Networking

GCP networking decides what is reachable: firewall rules that open ingress to the internet, VPC peering and shared VPC that let a foothold in one network reach another, Cloud DNS records left dangling at released resources, and load balancers that front backends. Networking rarely compromises a project on its own, but it turns a reachable foothold into reach across the environment and captures trusted names.

What folds in here#

  • Firewall rules: opening ingress with compute.firewalls.create/update, and finding rules already open to 0.0.0.0/0.
  • VPC: peering, shared VPC, and routes to pivot to internal instances and services.
  • Cloud DNS: hijacking dangling records that point at released GCP resources.
  • Load balancing: forwarding rules and backend services that expose or reach backends.

Identity-based movement (impersonation and actAs across projects) lives in identity; this surface is the network layer.

References#

Cookie Consent

We use cookies to enhance your experience. Learn more