|
|
|
|
@@ -20,7 +20,7 @@
|
|
|
|
|
|
|
|
|
|
compute.disableGuestAttributesAccess:
|
|
|
|
|
rules:
|
|
|
|
|
- enforce: true
|
|
|
|
|
- enforce: true
|
|
|
|
|
|
|
|
|
|
compute.disableInternetNetworkEndpointGroup:
|
|
|
|
|
rules:
|
|
|
|
|
@@ -40,17 +40,17 @@ compute.disableVpcExternalIpv6:
|
|
|
|
|
|
|
|
|
|
compute.requireOsLogin:
|
|
|
|
|
rules:
|
|
|
|
|
- enforce: true
|
|
|
|
|
- enforce: true
|
|
|
|
|
|
|
|
|
|
compute.restrictLoadBalancerCreationForTypes:
|
|
|
|
|
rules:
|
|
|
|
|
- allow:
|
|
|
|
|
values:
|
|
|
|
|
- in:INTERNAL
|
|
|
|
|
- allow:
|
|
|
|
|
values:
|
|
|
|
|
- in:INTERNAL
|
|
|
|
|
|
|
|
|
|
compute.skipDefaultNetworkCreation:
|
|
|
|
|
rules:
|
|
|
|
|
- enforce: true
|
|
|
|
|
- enforce: true
|
|
|
|
|
|
|
|
|
|
compute.setNewProjectDefaultToZonalDNSOnly:
|
|
|
|
|
rules:
|
|
|
|
|
@@ -61,35 +61,35 @@ compute.trustedImageProjects:
|
|
|
|
|
rules:
|
|
|
|
|
- allow:
|
|
|
|
|
values:
|
|
|
|
|
- "is:projects/centos-cloud"
|
|
|
|
|
- "is:projects/cos-cloud"
|
|
|
|
|
- "is:projects/debian-cloud"
|
|
|
|
|
- "is:projects/fedora-cloud"
|
|
|
|
|
- "is:projects/fedora-coreos-cloud"
|
|
|
|
|
- "is:projects/opensuse-cloud"
|
|
|
|
|
- "is:projects/rhel-cloud"
|
|
|
|
|
- "is:projects/rhel-sap-cloud"
|
|
|
|
|
- "is:projects/rocky-linux-cloud"
|
|
|
|
|
- "is:projects/suse-cloud"
|
|
|
|
|
- "is:projects/suse-sap-cloud"
|
|
|
|
|
- "is:projects/ubuntu-os-cloud"
|
|
|
|
|
- "is:projects/ubuntu-os-pro-cloud"
|
|
|
|
|
- "is:projects/windows-cloud"
|
|
|
|
|
- "is:projects/windows-sql-cloud"
|
|
|
|
|
- "is:projects/confidential-vm-images"
|
|
|
|
|
- "is:projects/confidential-space-images"
|
|
|
|
|
- "is:projects/backupdr-images"
|
|
|
|
|
- "is:projects/deeplearning-platform-release"
|
|
|
|
|
- "is:projects/serverless-vpc-access-images"
|
|
|
|
|
- "is:projects/gke-node-images"
|
|
|
|
|
- "is:projects/gke-windows-node-images"
|
|
|
|
|
- "is:projects/ubuntu-os-gke-cloud"
|
|
|
|
|
- "is:projects/centos-cloud"
|
|
|
|
|
- "is:projects/cos-cloud"
|
|
|
|
|
- "is:projects/debian-cloud"
|
|
|
|
|
- "is:projects/fedora-cloud"
|
|
|
|
|
- "is:projects/fedora-coreos-cloud"
|
|
|
|
|
- "is:projects/opensuse-cloud"
|
|
|
|
|
- "is:projects/rhel-cloud"
|
|
|
|
|
- "is:projects/rhel-sap-cloud"
|
|
|
|
|
- "is:projects/rocky-linux-cloud"
|
|
|
|
|
- "is:projects/suse-cloud"
|
|
|
|
|
- "is:projects/suse-sap-cloud"
|
|
|
|
|
- "is:projects/ubuntu-os-cloud"
|
|
|
|
|
- "is:projects/ubuntu-os-pro-cloud"
|
|
|
|
|
- "is:projects/windows-cloud"
|
|
|
|
|
- "is:projects/windows-sql-cloud"
|
|
|
|
|
- "is:projects/confidential-vm-images"
|
|
|
|
|
- "is:projects/confidential-space-images"
|
|
|
|
|
- "is:projects/backupdr-images"
|
|
|
|
|
- "is:projects/deeplearning-platform-release"
|
|
|
|
|
- "is:projects/serverless-vpc-access-images"
|
|
|
|
|
- "is:projects/gke-node-images"
|
|
|
|
|
- "is:projects/gke-windows-node-images"
|
|
|
|
|
- "is:projects/ubuntu-os-gke-cloud"
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
compute.vmExternalIpAccess:
|
|
|
|
|
rules:
|
|
|
|
|
- deny:
|
|
|
|
|
all: true
|
|
|
|
|
- deny:
|
|
|
|
|
all: true
|
|
|
|
|
|
|
|
|
|
# compute.disableInternetNetworkEndpointGroup:
|
|
|
|
|
# rules:
|
|
|
|
|
@@ -112,9 +112,9 @@ compute.vmExternalIpAccess:
|
|
|
|
|
|
|
|
|
|
compute.restrictProtocolForwardingCreationForTypes:
|
|
|
|
|
rules:
|
|
|
|
|
- allow:
|
|
|
|
|
values:
|
|
|
|
|
- is:INTERNAL
|
|
|
|
|
- allow:
|
|
|
|
|
values:
|
|
|
|
|
- is:INTERNAL
|
|
|
|
|
|
|
|
|
|
# compute.restrictSharedVpcHostProjects:
|
|
|
|
|
# rules:
|
|
|
|
|
|