पाठ 23 / 25

Secret Manager, Organization Policies and Security Command Center

Protect secrets and enforce guardrails across projects.

Guardrails at every level

Secret Manager stores API keys, passwords and certificates as versioned secrets with IAM-controlled access (roles/secretmanager.secretAccessor) and audit logging; Cloud Run and Cloud Run functions can mount secrets as environment variables or files. Organization policies set constraints across the hierarchy, such as disable service account key creation, restrict resource locations to Indian regions, enforce uniform bucket-level access or restrict public IPs on Cloud SQL. VPC Service Controls draw a security perimeter around services like BigQuery and Cloud Storage to reduce data exfiltration, even by a principal with valid credentials. Security Command Center finds misconfigurations, vulnerabilities and threats across the organization. Cloud KMS manages encryption keys when you need customer-managed encryption keys (CMEK) instead of Google's default encryption at rest.

A secret consumed by Cloud Run

The service account needs only accessor permission on this one secret.

printf '%s' "$(openssl rand -base64 24)" | gcloud secrets create payments-api-key --data-file=- \
  --replication-policy=automatic

gcloud secrets add-iam-policy-binding payments-api-key \
  --member=serviceAccount:orders-api@shop-dev-123456.iam.gserviceaccount.com \
  --role=roles/secretmanager.secretAccessor

gcloud run services update orders-api --region=asia-south1 \
  --set-secrets=PAYMENTS_API_KEY=payments-api-key:latest

# organization-wide guardrail
gcloud resource-manager org-policies enable-enforce iam.disableServiceAccountKeyCreation \
  --organization=123456789012

Lockers and building rules

Secret Manager is a set of lockers where each key opens one locker. Organization policies are building rules ("no ground-floor windows left open") that apply to every tenant whether they remember or not.

त्वरित जाँच: Which control restricts where resources can be created, for example only in Indian regions?

  • A Cloud Armor rule
  • An organization policy on resource locations
  • A BigQuery partition
  • A Pub/Sub ordering key
Answer

An organization policy on resource locations — The resource-locations organization policy constraint limits allowed regions across the hierarchy.