Files
riposte-marketplace/integrations/gcp-security/manifest.yaml
T
Guillaume BOURGEOIS 5501297984 feat(gcp-security): new Google Cloud cloud-containment integration
Compute Engine + Security Command Center, 7 commands: list/create/delete VPC
firewall rules (deny to isolate), list/stop instances, list SCC findings.
Service-account RS256 JWT auth (remote engine, PyJWT + cryptography).

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
2026-07-11 23:54:02 +02:00

98 lines
4.2 KiB
YAML

id: gcp_security
name: Google Cloud
version: 1.0.0
description: "Google Cloud Platform (Compute Engine + Security Command Center) — cloud containment: list/create/delete VPC firewall rules (deny to isolate), list and stop Compute Engine instances, and list Security Command Center findings. Authenticates with a Google service account (RS256 JWT bearer flow). Runs on a remote engine. Requires the Python 'PyJWT' and 'cryptography' libraries on the engine host (pip install pyjwt cryptography)."
changelog: "1.0.0 — Initial release: list/create/delete firewall rules, list/stop instances, list Security Command Center findings."
category: cloud
# Per-instance configuration. The scripts build a signed RS256 assertion from the
# service account's private_key/client_email and exchange it for an access token
# (scope cloud-platform). The service account needs Compute and Security Center
# roles. organization_id is only used by gcp-list-scc-findings.
config_schema:
properties:
service_account_json:
type: string
description: "Full service account key JSON (must contain client_email and private_key)"
x-soar-sensitive: true
project_id:
type: string
description: "GCP project ID"
organization_id:
type: string
description: "GCP organization ID (only required for Security Command Center findings)"
required:
- service_account_json
- project_id
commands:
- id: list_firewalls
name: gcp-list-firewalls
description: "List VPC firewall rules in the project."
risk: read
inputs_schema:
properties: {}
required: []
outputs_schema: { properties: {} }
- id: create_firewall
name: gcp-create-firewall
description: "Create a VPC firewall rule (e.g. a deny rule to isolate targets)."
inputs_schema:
properties:
name: { type: string, description: "Firewall rule name" }
network: { type: string, description: "Network name (default 'default')" }
direction: { type: string, description: "INGRESS or EGRESS (default INGRESS)" }
action: { type: string, description: "allow or deny (default deny)" }
protocol: { type: string, description: "Protocol (tcp, udp, all — default all)" }
ports: { type: string, description: "Comma-separated ports (optional; omit for all)" }
ranges: { type: string, description: "Comma-separated source/destination CIDR ranges (default 0.0.0.0/0)" }
priority: { type: number, description: "Rule priority 0-65535 (default 1000)" }
target_tags: { type: string, description: "Comma-separated target network tags (optional)" }
required: [name]
outputs_schema: { properties: {} }
- id: delete_firewall
name: gcp-delete-firewall
description: "Delete a VPC firewall rule by name."
inputs_schema:
properties:
name: { type: string, description: "Firewall rule name" }
required: [name]
outputs_schema: { properties: {} }
- id: list_instances
name: gcp-list-instances
description: "List Compute Engine instances in a zone."
risk: read
inputs_schema:
properties:
zone: { type: string, description: "Zone (e.g. europe-west1-b)" }
required: [zone]
outputs_schema: { properties: {} }
- id: stop_instance
name: gcp-stop-instance
description: "Stop a Compute Engine instance (containment)."
inputs_schema:
properties:
zone: { type: string, description: "Zone of the instance" }
instance: { type: string, description: "Instance name" }
required: [zone, instance]
outputs_schema: { properties: {} }
- id: list_scc_findings
name: gcp-list-scc-findings
description: "List Security Command Center findings for the organization."
risk: read
inputs_schema:
properties:
filter: { type: string, description: "Optional SCC filter (e.g. state=\"ACTIVE\")" }
page_size: { type: number, description: "Max findings (default 100)" }
required: []
outputs_schema: { properties: {} }
- id: test_connection
name: gcp-test-connection
description: "Verify the service-account token exchange and project access (used by the Test button)."
risk: read
inputs_schema:
properties: {}
required: []
outputs_schema: { properties: {} }