# Secret Manager, Organization Policies and Security Command Center — Google Cloud Platform

Source: https://www.skillbyai.com/en/gcp/p-security

> Protect secrets and enforce guardrails across projects.

## Guardrails at every level

**Secret Manager** stores API keys, passwords and certificates as versioned secrets with IAM-controlled access (`roles/secretmanager.secretAccessor`) and audit logging; Cloud Run and Cloud Run functions can mount secrets as environment variables or files. **Organization policies** set constraints across the hierarchy, such as *disable service account key creation*, *restrict resource locations* to Indian regions, *enforce uniform bucket-level access* or *restrict public IPs on Cloud SQL*. **VPC Service Controls** draw a security perimeter around services like BigQuery and Cloud Storage to reduce data exfiltration, even by a principal with valid credentials. **Security Command Center** finds misconfigurations, vulnerabilities and threats across the organization. **Cloud KMS** manages encryption keys when you need **customer-managed encryption keys (CMEK)** instead of Google's default encryption at rest.

## A secret consumed by Cloud Run

The service account needs only accessor permission on this one secret.

```bash
printf '%s' "$(openssl rand -base64 24)" | gcloud secrets create payments-api-key --data-file=- \
  --replication-policy=automatic

gcloud secrets add-iam-policy-binding payments-api-key \
  --member=serviceAccount:orders-api@shop-dev-123456.iam.gserviceaccount.com \
  --role=roles/secretmanager.secretAccessor

gcloud run services update orders-api --region=asia-south1 \
  --set-secrets=PAYMENTS_API_KEY=payments-api-key:latest

# organization-wide guardrail
gcloud resource-manager org-policies enable-enforce iam.disableServiceAccountKeyCreation \
  --organization=123456789012
```

## Lockers and building rules

Secret Manager is a set of lockers where each key opens one locker. Organization policies are building rules ("no ground-floor windows left open") that apply to every tenant whether they remember or not.

**Quiz:** Which control restricts where resources can be created, for example only in Indian regions?

- [ ] A Cloud Armor rule
- [x] An organization policy on resource locations
- [ ] A BigQuery partition
- [ ] A Pub/Sub ordering key

*Answer:* An organization policy on resource locations. The resource-locations organization policy constraint limits allowed regions across the hierarchy.
