Identity-Aware Proxy
Identity-Aware Proxy (IAP) TCP forwarding opens a tunnel to a private resource only after an IAM check, so nothing needs a public address or a VPN. The GCP Enterprise Baseline gives each group IAP and OS Login access to the stage projects it may reach, and can add one bastion per isolation domain.
What it does
With IAP TCP forwarding, a client such as gcloud compute ssh --tunnel-through-iap connects to Google, which checks that the caller holds roles/iap.tunnelResourceAccessor and then forwards the TCP stream from a fixed Google range to the target's private address. The target's firewall must admit that range. OS Login ties SSH access on a VM to the user's Google identity and IAM roles: roles/compute.osLogin lets a user log in without administrator rights, and no SSH key is kept in project metadata. Every tunnel and login is an audited, per-user event.
How BuiltForProd uses it
No VPN. The organization-scoped remote-access unit (environments/core/network/global) turns group_access into three roles per group and project: roles/iap.tunnelResourceAccessor, roles/compute.osLogin and roles/compute.viewer, which gcloud needs to resolve an instance.
| Groups | Projects they reach |
|---|---|
| Platform leads, platform engineers, both auditor groups | every stage project and acme-core-network (all) |
| DevOps leads | sandbox, dev, staging and prod |
| DevOps engineers; app, ETL and AI leads | sandbox, dev and staging |
| App developers, ETL engineers, AI engineers | sandbox and dev |
The matrix is the module default; a deployment can override it in the unit.
Only tagged targets. The organization firewall policy allows the IAP range only to resources that carry the secure tag iap-target, on ports 22, 3389, 8080 to 8090, 27017 and 6379, and logs every allowed connection (Cloud NGFW firewall policies). A VM without the tag is unreachable through IAP even for a group that holds the IAM role. The organization policy compute.requireOsLogin and the project baseline's enable-oslogin metadata make OS Login the only way onto a VM.
Bastions (optional). enable_bastion = true in network.hcl, off by default, runs one e2-micro bastion per isolation domain in the hub's shared subnet, bastion-acme-prod and bastion-acme-nonprod, at about $7 per month each:
Each bastion is a Shielded VM with OS Login, no external address and a service account without roles, tagged iap-target. Because the hub peers with both domains, a VPC firewall rule denies each bastion's egress to the other domain, so a bastion forwards only into its own domain. Stage-limited groups get IAP access to the bastions of their domains only, plus a custom role that just resolves the instance; the all groups already hold access on acme-core-network.
Terms you will see
| Term | Meaning |
|---|---|
| IAP TCP forwarding | A tunnel from the client through Google to a private address, after IAM checks. |
| Tunnel Resource Accessor | roles/iap.tunnelResourceAccessor, the right to open a tunnel. |
| OS Login | SSH as the user's own Google identity, governed by IAM. |
iap-target | The secure tag a resource needs to accept IAP traffic. |
| Bastion | A small VM in the hub that forwards into one isolation domain. |
Where to read more
- GCP Enterprise Baseline overview for how people reach the platform.
- Compute Engine for the VM settings the Baseline enforces.
- Least privilege for access narrowed per group and stage.