GCP VPC Firewall
Integration & Setup Manual
GCP VPC Firewall Integration Guide
Overview
Cup’n’String Guard integrates with Google Cloud Platform (GCP) VPC Firewall to enforce AI tool network policies for GCP-hosted developer environments and CI/CD infrastructure. Guard uses the Compute Engine API to declaratively apply VPC firewall rules with async operations — polling operation IDs until completion and rolling back on failure.
Support level
Cloud-Native Rules — Compute Engine API declarative apply with async operation polling and ETag-based drift detection. Guard owns only its tagged rules in the designated VPC network.
Recommended Guard mode
Observe to audit current VPC firewall rules against the desired AI tool policy baseline, then Enforce to activate automatic rule management.
Known limitations
- GCP VPC firewall rules apply at the network level — per-process enforcement is not available.
- Guard manages one project/network pair per provider instance; create multiple providers for multi-project deployments.
- GCP Firewall Policies (hierarchical) are not currently managed by Guard — only classic VPC firewall rules.
Setup outline
- Confirm the supported platform and deployment requirements with your administrator.
- Use a dedicated integration identity with the minimum required permissions and validated TLS connections.
- Review policy in your environment before enabling enforcement, then verify the intended access outcomes.
Contact the Cup’n’String team for deployment-specific configuration and verification guidance. Never share credentials in support messages or screenshots.
Integration Info
Links
Verify what categories and runtimes this stack fits inside in the global compatibility dashboard.
Supported Environments Matrix