Docs

Prepare your Google Cloud project

Let Identity-Aware Proxy reach your instances, enable the APIs Ostgate calls, and grant the IAM roles each person needs.

Updated

This is a one-time job for whoever administers the project. Ostgate acts entirely as the signed-in Google account, so it can do exactly what that account's IAM roles allow and nothing more.

1. Let Identity-Aware Proxy reach your instances

IAP connects to your instances from the address range 35.235.240.0/20. Add a firewall rule on the instances' VPC network that allows ingress from that range to the ports you use: 22 for SSH, 3389 for RDP, and any other port you want to tunnel.

In the Cloud Console: VPC network › Firewall › Create firewall rule, direction Ingress, source IPv4 range 35.235.240.0/20, and the TCP ports above. Or, for an administrator who uses the command line:

gcloud compute firewall-rules create allow-iap-ingress \
    --project=PROJECT_ID --network=NETWORK \
    --direction=INGRESS --action=allow \
    --rules=tcp:22,tcp:3389 --source-ranges=35.235.240.0/20

2. Enable the APIs you will use

In the project that holds the resources, under APIs & Services › Enable APIs and services:

  • Compute Engine API: always.
  • Cloud OS Login API: if your instances use OS Login.
  • Cloud SQL Admin API, Cloud Run Admin API, Cloud Logging API and Secret Manager API: only for the Cloud SQL and Cloud Run lists, the event log and Secret Manager credentials respectively.

When an API is off, Ostgate says so on that project only, and the rest of the app keeps working.

3. Grant IAM roles

Grant these to each person's Google account, on the project or on individual instances.

ToGrant
See instances, their serial output and SSH keys roles/compute.viewer (Compute Viewer)
Connect at all: SSH, RDP, files, tunnels, forwards roles/iap.tunnelResourceAccessor (IAP-secured Tunnel User)
SSH to instances that use OS Login roles/compute.osLogin, or roles/compute.osAdminLogin for sudo
SSH to instances without OS Login, set a Windows password, start and stop instances roles/compute.instanceAdmin.v1 (Compute Instance Admin)
See the event log roles/logging.viewer (Logs Viewer)
Use a password or key kept in Secret Manager roles/secretmanager.secretAccessor, plus roles/secretmanager.viewer to pick it from a list
See Cloud SQL instances roles/cloudsql.viewer (Cloud SQL Viewer)
See Cloud Run services roles/run.viewer (Cloud Run Viewer)

Google additionally requires roles/iam.serviceAccountUser on an instance's service account for OS Login access to that instance. The one role every connection needs is the IAP tunnel role; for an administrator:

gcloud projects add-iam-policy-binding PROJECT_ID \
    --member=user:EMAIL --role=roles/iap.tunnelResourceAccessor