Connect one or more Google Cloud Platform (GCP) accounts with IBM® Guardium® Exposure Manager by running a script to discover sensitive data in the cloud accounts. The connection automatically creates three service accounts and a Workload Identity Federation that are needed to facilitate the functioning of IBM Guardium Exposure Manager.
Before you begin
Verify that you have the following before you start the process of connecting your Google Cloud Platform (GCP) accounts with IBM Guardium Exposure Manager:
- List of GCP project IDs and their regions to be connected with UIBM Guardium Exposure Manager
- A GCP user that has cloud shell access
About this task
Use the following steps to connect IBM Guardium Exposure Manager with GCP accounts.
Procedure
-
From the main menu, click .
-
On the Connections page, click Add connection.
-
On the Add connection page, select Google Cloud Platform, and then click Next.
-
In the Add projects step, provide the project details (Project ID, Project name, and Environment), and then click the plus icon.
Note:
- By default, the project that you add at first is tagged as the Primary project where the Analyzer is deployed. To know more about the Analyzer, see Analyzer.
- If you want to add more than one project, repeat the account addition process (provide Project ID, Project name, and Environment, and then click the plus icon) as many times as required.
-
After you have added all the projects, click Next.
-
In the Connect projects step, follow the on-screen instructions to run a script and connect the projects that you have added, and then click Next.
Note: If you click
Cancel instead of
Next, then you get either of the following status messages:
- Connection pending, signifying that the list of cloud accounts is saved but none of the cloud accounts are connected successfully.
- Progress saved, signifying that the list of cloud accounts is saved but only a few of the cloud accounts are connected successfully.
-
In the Review progress step, follow the on-screen instructions to establish the connection of the projects that you have added, and then click Next.
-
In the Add regions step, follow the on-screen instructions to add regions for the projects that you have added, and then click Next.
Note: If you click
Cancel instead of
Done, then the system displays one of the following status messages:
- No regions added, signifying that you have not added any regions. You can click Add regions in the status message or you can add the regions later.
- Regions partially added, signifying that you have added a few of the regions. You can add the other regions later.
- All steps completed, signifying that you have completed all the steps successfully and all your data is saved.
If you click
Done, then the system displays the following status message:
Projects connected successfully, signifying that you have connected all or a few of the projects successfully. If you have not added all the regions for the projects, you can click Add more regions in the status message or you can add the regions later.
Results
While you connect IBM Guardium Exposure Manager to a GCP, the following three accounts and a Workload identity federation are automatically created:
- Cross Project service account
- Scans and monitors the metadata of the data assets that are discovered by IBM Guardium Exposure Manager. Cross Project service account is a basic GCP managed “viewer” role.
- Analyzer service account
- Reads the data inside the customer’s data stores, allowing the Analyzer to classify what’s inside the data stores. Only the Analyzer can access the data stores and the stored data in your cloud account. An n1-standard-2 instance type is used as the Analyzer by IBM Guardium Exposure Manager. To know more about the analyzer, see Analyzer.
- Workload Identity Federation
- Securely authenticates IBM Guardium Exposure Manager's backend with the GCP projects, enabling IBM Guardium Exposure Manager to use the cross project service-account.
- Polar Installation service account
- Helps in the installation and updating of the Analyzer.
To know more about the scope of permissions of the service accounts, see Accounts and permissions for Google Cloud Platform (GCP).