Skip to main content

Connect Google Cloud

Argus scans a Google Cloud project read-only with a service-account key or an OAuth refresh token. Nothing is installed in the project, and Argus only ever reads.

Before you start​

  • Permission to create a service account and grant it roles on the project (or an OAuth client to mint a refresh token).
  • An available account slot: Free connects one account, Pro connects an unlimited number. See Billing & plans.

Provider-side setup​

  1. In the project, create a service account for Argus.
  2. Grant it read-only roles, such as Viewer and Security Reviewer, scoped to what you want scanned. Argus only reads.
  3. Create a JSON key for the service account. Alternatively, use an OAuth refresh token minted from an OAuth client.

Required permissions​

Grant the service account, at project (or folder / organization) scope:

  • roles/viewer (Viewer, read-only)
  • roles/serviceusage.serviceUsageConsumer
  • a small custom role adding storage.buckets.getIamPolicy
  • for organization-wide scans only: roles/cloudasset.viewer

Enable the IAM API (iam.googleapis.com) in at least one project, and the Cloud Asset API for organization-wide scans.

Connect in Argus​

Go to Accounts and click Connect account. Pick Google Cloud, then the recommended Service-account key method. Enter:

FieldValue
Project IDthe GCP project id
Service-account key (JSON)paste the full JSON key file contents

OAuth refresh token​

The OAuth refresh token method takes a Client ID, Client secret and Refresh token instead of a key file.

Connection test​

Finish the wizard. Argus stores the credential server-side and runs an asynchronous connection test before the first scan. The account card reports Connected, Checking…, or Failed. On a failure, re-check the values above and use Test connection on the account card to retry.

Official Google Cloud documentation​