Two Terraform guardrails every startup should add on day one
Most early cloud incidents come from two avoidable things: a leaked key and a public bucket. Both can be blocked centrally with Google Cloud organisation policies, managed in Terraform so the rule stays in place as the team grows.
What they do
- Disable service account key creation removes the risk of long-lived credentials being committed to a repository.
- Public access prevention stops anyone making a Cloud Storage bucket public by mistake.
resource "google_org_policy_policy" "disable_sa_keys" {
name = "projects/${var.project_id}/policies/iam.disableServiceAccountKeyCreation"
parent = "projects/${var.project_id}"
spec {
rules {
enforce = "TRUE"
}
}
}
Enable the Organization Policy API first, and test in a non-production project, because blocking keys can break pipelines that still depend on them.
Want the full set applied and tested for your cloud? See the Guardrails Pack.