Securing GCP Projects with VPC Service Controls

แชร์
ฝัง
  • เผยแพร่เมื่อ 14 ต.ค. 2024

ความคิดเห็น • 17

  • @EshanAnas
    @EshanAnas 5 ปีที่แล้ว +5

    Sure, this was great. Please come up with more content like this.
    Thanks GCP

  • @imanghanizada5397
    @imanghanizada5397 5 ปีที่แล้ว +3

    SuperExfiltrationProtection!
    Great content!

  • @GaryNichols
    @GaryNichols 5 ปีที่แล้ว +4

    Could you do a similar video, but one that shows using the DLP API to protect from data exfil?

    • @mrgoogle-nyc
      @mrgoogle-nyc 5 ปีที่แล้ว +2

      Hi Gary, thanks for your note - I will pass this feedback along to the team!

  • @KubernetesEverton
    @KubernetesEverton 5 ปีที่แล้ว +1

    Simple but efficient!

  • @nitinmuteja
    @nitinmuteja 2 ปีที่แล้ว +1

    The VPC service controls API being at the organization level makes this implementation more troublesome. Had this been at the project level, we could have. easily incorporated it via our deployment pipeline.

  • @dsinghr
    @dsinghr 5 ปีที่แล้ว +2

    Basically firewall rules for your GCP services.

    • @luketaylor6935
      @luketaylor6935 4 ปีที่แล้ว

      cloud.google.com/terms/identity/sla

  • @sidharthmohan1277
    @sidharthmohan1277 3 ปีที่แล้ว

    Hi
    Is there any way..Where we can opt/order only selected service's from project/folder in GCP (eg. Cloud Run only ) and other services (Eg : Load balance, Instance, storage) are blocked using "VPC Service Controls" for all the IAM users?
    Thanks

  • @nitinmuteja
    @nitinmuteja 2 ปีที่แล้ว

    I don't know why we can't disable the api to be public even after creating private service connect links? In azure, if we enable private links on storage accounts, it won't have a public endpoint available. I think we should have similar options for the GCS buckets as well.

  • @jorgemarioloaicigarodrigue2295
    @jorgemarioloaicigarodrigue2295 3 ปีที่แล้ว

    What would happen if the malicious actor copied from the protected bucket to a local machine?

  • @girishkumar518
    @girishkumar518 3 ปีที่แล้ว

    We are bit confused about accessing cloud function ..we want to make it private so added ingress setting to allow internal traffic
    but we unable to communicate from the GKE cluster with in the same project getting 403 error
    how could we do that

  • @danielcanizalez8558
    @danielcanizalez8558 4 ปีที่แล้ว

    Great!

  • @AmanKumar-fs5pw
    @AmanKumar-fs5pw 4 ปีที่แล้ว

    Where is the relation between VPC and Cloud storage bucket? did we ever setup cloud bucket within VPC ?

  • @magnusthorne
    @magnusthorne 3 ปีที่แล้ว

    Why call it VPC when it is protecting an API endpoint?

    • @edvasqueza
      @edvasqueza 2 ปีที่แล้ว

      exactly, very confusing

  • @EshanAnas
    @EshanAnas 5 ปีที่แล้ว

    Smart Google haha