The following sections describe Cloud Discovery & Visibility (CDV) features and configuration specific to GCP environments.
Before you begin
Ensure that the following requirements are met:
- You must be running Address Manager v9.2.0 or greater
- You must have a GCP account to retrieve the GCP data with the following
permissions set:
- GCP Cloud Logging permissions:
logging.sinks.createlogging.sinks.deletelogging.sinks.get
- GCP Pub/Sub permissions:
pubsub.topics.createpubsub.topics.getIamPolicypubsub.topics.setIamPolicypubsub.topics.attachSubscriptionpubsub.topics.getpubsub.topics.deletepubsub.subscriptions.consumepubsub.subscriptions.createpubsub.subscriptions.delete
- GCP Private VPC/Subnets permissions:
compute.networks.getcompute.networks.listcompute.subnetworks.getcompute.subnetworks.list
- GCP VM Instance permissions:
compute.instances.getcompute.instances.list
- GCP DNS Zones (Private) permissions:
compute.zones.getcompute.zones.listcompute.regions.getcompute.regions.listdns.managedZones.listdns.resourceRecordSets.listdns.resourceRecordSets.get
- GCP DNS Zones (Public) permissions:
compute.zones.getcompute.zones.listcompute.regions.getcompute.regions.listdns.managedZones.listdns.resourceRecordSets.listdns.resourceRecordSets.get
- GCP Load Balancer permissions:
compute.instanceTemplates.getcompute.instanceTemplates.listcompute.instanceGroups.listcompute.instanceGroups.getcompute.instances.getcompute.instances.listcompute.backendServices.getcompute.backendServices.listcompute.regionBackendServices.getcompute.regionBackendServices.listcompute.globalForwardingRules.getcompute.globalForwardingRules.listcompute.forwardingRules.getcompute.forwardingRules.listcompute.targetPools.getcompute.targetPools.listcompute.targetHttpProxies.getcompute.targetHttpProxies.listcompute.targetHttpsProxies.getcompute.targetHttpsProxies.listcompute.regionTargetHttpProxies.getcompute.regionTargetHttpProxies.listcompute.regionTargetHttpsProxies.getcompute.regionTargetHttpsProxies.listcompute.targetSslProxies.getcompute.targetSslProxies.listcompute.targetTcpProxies.getcompute.targetTcpProxies.listcompute.urlMaps.getcompute.urlMaps.listcompute.regionUrlMaps.getcompute.regionUrlMaps.list
- GCP Private Endpoints permissions:
dns.managedZones.getdns.managedZones.listdns.resourceRecordSets.getdns.resourceRecordSets.listcompute.globalForwardingRules.getcompute.globalForwardingRules.listcompute.forwardingRules.getcompute.forwardingRules.get
- GCP Kubernetes Engine permissions:
container.clusters.getcontainer.clusters.listcompute.instanceGroups.get
- GCP Cloud Logging permissions: