Skip to content

Latest commit

 

History

5 Commits

Folders and files

NameName
Last commit message
Last commit date
 
 
 
 
 
 
 
 
 
 
 
 

Repository files navigation

ZonedAccuracy Cloud Security / Zero Trust

A Google Cloud security architecture demonstrating Zero Trust principles, least-privilege IAM, network segmentation, deny-by-default access controls, Identity-Aware Proxy administration, firewall audit logging, Infrastructure as Code, and automated security validation.

Architecture

                     Internet
                        |
                        v
                 Public Entry Layer
                        |
                        v
             Public Subnet 10.10.10.0/24
                        |
                 Explicit Access
                        |
                        v
            Private Subnet 10.10.20.0/24
                        |
                        v
                 Protected Services


Administrative Access
        |
        v
Google Identity-Aware Proxy
        |
        v
Restricted SSH
        |
        v
Authorized Resources

Zero Trust Principles

This project follows several core Zero Trust concepts:

  • Deny access by default
  • Verify access explicitly
  • Apply least privilege
  • Segment cloud networks
  • Restrict administrative access
  • Protect sensitive configuration
  • Log security-relevant network activity
  • Continuously validate security controls

Network Segmentation

The architecture uses a custom Google Cloud VPC:

zonedaccuracy-security-lab-vpc

Automatic subnet creation is disabled.

Two isolated network segments are configured:

Network CIDR Purpose
Public Subnet 10.10.10.0/24 Public-facing workloads
Private Subnet 10.10.20.0/24 Protected internal workloads

Internal ingress traffic is denied by default unless explicitly permitted by a higher-priority security rule.

Least-Privilege IAM

A dedicated service account provides workload identity:

za-zero-trust-service

Only the required telemetry permissions are assigned:

roles/logging.logWriter
roles/monitoring.metricWriter

Broad administrative roles such as Owner and Editor are intentionally excluded.

Secure Administrative Access

SSH is not exposed unrestricted to the Internet.

Administrative SSH access is restricted to Google Cloud Identity-Aware Proxy:

35.235.240.0/20

This avoids exposing administrative access through a 0.0.0.0/0 SSH rule.

Firewall Security

The Terraform configuration implements:

  • Deny-by-default internal ingress
  • Restricted Google Cloud health-check access
  • IAP-restricted SSH
  • Targeted firewall tags
  • Firewall audit logging

Health-check traffic is limited to Google Cloud health-check ranges and TCP ports 80 and 443.

Audit Logging

Firewall logging is enabled to provide visibility into security-relevant network activity.

This provides an audit trail for analyzing allowed and denied connections and identifying which firewall policies handled traffic.

Automated Security Validation

The repository includes:

scripts/security-check.sh

The script automatically validates security controls including:

  • Terraform configuration validity
  • Terraform state protection
  • Sensitive tfvars protection
  • SSH exposure
  • Broad IAM roles
  • Network segmentation
  • Deny-by-default firewall policy

Verified result:

Passed: 7
Failed: 0

Run the checks with:

./scripts/security-check.sh

Infrastructure as Code

The GCP security architecture is managed using Terraform.

Validate the configuration with:

cd terraform
terraform init
terraform fmt
terraform validate
terraform plan

Sensitive Terraform variables and state files are excluded from source control.

Repository Structure

zonedaccuracy-cloud-security-zero-trust/
├── docs/
│   └── architecture.md
├── policies/
│   ├── firewall-policy.json
│   └── iam-policy.json
├── scripts/
│   └── security-check.sh
├── terraform/
│   ├── main.tf
│   ├── outputs.tf
│   ├── providers.tf
│   ├── variables.tf
│   └── versions.tf
├── tests/
├── .gitignore
└── README.md

Security Controls

Security Control Implementation
Zero Trust Explicit access with default-deny design
Least privilege Restricted service-account IAM roles
Network isolation Public/private subnet segmentation
Administrative security IAP-restricted SSH
Firewall security Explicit ingress rules
Auditability Firewall logging
Secret protection Sensitive files excluded from Git
Security validation Automated Bash security checks
Infrastructure as Code Terraform

Technologies

  • Google Cloud Platform
  • Terraform
  • Google Cloud IAM
  • Google Cloud VPC
  • Google Cloud Firewall
  • Identity-Aware Proxy
  • Cloud Logging
  • Bash
  • Git
  • GitHub

Skills Demonstrated

  • Cloud Security Engineering
  • Zero Trust Architecture
  • IAM and Least Privilege
  • Network Segmentation
  • Firewall Engineering
  • Infrastructure as Code
  • Cloud Audit Logging
  • Security Policy Design
  • Secret Protection
  • Security Automation
  • Security Validation
  • Google Cloud Platform

ZonedAccuracy Cloud Portfolio

This repository is part of the ZonedAccuracy Cloud Portfolio, a collection of hands-on projects demonstrating cloud engineering, DevOps, SRE, security, automation, and cloud architecture skills.

ZonedAccuracy.com

About

Google Cloud Zero Trust security architecture using Terraform, least-privilege IAM, network segmentation, deny-by-default firewall controls, IAP, audit logging, and automated security validation.

Topics

Resources

Stars

1 star

Watchers

0 watching

Forks

Releases

Packages

Contributors

Languages