App Topology supports VPC Service Controls to strengthen data security and mitigate the risks of data exfiltration. With VPC Service Controls, you can configure security perimeters around the resources of your Google Cloud services and control the movement of data across the perimeter boundary.
When you enable the App Topology API, App Topology adds an access path for limited metadata for App Hub applications, Cloud Trace traces, and Cloud Monitoring alerts. Examples of metadata include trace span start and end times and App Topology application IDs.
VPC Service Controls restrictions for App Hub apply only to App Hub interactions in the management project. As a result, App Topology can read data for applications and discovered services and workloads for all descendent projects of the app-enabled folder, even if those projects are not in the same perimeter as the management project.
When you restrict the App Topology API in a perimeter, we recommend that you add to that perimeter the APIs for services that provide data to App Topology, including:
- App Hub API (
apphub.googleapis.com) - Cloud Asset API (
cloudasset.googleapis.com) - Developer Connect API (
developerconnect.googleapis.com) - Cloud Monitoring API (
monitoring.googleapis.com) - Security Command Center API (
securitycenter.googleapis.com) - Cloud Trace API (
trace.googleapis.com)
See the VPC Service Controls documentation for more information about supported products.
What's next
- Learn about configuring service perimeters.