TABLE OF CONTENTS
GCP Account Connection Overview
Before Aqua CSPM can produce any security scan results, you must connect a cloud account. For Google Cloud, this is done through the use of a Service Account. A Service Account is an entity that can be assumed by a third party and secured to only access resources in a project.
Drag and Drop (Recommended)
Step 1: Navigate to the Cloud Accounts page.
- Click Connect Account on the top right.
Step 2: Choose "Google Cloud Platform (GCP)" under Account Type and "Drag and Drop (Recommended)" under Method.
Step 3: Use the following steps to create a Service Account and attach a role.
- Log into your Google Cloud console and navigate to IAM Admin > Service Accounts.
- Click Create Service Account.
- Enter "Aqua" in the Service account name, enter "Aqua API Access" in the Service account description, and click Create.
- Select the role: Project > Viewer and click Continue.
- Click Done.
- Select the newly created Service Account.
- Select ADD KEY > Create new key.
- Select JSON > Create.
- Save the provided JSON file (Credentials).
Step 4: Drag and drop the newly created JSON file in the Aqua connection wizard.
Step 1: Follow the Drag and Drop Instructions without dragging and dropping the JSON file.
Step 2: Open the JSON file and copy and paste the Project ID, Client Email, and Private Key.
Did you find it helpful?Send feedback