80 and 443.
Firewall logging is enabled to provide visibility into security-relevant network activity.
This provides an audit trail for analyzing allowed and denied connections and identifying which firewall policies handled traffic.
The repository includes:
scripts/security-check.sh
The script automatically validates security controls including:
- Terraform configuration validity
- Terraform state protection
- Sensitive tfvars protection
- SSH exposure
- Broad IAM roles
- Network segmentation
- Deny-by-default firewall policy
Verified result:
Passed: 7
Failed: 0
Run the checks with:
./scripts/security-check.shThe GCP security architecture is managed using Terraform.
Validate the configuration with:
cd terraform
terraform init
terraform fmt
terraform validate
terraform planSensitive Terraform variables and state files are excluded from source control.
zonedaccuracy-cloud-security-zero-trust/
├── docs/
│ └── architecture.md
├── policies/
│ ├── firewall-policy.json
│ └── iam-policy.json
├── scripts/
│ └── security-check.sh
├── terraform/
│ ├── main.tf
│ ├── outputs.tf
│ ├── providers.tf
│ ├── variables.tf
│ └── versions.tf
├── tests/
├── .gitignore
└── README.md
| Security Control | Implementation |
|---|---|
| Zero Trust | Explicit access with default-deny design |
| Least privilege | Restricted service-account IAM roles |
| Network isolation | Public/private subnet segmentation |
| Administrative security | IAP-restricted SSH |
| Firewall security | Explicit ingress rules |
| Auditability | Firewall logging |
| Secret protection | Sensitive files excluded from Git |
| Security validation | Automated Bash security checks |
| Infrastructure as Code | Terraform |
- Google Cloud Platform
- Terraform
- Google Cloud IAM
- Google Cloud VPC
- Google Cloud Firewall
- Identity-Aware Proxy
- Cloud Logging
- Bash
- Git
- GitHub
- Cloud Security Engineering
- Zero Trust Architecture
- IAM and Least Privilege
- Network Segmentation
- Firewall Engineering
- Infrastructure as Code
- Cloud Audit Logging
- Security Policy Design
- Secret Protection
- Security Automation
- Security Validation
- Google Cloud Platform
This repository is part of the ZonedAccuracy Cloud Portfolio, a collection of hands-on projects demonstrating cloud engineering, DevOps, SRE, security, automation, and cloud architecture skills.
ZonedAccuracy.com