Sachan & Partners

Two Terraform guardrails every startup should add on day one

Most early cloud incidents come from two avoidable things: a leaked key and a public bucket. Both can be blocked centrally with Google Cloud organisation policies, managed in Terraform so the rule stays in place as the team grows.

What they do

resource "google_org_policy_policy" "disable_sa_keys" {
  name   = "projects/${var.project_id}/policies/iam.disableServiceAccountKeyCreation"
  parent = "projects/${var.project_id}"

  spec {
    rules {
      enforce = "TRUE"
    }
  }
}

Enable the Organization Policy API first, and test in a non-production project, because blocking keys can break pipelines that still depend on them.

Want the full set applied and tested for your cloud? See the Guardrails Pack.