Terraform security toolkit
Policy-as-code you can drop into your pipeline. Start free, upgrade when you want setup and support.
What a guardrail looks like
Two Google Cloud organisation policies: no long-lived service account keys, and no public Cloud Storage buckets. This needs the Organization Policy API enabled.
resource "google_org_policy_policy" "disable_sa_keys" {
name = "projects/${var.project_id}/policies/iam.disableServiceAccountKeyCreation"
parent = "projects/${var.project_id}"
spec {
rules {
enforce = "TRUE"
}
}
}
resource "google_org_policy_policy" "no_public_buckets" {
name = "projects/${var.project_id}/policies/storage.publicAccessPrevention"
parent = "projects/${var.project_id}"
spec {
rules {
enforce = "TRUE"
}
}
}
- Free baseline modules on GitHub (add your repository link in site.json)
- Paid Guardrails Pack: modules tailored to your cloud, set up and tested with you
- Works with GitHub Actions and Cloud Build