咨询GCP项目级关闭公网端口及限制开发者开放公网端口的方法
1. How to Close Open Public Ports at the Project Level in GCP?
Closing open public ports across your GCP project starts with auditing and modifying your VPC firewall rules—these are the primary controls that allow traffic into your resources. Here's a practical step-by-step approach:
Audit existing public-facing firewall rules
- In the GCP Console: Navigate to VPC Network > Firewall. Look for rules where the
Source IP rangesfield includes0.0.0.0/0(or any broad public CIDR) andAllowed protocols and portslists ports that shouldn’t be exposed to the internet. - Using the
gcloudCLI: Run this command to filter and list all public-facing rules quickly:gcloud compute firewall-rules list --filter="sourceRanges:0.0.0.0/0" --format="table(name,allowed,sourceRanges,description)"
- In the GCP Console: Navigate to VPC Network > Firewall. Look for rules where the
Remediate the rules
- Delete unnecessary rules: If a rule is no longer needed (e.g., a test rule that left port 22 open to the world), delete it via the Console (select the rule > click Delete) or CLI:
gcloud compute firewall-rules delete YOUR_RULE_NAME - Restrict access instead of deleting: For rules that are necessary but shouldn’t be public, update the
Source IP rangesto only trusted IPs (like your team’s office network). Using CLI:gcloud compute firewall-rules update YOUR_RULE_NAME --source-ranges 192.168.1.0/24,203.0.113.5/32
- Delete unnecessary rules: If a rule is no longer needed (e.g., a test rule that left port 22 open to the world), delete it via the Console (select the rule > click Delete) or CLI:
Critical note: Project-level firewall rules apply to all VPC networks in your project. Always test changes in a non-production environment first to avoid breaking critical services (like SSH access to your VMs).
2. Preventing Public Port Exposure & Compliance Tools in GCP
Let’s break down your three sub-questions clearly:
A. How to block developers from opening public ports?
The most effective safeguards are using IAM permissions and organization policies:
- Restrict IAM permissions: Limit who can create or modify firewall rules. Avoid assigning broad roles like
roles/compute.adminto developers; instead, use granular roles likeroles/compute.instanceAdmin(which lets them manage VMs but not firewall rules). For custom access needs, create a custom IAM role that explicitly excludescompute.firewallRules.createandcompute.firewallRules.updatepermissions. - Enforce organization policies: Use the
constraints/compute.restrictFirewallRulespolicy at the organization or project level. This policy lets you define allowed source ranges, protocols, and ports for firewall rules. You can configure it to deny any rule that uses0.0.0.0/0as a source, effectively blocking public port openings. To set this up:- Go to IAM & Admin > Organization Policies in the Console.
- Search for "Restrict firewall rules".
- Set the policy to "Enforce" and define allowed source ranges (exclude
0.0.0.0/0).
B. Deny policies to block VMs with open public security rules?
You can’t directly block VM creation based on existing firewall rules, but the organization policy mentioned above (constraints/compute.restrictFirewallRules) prevents the creation of rules that would expose VMs to the public. Additionally, use Cloud Audit Logs to monitor any attempts to create public-facing rules, and set up alerts via Cloud Monitoring to notify admins immediately when such an attempt is made.
C. GCP tool similar to AWS Config for remediation?
Yes, GCP offers several tools for compliance monitoring and automated remediation:
- Google Cloud Policy Intelligence (formerly Config Controller): This tool lets you define compliance policies and automatically remediate non-compliant resources. For example, you can set a policy to delete any firewall rule with
0.0.0.0/0as a source, and Policy Intelligence will enforce this automatically. - Cloud Asset Inventory + Cloud Functions: Use Cloud Asset Inventory to detect non-compliant resources (like public firewall rules) in real time. Then, trigger a Cloud Function to remediate the issue—for example, updating the rule’s source IP range to a trusted CIDR or deleting the rule entirely.
- Security Command Center: This service provides compliance insights and alerts you to non-compliant resources. You can integrate it with Cloud Functions or third-party tools to build automated remediation workflows.
内容的提问来源于stack exchange,提问作者Dixon Joseph Dalmeida

