Sachan & Partners

Terraform security toolkit

Policy-as-code you can drop into your pipeline. Start free, upgrade when you want setup and support.

What a guardrail looks like

Two Google Cloud organisation policies: no long-lived service account keys, and no public Cloud Storage buckets. This needs the Organization Policy API enabled.

resource "google_org_policy_policy" "disable_sa_keys" {
  name   = "projects/${var.project_id}/policies/iam.disableServiceAccountKeyCreation"
  parent = "projects/${var.project_id}"

  spec {
    rules {
      enforce = "TRUE"
    }
  }
}

resource "google_org_policy_policy" "no_public_buckets" {
  name   = "projects/${var.project_id}/policies/storage.publicAccessPrevention"
  parent = "projects/${var.project_id}"

  spec {
    rules {
      enforce = "TRUE"
    }
  }
}

Ask about the Guardrails Pack