This document describes how to configure Google Cloud folders as members in service perimeters.
Before you begin
Read about creating service perimeters.
Verify that you have the permissions required to create and manage service perimeters (
roles/accesscontextmanager.policyAdmin).Identify the IDs of the folders that you want to add to service perimeters.
Add folders to a perimeter
You can configure a perimeter to include folders as protected resources when you create or update a perimeter.
Console
In the Google Cloud console navigation menu, click Security > VPC Service Controls.
To create a new perimeter, click New perimeter.
To modify an existing perimeter, select the perimeter and click Edit.
Select Resources to protect.
In the Resources to protect pane, click Add folders.
In the Search folders dialog, search for and select the folders that you want to protect.
Click Select. The added folders appear in the Folders section.
Click Continue.
Click Create or Save.
For information about other perimeter configurations, see Create a service perimeter.
gcloud
To create a perimeter in enforced mode and include folders as protected resources, run the following
perimeters createcommand:gcloud access-context-manager perimeters create NAME \ --title=TITLE \ --resources=FOLDER_ID \ --restricted-services=RESTRICTED-SERVICES \ --policy=POLICY_NAME
To create a perimeter in dry run mode and include folders as protected resources, use the
perimeters dry-run createcommand.To update an existing perimeter in enforced mode and include folders as protected resources, run the following
perimeters updatecommand:gcloud access-context-manager perimeters update \ PERIMETER_ID \ --add-resources=FOLDER_ID
To update an existing perimeter in dry run mode and include folders as protected resources, use the
perimeters dry-run updatecommand.
Replace FOLDER_ID with a comma-separated list of one or more
folder IDs. For example, folders/12345. The --resources and
--add-resources arguments also support projects and VPC
networks.
For information about other perimeter configurations, see Create a service perimeter.
Remove folders from a perimeter
You can remove folders from an existing perimeter.
Console
In the Google Cloud console navigation menu, click Security > VPC Service Controls.
To modify an existing perimeter, select the perimeter and click Edit.
Select Resources to protect.
In the Folders section of the Resources to protect pane, select the folders that you want to remove.
Click Remove selected.
Click Continue.
Click Save.
For more information, see Update a service perimeter.
gcloud
To remove folders from an existing perimeter in enforced mode, run the
following
perimeters update
command:
gcloud access-context-manager perimeters update \ PERIMETER_ID \ --remove-resources=FOLDER_ID
To remove folders from an existing perimeter in dry run mode, use the
perimeters dry-run update
command.
Replace FOLDER_ID with a comma-separated list of one or more
folder IDs. For example, folders/12345. The --remove-resources argument
also supports projects and VPC networks.
For more information, see Update a service perimeter.
Look up configured perimeters for a resource
Use the gcloud CLI or the LookupConfiguredServicePerimeter API
method to see which enforced or dry run service perimeters apply to a project or
folder.
gcloud
To look up the configured perimeter for a project or folder, run the
following
lookup-configured-perimeter
command:
gcloud access-context-manager lookup-configured-perimeter \ --resource=RESOURCE
Replace RESOURCE with the resource name in the format
projects/PROJECT_NUMBER or
folders/FOLDER_NUMBER.
API
To look up the configured perimeter for a project, call the
LookupConfiguredServicePerimeter method:
GET https://accesscontextmanager.googleapis.com/v1/projects/PROJECT_NUMBER:lookupConfiguredServicePerimeter
To look up the configured perimeter for a folder, call the
LookupConfiguredServicePerimeter method:
GET https://accesscontextmanager.googleapis.com/v1/folders/FOLDER_NUMBER:lookupConfiguredServicePerimeter
Required permissions
To query configured perimeters for a resource, ensure that you have the following IAM permissions on the relevant Access Policies:
accesscontextmanager.policies.getaccesscontextmanager.servicePerimeters.list
Example response
{
"servicePerimeter": "accessPolicies/123456/servicePerimeters/my_enforced_perimeter",
"servicePerimeterDryRun": "accessPolicies/123456/servicePerimeters/my_dry_run_perimeter",
"restrictedResource": "folders/789012",
"restrictedResourceDryRun": "projects/345678"
}
In this example, the project inherits the enforced perimeter from the
folders/789012 ancestor folder. In contrast, the dry run perimeter is
configured directly on the projects/345678 project.
Manage projects in a perimeter using folders
You can add or remove a project indirectly from a perimeter by moving the project into or out of a folder that you have configured in the perimeter. For more information, see Move a project into a folder.
For information about adding or removing projects explicitly from a perimeter, see Update a service perimeter.
Troubleshoot
If you encounter issues or unexpected behavior while configuring folder memberships, do the following:
- Look up the configured perimeters for the resource to confirm whether the resource inherits a perimeter from an ancestor folder.
- Check audit logs for perimeter violation details. For more information, see Retrieve troubleshooting information from audit logs.
- Verify that projects migrated to folder-based perimeters have completed the 48-hour hierarchy propagation window before removing explicit project bindings.
What's next
- Learn more about dry run mode.
- Learn more about ingress and egress rules.
- Learn more about troubleshooting common issues.