Skip to content

Add GCP IAM Conditions evidence gates#1729

Open
cuph7022 wants to merge 2 commits into
UnitOneAI:mainfrom
cuph7022:cuph7022-gcp-iam-conditions-1727
Open

Add GCP IAM Conditions evidence gates#1729
cuph7022 wants to merge 2 commits into
UnitOneAI:mainfrom
cuph7022:cuph7022-gcp-iam-conditions-1727

Conversation

@cuph7022

@cuph7022 cuph7022 commented Jun 8, 2026

Copy link
Copy Markdown

Summary

  • Add IAM Conditions and time-bound access evidence gates to the GCP review workflow.
  • Extend output guidance with principal, role, resource scope, condition title, expiry/scope expression, unsupported basic/public grant status, evidence, and review status.
  • Add Terraform conditional binding examples, gcloud projects get-iam-policy export evidence, and unsupported basic/public grant checks to the benchmark checklist.
  • Bump gcp-review to version 1.1.0 and add Google IAM Conditions references.

Closes #1727

Validation

  • Reviewed the generated Markdown changes through the GitHub API compare output.
  • Confirmed the updated skill includes version: "1.1.0", the IAM Conditions evidence gate, and the output evidence table.
  • Confirmed the checklist includes Terraform condition examples, gcloud ... get-iam-policy, and unsupported basic/public grant checks.
  • Did not clone the repository, install dependencies, or run project code.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

[REVIEW] gcp-review: add IAM Conditions and time-bound access evidence gates

1 participant