is there a way to restrict creation of specific resource in GCP irrespective of the IAM roles?

Viewed 238

I need to restrict creation of VPCsof all the projects irrespective of the IAM roles.

I tried the organisation policies, I was not able to find any policy which restricts the creation of resources.

Is there any other way I can do restrict creation of VPCs?

1 Answers

It's not possible to restrict VPC creation using Organization policies but there's another approach utilizing IAM roles & permissions.

Have a look at the documentation regarding roles needed to administer all your networks.

The most powerful role is roles/compute.networkAdmin which gives you control over every aspect of networking in your project;

Permissions to create, modify, and delete networking resources, except for firewall rules and SSL certificates. The network admin role allows read-only access to firewall rules, SSL certificates, and instances (to view their ephemeral IP addresses). The network admin role does not allow a user to create, start, stop, or delete instances.

If you want to limit users' permissions assign them a roles/compute.networkUser role:

Provides access to a shared VPC network

Once granted, service owners can use VPC networks and subnets that belong to the host project. For example, a network user can create a VM instance that belongs to a host project network but they cannot delete or create new networks in the host project.

And if you want some examples have a look at this document describing a IAM roles for Networking-related Job Functions.

Related