User Guide

How to create a Google Cloud segment

Preview

Create a Google Cloud segment to discover resources in your Google Cloud environment and audit the ones you want to track in Inventory. By default, scans and audits for the segment run on AlloyScan cloud workers, services hosted and managed by AlloyScan. You do not need to install or maintain any local components.

NOTE: With the default cloud worker, Google Cloud credentials are encrypted and stored in the AlloyScan cloud. If you want to keep them within your local network, you can use a local Audit Service instead. This can be a service you already use for other segments.

Prerequisites

  • You are a Site Administrator.
  • You have a Google Cloud service account with the permissions listed below and its client email, private key, and project ID, or its credential JSON file.
  • For local execution, an Audit Service is available with access to the provider API.

Google Cloud permissions

Assign the service account the Viewer role (roles/viewer) for the resources you want to scan. Viewer provides read-only access to Google Cloud resources. The same role applies to cloud-worker and local execution.

Create the segment

  1. Open Network > Segments and select + New segment.
  2. Select Google Cloud Platform and select Next.
  3. Under Execution placement, keep AlloyScan cloud worker, which is selected by default. To run scans and audits in your environment, select Local Audit service and choose an Audit Service.
  4. Review the segment name and change it if needed. Select the Google Cloud resources and project scope you want to scan.
  5. Select or add credentials for the provider. Cloud execution uses cloud credentials stored in AlloyScan; local execution uses credentials from the selected Audit Service.
  6. Create a scan schedule, or continue without a schedule. For cloud execution, Cloud start window (minutes) specifies how long after the scheduled time the scan may start.
  7. Review the settings and create the segment.

Use a cloud worker for an existing segment

Open the segment's settings, select AlloyScan cloud worker under Execution placement, select or add compatible cloud credentials, and save. Existing Audit Service credentials are not transferred to cloud storage. You can continue using local execution without changing the segment's credentials.

Verify

  1. Open the segment and select Scan.
  2. Review the scan results and audit the resources you want to inventory.
  3. Open Inventory > Google and review the audited resources.