diff --git a/fast/stages/0-bootstrap/data/org-policies/compute.yaml b/fast/stages/0-bootstrap/data/org-policies/compute.yaml index 55c18f262..652ac6456 100644 --- a/fast/stages/0-bootstrap/data/org-policies/compute.yaml +++ b/fast/stages/0-bootstrap/data/org-policies/compute.yaml @@ -55,13 +55,13 @@ compute.trustedImageProjects: # rules: # - enforce: true -# compute.disableNestedVirtualization: -# rules: -# - enforce: true +compute.disableNestedVirtualization: + rules: + - enforce: true -# compute.disableSerialPortAccess: -# rules: -# - enforce: true +compute.disableSerialPortAccess: + rules: + - enforce: true # compute.restrictCloudNATUsage: # rules: diff --git a/fast/stages/0-bootstrap/data/org-policies/storage.yaml b/fast/stages/0-bootstrap/data/org-policies/storage.yaml index 2578d5a52..bf33618a2 100644 --- a/fast/stages/0-bootstrap/data/org-policies/storage.yaml +++ b/fast/stages/0-bootstrap/data/org-policies/storage.yaml @@ -9,3 +9,7 @@ storage.uniformBucketLevelAccess: rules: - enforce: true + +storage.publicAccessPrevention: + rules: + - enforce: true diff --git a/tests/fast/stages/s0_bootstrap/checklist.yaml b/tests/fast/stages/s0_bootstrap/checklist.yaml index f779be90d..77922f0a9 100644 --- a/tests/fast/stages/s0_bootstrap/checklist.yaml +++ b/tests/fast/stages/s0_bootstrap/checklist.yaml @@ -362,7 +362,7 @@ counts: google_essential_contacts_contact: 3 google_logging_organization_sink: 3 google_logging_project_bucket_config: 3 - google_org_policy_policy: 17 + google_org_policy_policy: 20 google_organization_iam_binding: 25 google_organization_iam_custom_role: 6 google_organization_iam_member: 35 @@ -381,4 +381,4 @@ counts: google_tags_tag_key: 1 google_tags_tag_value: 1 modules: 16 - resources: 186 + resources: 189 diff --git a/tests/fast/stages/s0_bootstrap/simple.yaml b/tests/fast/stages/s0_bootstrap/simple.yaml index 7320bcb88..14738b8a8 100644 --- a/tests/fast/stages/s0_bootstrap/simple.yaml +++ b/tests/fast/stages/s0_bootstrap/simple.yaml @@ -1,4 +1,4 @@ -# Copyright 2023 Google LLC +# Copyright 2024 Google LLC # # Licensed under the Apache License, Version 2.0 (the "License"); # you may not use this file except in compliance with the License. @@ -18,7 +18,7 @@ counts: google_essential_contacts_contact: 3 google_logging_organization_sink: 3 google_logging_project_bucket_config: 3 - google_org_policy_policy: 17 + google_org_policy_policy: 20 google_organization_iam_binding: 25 google_organization_iam_custom_role: 6 google_organization_iam_member: 22 @@ -38,7 +38,7 @@ counts: google_tags_tag_value: 1 local_file: 7 modules: 15 - resources: 177 + resources: 180 outputs: custom_roles: