> ## Documentation Index
> Fetch the complete documentation index at: https://docs.iru.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Google Cloud Platform

> Connect Google Cloud Platform to Iru Compliance with a read-only service account and JSON key.

### About Google Cloud Platform

Iru connects to your **Google Cloud** project with a **service account** and a **JSON key**. Create the account once, grant the **read-only** roles you need, then upload the key in Iru. Iru collects configuration and inventory evidence. It does **not** change resources in your project.

### How It Works

Iru authenticates with the service account **JSON key** you upload in the connector wizard. Grant roles at the **project** level so Iru can read resources in that project.

| Detail             | Value                    |
| ------------------ | ------------------------ |
| **Category**       | Cloud infrastructure     |
| **Authentication** | Service account JSON key |

#### What Iru collects

| Source                              | Evidence Iru collects                                                                                                                              |
| ----------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------- |
| Google BigQuery                     | Dataset and table inventory, dataset access, encryption, and expiration settings                                                                   |
| Google Cloud IAM                    | Principals, service accounts, custom roles, and role bindings across the resource hierarchy                                                        |
| Google Cloud Key Management Service | Key rings and keys, including protection level, rotation schedule, and state                                                                       |
| Google Cloud Logging                | Log sinks, retention settings, and admin activity records (excluding logs with private contents)                                                   |
| Google Cloud Storage                | Bucket inventory and settings such as public access prevention, uniform bucket-level access, versioning, retention, encryption, and access logging |
| Google Compute Engine               | VPC networks, subnets, firewall rules, and routes                                                                                                  |

#### Read-only roles

Add each role you need. All of these roles are read-only.

| Role                   | Role ID                       | What it covers                                                                     |
| ---------------------- | ----------------------------- | ---------------------------------------------------------------------------------- |
| Security Auditor       | `roles/iam.securityAuditor`   | IAM: resources, folder and project hierarchy, policies, and security configuration |
| BigQuery Data Viewer   | `roles/bigquery.dataViewer`   | BigQuery: datasets and their contents                                              |
| Cloud KMS Viewer       | `roles/cloudkms.viewer`       | Cloud KMS: get and list on keys and key rings                                      |
| Compute Network Viewer | `roles/compute.networkViewer` | Compute Engine: read-only networking resources                                     |
| Logs Viewer            | `roles/logging.viewer`        | Cloud Logging: view logs except those with private contents                        |
| Storage Bucket Viewer  | `roles/storage.bucketViewer`  | Cloud Storage: buckets and metadata (excluding IAM policies)                       |

Official references: [Service accounts](https://cloud.google.com/iam/docs/service-account-overview), [Create service account keys](https://cloud.google.com/iam/docs/keys-create-delete), [Organization policies for service accounts](https://docs.cloud.google.com/iam/docs/service-accounts-custom-constraints).

### Prerequisites

* Permission in Google Cloud to create **service accounts** and **service account keys** in the project you want Iru to monitor (for example **Service Account Admin** and **Service Account Key Admin**).
* **Admin** access to the Iru web app.
* The Google Cloud **project** you want Iru to monitor. Grant roles on that project so evidence covers its resources.

### Connect Google Cloud Platform to Iru

Create the service account and JSON key in **Google Cloud**, then upload the key in **Iru Compliance**.

<Tabs>
  <Tab title="Google Cloud">
    <Note>
      Complete this tab before you turn on **Google Cloud Platform** in **Iru Compliance**.
    </Note>

    #### Create the service account and grant roles

    <Steps>
      <Step title="Sign in and select the project">
        Open the [Google Cloud console](https://console.cloud.google.com/) and select the **project** Iru should monitor.
      </Step>

      <Step title="Open Service Accounts">
        In the navigation menu, go to **IAM & Admin** → **Service Accounts**.

        <Frame>
          <img src="https://mintcdn.com/iru/HMIBk0Tq7gdyWA0i/assets/media/images/iru-compliance-source-google-service-account.png?fit=max&auto=format&n=HMIBk0Tq7gdyWA0i&q=85&s=447d80eb8fd9ad7a60f4de5f976611de" alt="Google Cloud console navigation showing IAM and Admin with Service Accounts selected" width="1116" height="1214" data-path="assets/media/images/iru-compliance-source-google-service-account.png" />
        </Frame>
      </Step>

      <Step title="Create the service account">
        Click **Create service account**. Enter a **Service account name** (for example **Iru Compliance**). Google fills in the service account ID and email. Click **Create and continue**.
      </Step>

      <Step title="Grant the read-only roles">
        In the **Permissions** step, add each role from the [**Read-only roles**](#read-only-roles) table that you need, then click **Continue** and **Done**.

        <Frame>
          <img src="https://mintcdn.com/iru/HMIBk0Tq7gdyWA0i/assets/media/images/iru-compliance-source-google-permissions.png?fit=max&auto=format&n=HMIBk0Tq7gdyWA0i&q=85&s=4d5a4ee57340eab8d5a01b7b58d4083d" alt="Google Cloud Permissions step with Security Auditor, BigQuery Data Viewer, Cloud KMS Viewer, Compute Network Viewer, Logs Viewer, and Storage Bucket Viewer roles" width="1027" height="1807" data-path="assets/media/images/iru-compliance-source-google-permissions.png" />
        </Frame>

        <Tip>
          You can grant only the roles you need now. Adding all six means you do not have to return to the console later.
        </Tip>
      </Step>
    </Steps>

    #### Create and download the JSON key

    <Steps>
      <Step title="Open the service account">
        Go to **IAM & Admin** → **Service Accounts**, then open the account you created.
      </Step>

      <Step title="Select the Keys tab">
        Select the **Keys** tab.
      </Step>

      <Step title="Click Add key">
        Click **Add key**.

        <Frame>
          <img src="https://mintcdn.com/iru/HMIBk0Tq7gdyWA0i/assets/media/images/iru-compliance-source-google-add-key.png?fit=max&auto=format&n=HMIBk0Tq7gdyWA0i&q=85&s=127325d179363697d9b34581aa2e12db" alt="Google Cloud service account Keys tab with Add key for Iru Compliance" width="1692" height="1092" data-path="assets/media/images/iru-compliance-source-google-add-key.png" />
        </Frame>
      </Step>

      <Step title="Create a new key">
        Click **Create new key**.
      </Step>

      <Step title="Select JSON and create the key">
        Select **JSON**, then click **Create**. The key file downloads to your computer.

        <Frame>
          <img src="https://mintcdn.com/iru/HMIBk0Tq7gdyWA0i/assets/media/images/iru-compliance-source-google-json-key.png?fit=max&auto=format&n=HMIBk0Tq7gdyWA0i&q=85&s=b71d635a8b30cf01a36637f045df46c1" alt="Create private key dialog for Iru Compliance with JSON selected" width="767" height="453" data-path="assets/media/images/iru-compliance-source-google-json-key.png" />
        </Frame>
      </Step>

      <Step title="Store the key securely">
        Google cannot recover this file if you lose it. Anyone with the file has the service account’s access. Store it in a password manager or secrets vault, and delete your local copy after you connect the source in Iru.
      </Step>
    </Steps>

    <AccordionGroup>
      <Accordion title="If your organization restricts predefined roles">
        Some organizations limit which predefined roles an admin can grant. Build a custom role with the same read-only permissions instead:

        1. Go to **IAM & Admin** → **Roles** and click **Create role**.
        2. Add the permissions you need. Use the role IDs in [**Read-only roles**](#read-only-roles) as a reference for what each predefined role includes.
        3. Assign the custom role to the service account instead of the predefined roles.
      </Accordion>

      <Accordion title="Optional: create the service account with gcloud">
        If you prefer the CLI, run this with **gcloud** while signed in as a user who can create service accounts and keys in the project. Set `PROJECT_ID`, then run the script.

        ```bash theme={null}
        # Set these two values, then run the script.
        PROJECT_ID="your-project-id"
        SA_NAME="iru-compliance"
        SA_EMAIL="${SA_NAME}@${PROJECT_ID}.iam.gserviceaccount.com"

        gcloud config set project "$PROJECT_ID"

        # 1. Create the service account
        gcloud iam service-accounts create "$SA_NAME" \
          --display-name="Iru Compliance"

        # 2. Bind the read-only roles at the project level
        for ROLE in \
          roles/iam.securityAuditor \
          roles/bigquery.dataViewer \
          roles/cloudkms.viewer \
          roles/compute.networkViewer \
          roles/logging.viewer \
          roles/storage.bucketViewer
        do
          gcloud projects add-iam-policy-binding "$PROJECT_ID" \
            --member="serviceAccount:${SA_EMAIL}" \
            --role="$ROLE"
        done

        # 3. Create the JSON key in the current directory
        gcloud iam service-accounts keys create iru-compliance-key.json \
          --iam-account="$SA_EMAIL"
        ```

        The script writes `iru-compliance-key.json` to the directory you run it from. Upload that file in the [**Iru Compliance**](#iru-compliance) tab.
      </Accordion>
    </AccordionGroup>

    <Note>
      Continue on the [**Iru Compliance**](#iru-compliance) tab.
    </Note>
  </Tab>

  <Tab title="Iru Compliance">
    <Note>
      Finish the [**Google Cloud**](#google-cloud) tab first so you have the JSON key file.
    </Note>

    <Steps>
      <Step title="Open Sources">
        In Iru Compliance, on the left navigation bar, expand **Compliance** and select **Sources**.

        <Frame>
          <img src="https://mintcdn.com/iru/tI0HDLDwHj8r9Ile/assets/media/images/iru-navigation-compliance-sources.png?fit=max&auto=format&n=tI0HDLDwHj8r9Ile&q=85&s=87dcef15fc17d2fb9a6e53f454e41710" alt="Left navigation: Compliance expanded, Sources selected" width="410" height="1024" data-path="assets/media/images/iru-navigation-compliance-sources.png" />
        </Frame>
      </Step>

      <Step title="Turn on Google Cloud Platform">
        Find **Google Cloud Platform** (set **Category** to **Cloud infrastructure** or use **Search by name or description**). On that card, turn on the **toggle**. A browser tab or window may open for the connector wizard.
      </Step>

      <Step title="Upload the JSON key">
        On the setup screen, click **Choose File** and select the JSON key you downloaded. The contents of the file appear in the field below.
      </Step>

      <Step title="Finish the connection">
        Click **Save**, then click **Connect**. When the connection succeeds, the wizard shows **Connection Configured**.
      </Step>

      <Step title="Confirm the source is Active">
        Close the **Iru is requesting access to external services** browser tab, then return to **Compliance** → **Sources** and confirm the **Google Cloud Platform** card is **Active**.
      </Step>
    </Steps>
  </Tab>
</Tabs>

### Troubleshooting

<AccordionGroup>
  <Accordion title="Nothing opens when you turn the source on">
    Check **pop-up blocker** settings for the Iru site and try again.
  </Accordion>

  <Accordion title="Key creation is blocked by organization policy">
    If **Create** returns a policy error, your organization may enforce `constraints/iam.disableServiceAccountKeyCreation`. An organization policy administrator must add an exception for your project before you can download a key. See Google’s guide to [organization policies for service accounts](https://docs.cloud.google.com/iam/docs/service-accounts-custom-constraints).
  </Accordion>

  <Accordion title="Connection fails or evidence is incomplete">
    Confirm the JSON key belongs to the service account in the correct **project**, and that the account has the roles listed under [**Read-only roles**](#read-only-roles) for the evidence you need.
  </Accordion>
</AccordionGroup>

### Related Articles

<CardGroup cols={2}>
  <Card title="Sources Management" icon="plug" href="/en/compliance/sources-management">
    Browse and manage every Compliance source.
  </Card>

  <Card title="Getting Started With Compliance" icon="rocket" href="/en/compliance/getting-started-with-compliance">
    Frameworks, actions, and **Artifacts**.
  </Card>

  <Card title="Iru Overview" icon="layer-group" href="/en/iru/platform-overview/iru-overview">
    How Endpoint, Compliance, and Identity fit together.
  </Card>

  <Card title="Artifacts Management" icon="folder-open" href="/en/compliance/artifacts-management">
    Upload, review, and organize evidence from sources and actions.
  </Card>
</CardGroup>
