Skip to content

Add GCP VPC Service Controls evidence gates#1186

Open
Peter7896 wants to merge 1 commit into
UnitOneAI:mainfrom
Peter7896:codex/gcp-vpcsc-evidence-gates
Open

Add GCP VPC Service Controls evidence gates#1186
Peter7896 wants to merge 1 commit into
UnitOneAI:mainfrom
Peter7896:codex/gcp-vpcsc-evidence-gates

Conversation

@Peter7896
Copy link
Copy Markdown

Summary

  • add VPC Service Controls as a GCP data-perimeter supplement separate from CIS scoring
  • require enforced status versus dry-run spec evidence for resources, restricted services, ingress/egress policies, and access levels
  • add bridge-perimeter review for PERIMETER_TYPE_BRIDGE, including project/data-domain scope, justification, and compensating controls
  • add Shared VPC host/service project coverage checks and Not Evaluable handling when only Terraform module inputs are available
  • update severity guidance, output format, common pitfalls, references, and changelog for version 1.0.1

Scope

This addresses #1169. I also posted an attempt comment before implementation: #1169 (comment)

Closes #1169

/claim #1169

Validation

  • git diff --check (only existing Windows LF-to-CRLF warning)
  • verified markdown code fence count is even (6)
  • verified issue-specific markers for VPC Service Controls, enforced status, dry-run spec, use_explicit_dry_run_spec, PERIMETER_TYPE_BRIDGE, Shared VPC coverage, Not Evaluable handling, and version 1.0.1

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

[REVIEW] gcp-review: add VPC Service Controls dry-run and bridge evidence gates

1 participant