Docs
Prepare your Google Cloud project
Let Identity-Aware Proxy reach your instances, enable the APIs Ostgate calls, and grant the IAM roles each person needs.
Updated
This is a one-time job for whoever administers the project. Ostgate acts entirely as the signed-in Google account, so it can do exactly what that account's IAM roles allow and nothing more.
1. Let Identity-Aware Proxy reach your instances
IAP connects to your instances from the address range 35.235.240.0/20. Add a
firewall rule on the instances' VPC network that allows ingress from that range to the
ports you use: 22 for SSH, 3389 for RDP, and any other port you want to tunnel.
In the Cloud Console: VPC network › Firewall › Create firewall rule, direction
Ingress, source IPv4 range 35.235.240.0/20, and the TCP ports above. Or,
for an administrator who uses the command line:
gcloud compute firewall-rules create allow-iap-ingress \
--project=PROJECT_ID --network=NETWORK \
--direction=INGRESS --action=allow \
--rules=tcp:22,tcp:3389 --source-ranges=35.235.240.0/20
2. Enable the APIs you will use
In the project that holds the resources, under APIs & Services › Enable APIs and services:
- Compute Engine API: always.
- Cloud OS Login API: if your instances use OS Login.
- Cloud SQL Admin API, Cloud Run Admin API, Cloud Logging API and Secret Manager API: only for the Cloud SQL and Cloud Run lists, the event log and Secret Manager credentials respectively.
When an API is off, Ostgate says so on that project only, and the rest of the app keeps working.
3. Grant IAM roles
Grant these to each person's Google account, on the project or on individual instances.
| To | Grant |
|---|---|
| See instances, their serial output and SSH keys | roles/compute.viewer (Compute Viewer) |
| Connect at all: SSH, RDP, files, tunnels, forwards | roles/iap. (IAP-secured Tunnel User) |
| SSH to instances that use OS Login | roles/compute.osLogin, or roles/compute.osAdminLogin for
sudo |
| SSH to instances without OS Login, set a Windows password, start and stop instances | roles/compute.instanceAdmin.v1 (Compute Instance Admin) |
| See the event log | roles/logging.viewer (Logs Viewer) |
| Use a password or key kept in Secret Manager | roles/secretmanager.secretAccessor, plus
roles/secretmanager.viewer to pick it from a list |
| See Cloud SQL instances | roles/cloudsql.viewer (Cloud SQL Viewer) |
| See Cloud Run services | roles/run.viewer (Cloud Run Viewer) |
Google additionally requires roles/iam.serviceAccountUser on an instance's
service account for OS Login access to that instance. The one role every connection needs
is the IAP tunnel role; for an administrator:
gcloud projects add-iam-policy-binding PROJECT_ID \
--member=user:EMAIL --role=roles/iap.tunnelResourceAccessor