Google CloudStatic-verified

The Rule that Wins over Every Allow

A deny policy is evaluated before any allow and stops the request whatever roles the caller holds, Owner included - the only way to say nobody deletes the audit bucket and mean it. public:all with the break-glass group excepted is the shape; a rule with no exceptions locks out break-glass too and says so; a rule conditioned on a tag denies nothing until the tag is attached, and is counted.

terraformGoogle Cloudgcp
gcp-iam-deny-policyvizier v1.2.0

Verification

Static-verified

Passed: validated and lint-clean (provider-schema-validated for AWS/Azure/GCP; Terraform-language lint elsewhere).

Conformance

  • Static validation (fmt · validate · tflint)
  • No applicable security policies for this provider
  • Plan tests (mocked: validation rules · outputs)

Provenance

  • SHA-256 checksum
  • Signature (pending)

Functional

  • Live test pending (no cloud run yet)

Last verified 2026-09-14 · how we verify

Use it from the registry

terraform · opentofu
module "iam_deny_policy" {
  source  = "www.iac-bazaar.com/iac-bazaar/gcp-iam-deny-policy/gcp"
  version = "1.0.0"
}

Needs a registry token from /account/tokens. The module itself is free; the account is what identifies you. Full setup: registry docs.

Inputs & outputs

Create a free account to read this module's contract

The declared contract - every input name, type, default and description, plus every output - is shown to signed-in accounts, not to anonymous visitors.

A free account sees the contract of every module in the catalogue. There is no subscription and nothing to buy - the modules are free to download, and they run under Vizier.

Documentation

gcp-iam-deny-policy

An IAM deny policy: the rule that wins over every allow. Works with Terraform and OpenTofu (>= 1.6), google provider >= 6.0, < 7.0.

Deny is evaluated first and cannot be out-granted. Allow policies at every level add up; a deny policy is checked before any of them, and an explicit deny stops the request whatever roles the caller holds, Owner included. It is the only way to write "nobody deletes the audit bucket" and mean nobody.

principalSet://goog/public:all is how you say everyone. The usual intent is everyone except the break-glass group: deny public:all and put the group in exception_principals. A rule with no exceptions denies the break-glass group too - sometimes the point, sometimes a lock-out - and needs accept_no_break_glass.

A conditioned deny waits for its trigger. A CEL condition over resource tags means the rule denies nothing until the tag is attached. A policy whose every rule is conditional needs accept_only_conditional_rules; acts_immediately reports whether anything denies on day one.

Permissions are written service.googleapis.com/verb, not the role spelling. A validation checks the shape, because the API's error does not.

Verification

Static validation runs tofu fmt, init, validate, tflint and checkov. This module has not yet had a live test, so it is published as statically validated with its live test pending and does not carry the live-tested mark.

Usage code & full reference need an account

The complete copy-paste usage, the full input/output reference, and operational notes are free with an account - shown here and bundled in the download. Sign in and this section fills in.

  • Usage

Related modules

Static validatedLive test pending

gcp-firewall-policy

A global network firewall policy exists independently of any network; an association puts it in the path, and a policy with a hundred rules and none governs nobody while rendering as fully configured. enable_logging defaults to false on every rule, so a deny that fires leaves no evidence. Refuses a policy with no network, logs every rule unless told not to, and counts the disabled ones.

View module
Static validatedLive test pending

gcp-service-perimeter

spec is the dry-run configuration and status is the enforced one - two blocks of the same shape, and a perimeter with only a spec is evaluated on every request, logs violations, and blocks nothing. Empty restricted_services is the other way to have none: the perimeter exists, covers the projects, and governs no API.

View module
Static validatedLive test pending

gcp-recaptcha

A key with a testing score returns that score for every assessment, bots included - right for staging and, on a production key, a filter that filters nothing; allow_all_domains lets any site consume your assessments against your quota. Testing mode refused without acceptance, domains required on web keys, invisible scoring by default; only a backend assessment call turns a token into a decision.

View module
Static validatedLive test pending

gcp-cloud-ids

Creating the endpoint creates no packet mirroring policy, so an endpoint with nothing mirrored is provisioned, billed by the hour, shown with a green check and has never seen a packet. The mirroring policy is created with it and refused when it mirrors nothing. Cloud IDS detects and never blocks; blocks_traffic is an output that is always false.

View module
Live-tested

gcp-cloud-armor

A global Cloud Armor WAF policy with preconfigured OWASP SQLi and XSS rules enforcing by default, an optional per-client rate limit, and custom IP allow/deny rules - attachable to many backends.

View module
Static validatedLive test pending

gcp-security-command-center

The findings page is not a pager: a project accumulates thousands of findings with nobody having received a message, and a mute rule silences a whole category, now and in future, with no record why. Streams CRITICAL and HIGH findings to a Pub/Sub topic as a requirement, refuses a mute without a written reason, and refuses a custom detector created DISABLED, which is listed and evaluates nothing.

View module