GCP Cloud Account Onboarding
Focus
Focus
Prisma AIRS

GCP Cloud Account Onboarding

Table of Contents

GCP Cloud Account Onboarding

Learn about GCP cloud account onboarding prerequisites and the onboarding workflow in Strata Cloud Manager.
Where Can I Use This?What Do I Need?
  • Prisma AIRS AI Runtime Security in GCP
Onboarding your Google Cloud Platform account connects it to Strata Cloud Manager so Prisma® AIRS™ can discover and protect your AI workloads. Without onboarding, Prisma AIRS cannot see your cloud resources or intercept AI traffic flowing through virtual machines, GKE clusters, or Vertex AI services in your GCP environment.
The onboarding process uses a Terraform template you download from Strata Cloud Manager to create a service account in your GCP project. The service account grants Prisma AIRS the permissions it needs to read VPC flow logs and Vertex AI audit logs, enumerate assets such as GKE clusters, Compute Engine instances, and AI models, and route discovered assets into the AI Runtime firewall protection workflow.
Before running the onboarding workflow in Strata Cloud Manager, complete the GCP Cloud Account Onboarding Prerequisites: enable VPC flow logs and Vertex AI Data Access Audit Logs, create a Cloud Storage bucket and Log Router sink to collect those logs, assign the required IAM permissions to your Terraform user, and create the GCP service identity.
After completing the prerequisites, use Onboard GCP Cloud Account in Strata Cloud Manager to select permission scopes, define application boundaries for asset grouping, download and apply the Terraform template in GCP, and validate asset discovery. Logs can take up to an hour to populate in the storage bucket after initial onboarding.