GCP Cloud Account Onboarding
Learn about GCP cloud account onboarding prerequisites and the onboarding
workflow in Strata Cloud Manager.
| Where Can I Use This? | What Do I Need? |
- Prisma AIRS AI Runtime Security in
GCP
|
|
Onboarding your Google Cloud Platform account connects it to Strata Cloud Manager so
Prisma® AIRS™ can discover and protect your AI workloads. Without onboarding, Prisma
AIRS cannot see your cloud resources or intercept AI traffic flowing through virtual
machines, GKE clusters, or Vertex AI services in your GCP environment.
The onboarding process uses a Terraform template you download from Strata Cloud Manager
to create a service account in your GCP project. The service account grants Prisma
AIRS the permissions it needs to read VPC flow logs and Vertex AI audit logs,
enumerate assets such as GKE clusters, Compute Engine instances, and AI models,
and route discovered assets into the AI Runtime firewall protection workflow.
Before running the onboarding workflow in
Strata Cloud Manager, complete the
GCP Cloud Account Onboarding Prerequisites: enable VPC
flow logs and Vertex AI Data Access Audit Logs, create a Cloud Storage bucket and
Log Router sink to collect those logs, assign the required IAM permissions to your
Terraform user, and create the GCP service identity.
After completing the prerequisites, use
Onboard GCP Cloud Account in Strata Cloud Manager to select
permission scopes, define application boundaries for asset grouping, download and
apply the Terraform template in GCP, and validate asset discovery. Logs can take
up to an hour to populate in the storage bucket after initial onboarding.