What do we fetch from GCP?
- bigquery datasets
Which APIs need to be enabled for the integration?
The following APIs are required for the Integration:
- In short, GCP is designed such that a product can be in use even though its API (or, if they’re separate, its Admin API) is disabled. If all Vanta can deduce is that the API is disabled, we can’t conclude that there isn’t insecure infrastructure behind it! That’s an admittedly odd decision on GCP’s part.
For customers concerned about enabling the API constituting a risk: enabling the API does create a route for other programmatic access to a service, it doesn’t also confer permissions to use or modify that service. Keeping unused APIs disabled is, in some sense, a control, but it’s a thankfully redundant one.
For customers concerned about pricing: these metadata APIs are billed differently from the products themselves. Don’t worry––our polling the Spanner API will not incur astronomical Spanner bills. For a typical project, Vanta’s API usage across all products is measured in U.S. cents.
Are there other options to set up the integration besides using cloud shell?
Yes. The steps included in the shell script can be performed manually through the GCP cloud console UI. Please see this video for guidance on connecting using the GCP console