Connect Google Cloud
Argus scans a Google Cloud project read-only with a service-account key or an OAuth refresh token. Nothing is installed in the project, and Argus only ever reads.
Before you start
- Permission to create a service account and grant it roles on the project (or an OAuth client to mint a refresh token).
- An available account slot: Free connects one account, Pro connects an unlimited number. See Billing & plans.
Provider-side setup
- In the project, create a service account for Argus.
- Grant it read-only roles, such as Viewer and Security Reviewer, scoped to what you want scanned. Argus only reads.
- Create a JSON key for the service account. Alternatively, use an OAuth refresh token minted from an OAuth client.
Required permissions
Grant the service account, at project (or folder / organization) scope:
roles/viewer(Viewer, read-only)roles/serviceusage.serviceUsageConsumer- a small custom role adding
storage.buckets.getIamPolicy - for organization-wide scans only:
roles/cloudasset.viewer
Enable the IAM API (iam.googleapis.com) in at least one project, and the
Cloud Asset API for organization-wide scans.
Connect in Argus
Go to Accounts and click Connect account. Pick Google Cloud, then the recommended Service-account key method. Enter:
| Field | Value |
|---|---|
| Project ID | the GCP project id |
| Service-account key (JSON) | paste the full JSON key file contents |
OAuth refresh token
The OAuth refresh token method takes a Client ID, Client secret and Refresh token instead of a key file.
Connection test
Finish the wizard. Argus stores the credential server-side and runs an asynchronous connection test before the first scan. The account card reports Connected, Checking…, or Failed. On a failure, re-check the values above and use Test connection on the account card to retry.