Table of contents

Add a Google Cloud Platform account

When you add a Google Cloud Platform (GCP) account to Workload Security, all GCP VM instances associated with that account are imported into Workload Security and become visible in the Workload Security console in Computers > your_GCP_service_account > your_GCP_project.

Once imported, the GCP VM instances can be managed like any other computer.

Adding a GCP account to Workload Security is equivalent to adding a GCP connector through the Workload Security API.

Benefits of adding a GCP account

The following are benefits of adding a GCP account (through Computers > Add GCP Account) instead of adding individual GCP VMs (through Computers > Add Computer):

  • Changes in your GCP VM inventory are automatically reflected in the Workload Security console. For example, if you delete a number of VM instances in GCP, those instances disappear automatically from the manager. By contrast, if you use Computers > Add Computer, GCP instances that you have deleted remain visible in the manager until you manually delete them.
  • VMs are organized into projects in the manager, which lets you easily see which GCP VMs are protected and which are not. Without the GCP account, all your GCP VMs appear at the same root level under Computers.
  • Your smaller-sized GCP instances are billed at a lower rate (if you are using metered billing). By contrast, if you use Computers > Add Computer, all your GCP instances regardless of size are billed at the highest Data Center rate. For details on billing, see About billing and pricing.

Configure a proxy setting for the GCP account

Optionally, you can configure Workload Security to use a proxy server to access resources in GCP service accounts. For details, see Connect to cloud accounts via proxy.

Add a GCP account to Workload Security

To add a GCP account to Workload Security:

  1. If you have not done so already, Create a Google Cloud Platform service account for Workload Security.
  2. In the Workload Security console, go to Computers > Add > Add GCP Account.
    Add Computers
  3. Enter a Display Name. You should use the GCP service account name. Examples: GCP Workload Security, Finance GCP Workload Security, Marketing GCP Workload Security.
  4. Choose the Service Account Key. The key is a JSON file that you saved earlier, when creating the GCP service account. See Create a Google Cloud Platform service account for details.
  5. Click Next.
  6. Review the summary information, and then click Close. The following occurs:
    • The Workload Security console displays your GCP service account and its associated projects in their own branch on the left side of the Computers page, as per the following illustration. Associated VMs are displayed in the main pane. You can right-click your GCP service account name and select Synchronize Now to see the latest set of GCP VMs.
    • If you previously added VM instances from this service account through the Computers > Add Computers option (instead of the Computers > Add GCP Account option described here), these VMs are moved to the correct project under the service account you just added. This move occurs only for VMs that have the agent version 12.0 or later installed. VMs with pre-12.0 agents remain listed under the root Computers folder.
      The following image shows the imported GCP service account, projects, and a VM.
      Smart Folders tree with GCP service account
  7. Repeat the steps in this procedure for each GCP service account you want to add.

You have now added a GCP service account to Workload Security. Proceed to Install the agent on Google Cloud Platform VMs if you have not done so already.

Remove a GCP account

Removing a GCP account from the Workload Security console is permanent, but it does not affect the GCP account. VM instances with agents continue to be protected, but do not receive security updates. If you later reactivate agents on these VM instances, the agents will download the latest security updates at the next scheduled update.

To remove a GCP account:

  1. In the Workload Security console, click Computers at the top.
  2. Right-click the GCP account in the tree on the left, and select Remove Cloud Account.
  3. Confirm that you want to remove the account.

Synchronize a GCP account

When you synchronize (sync) a GCP account, Workload Security connects to the GCP API to obtain and display the latest set of GCP VMs.

To force a synchronization immediately:

  1. In the Workload Security console, click Computers.
  2. On the left, right-click your GCP account and select Synchronize Now.

There is also a background synchronization that occurs every 10 minutes, and this interval is not configurable. If you force a synchronization, the background synchronization is unaffected and continues to occur according to its original schedule.