IAP in Front of a Web Backend: Who Gets Through, How Often They Prove It

Identity-Aware Proxy access to a web backend service: the httpsResourceAccessor binding that decides who gets through (nobody by default), re-authentication every eight hours by the method you choose, the Host header check against your domains, and a troubleshooting link on the denied page. IAP guards the path through the load balancer and no other; the backend must still verify the signed header.

This is the operations reference: version drift, dependants and neighbours. For what the module provisions, its inputs and outputs, and how to buy it, see the catalogue entry.

terraformGoogle CloudSecurity & Identityv1.0.0static-validated

Provider drift

This artifact declares no Terraform provider requirements, so there is nothing to drift. Provider freshness applies to Terraform and OpenTofu modules.

What depends on this

No reference architecture names this module, so changing it affects only configurations that reference it directly.

Nearest alternatives

Same cloud, same category. These are what you would weigh against it without changing provider.

The same job on other clouds

Zero Trust Application Access on other providers. Useful when the cloud is still open, or when you are pricing a second one. How far a comparison like that can be trusted is covered in comparing clouds.

Installing it

module "gcp_iap_web" {
  source  = "www.iac-bazaar.com/iac-bazaar/gcp-iap-web/gcp"
  version = "1.0.0"
}

A registry token is required for the download itself. Installing through the registry protocol has the two credential steps.