Onboarding a Google Cloud Platform (GCP) Project and Google Workspace
Prerequisites
-
You must have Owner permissions for the GCP
Google® Cloud Platform - a suite of cloud computing services that runs on the same infrastructure that Google uses internally for its end-user products, such as Google Search, Gmail, Google Drive, and YouTube. project.
-
To connect Google Workspace to CloudGuard, you must have Owner permissions for the Google Workspace.
To onboard a GCP project to CloudGuard:
-
In GCP, open the project that you want to onboard to CloudGuard. Keep the GCP project open throughout this procedure.
-
In the CloudGuard UI, from the left menu, expand Assets and click Environments.
-
In the toolbar above the table, in the top left, click Add and then click GCP Project.
The GCP Onboarding wizard opens.
-
In the Welcome step of the wizard:
-
Copy the Project ID from GCP.
-
Paste the Project ID into CloudGuard.
-
In CloudGuard, click Next.
-
-
In the Configurations step of the wizard:
-
Optional - For Environment Display Name, enter a name for the integration to appear in the CloudGuard UI. By default, the Display Name is the Project ID.
-
Select an Organizational Unit to associate with the integration.
Note - An integration of GCP with CloudGuard CNAPP
Cloud-Native Application Protection Platform - a cloud-native security model that encompasses Cloud Security Posture Management (CSPM), Cloud Service Network Security (CSNS), and Cloud Workload Protection Platform (CWPP) in a single holistic platform. always includes the CSPM feature in CloudGuard CNAPP. The CSPM slider is on by default, and cannot be turned off.
-
Optional - To onboard GCP to CloudGuard without onboarding Google Workspace, move the Workspace slider to "off".
Note - It is also possible to connect Google Workspace to CloudGuard after you finish the GCP onboarding.
-
Click Next.
-
-
In the Connect step of the wizard:
-
Click Onboarding Script to review the GCP onboarding script that CloudGuard generates automatically.
-
Copy the command from CloudGuard.
-
Paste the command into the CLI of the GCP project.
The CLI of the GCP project generates a JSON
JavaScript Object Notation. A lightweight data interchange format. that contains GCP credentials.
-
In the CLI of the GCP project, copy the JSON (including the opening and closing brackets).
-
In CloudGuard, paste the JSON into the Credentials JSON field.
-
Click Next.
-
-
In the Workspace step of the wizard, do one of these:
-
If you are onboarding a Google Workspace:
-
Follow the instructions shown in the CloudGuard UI to configure Google Workspace.
-
Click Next.
-
-
If you are not onboarding a Google Workspace, click Skip.
-