Skip to main content

Identity-Aware Proxy

Identity-Aware Proxy (IAP) TCP forwarding opens a tunnel to a private resource only after an IAM check, so nothing needs a public address or a VPN. The GCP Enterprise Baseline gives each group IAP and OS Login access to the stage projects it may reach, and can add one bastion per isolation domain.

What it does​

With IAP TCP forwarding, a client such as gcloud compute ssh --tunnel-through-iap connects to Google, which checks that the caller holds roles/iap.tunnelResourceAccessor and then forwards the TCP stream from a fixed Google range to the target's private address. The target's firewall must admit that range. OS Login ties SSH access on a VM to the user's Google identity and IAM roles: roles/compute.osLogin lets a user log in without administrator rights, and no SSH key is kept in project metadata. Every tunnel and login is an audited, per-user event.

How BuiltForProd uses it​

No VPN. The organization-scoped remote-access unit (environments/core/network/global) turns group_access into three roles per group and project: roles/iap.tunnelResourceAccessor, roles/compute.osLogin and roles/compute.viewer, which gcloud needs to resolve an instance.

GroupsProjects they reach
Platform leads, platform engineers, both auditor groupsevery stage project and acme-core-network (all)
DevOps leadssandbox, dev, staging and prod
DevOps engineers; app, ETL and AI leadssandbox, dev and staging
App developers, ETL engineers, AI engineerssandbox and dev

The matrix is the module default; a deployment can override it in the unit.

Only tagged targets. The organization firewall policy allows the IAP range only to resources that carry the secure tag iap-target, on ports 22, 3389, 8080 to 8090, 27017 and 6379, and logs every allowed connection (Cloud NGFW firewall policies). A VM without the tag is unreachable through IAP even for a group that holds the IAM role. The organization policy compute.requireOsLogin and the project baseline's enable-oslogin metadata make OS Login the only way onto a VM.

Bastions (optional). enable_bastion = true in network.hcl, off by default, runs one e2-micro bastion per isolation domain in the hub's shared subnet, bastion-acme-prod and bastion-acme-nonprod, at about $7 per month each:

Each bastion is a Shielded VM with OS Login, no external address and a service account without roles, tagged iap-target. Because the hub peers with both domains, a VPC firewall rule denies each bastion's egress to the other domain, so a bastion forwards only into its own domain. Stage-limited groups get IAP access to the bastions of their domains only, plus a custom role that just resolves the instance; the all groups already hold access on acme-core-network.

Terms you will see​

TermMeaning
IAP TCP forwardingA tunnel from the client through Google to a private address, after IAM checks.
Tunnel Resource Accessorroles/iap.tunnelResourceAccessor, the right to open a tunnel.
OS LoginSSH as the user's own Google identity, governed by IAM.
iap-targetThe secure tag a resource needs to accept IAP traffic.
BastionA small VM in the hub that forwards into one isolation domain.

Where to read more​