1.0 Introduction
This article describes how to configure or onboard the GCP connection to Fortanix Key Insight to scan your cryptographic elements (keys and services).
2.0 Terminology Reference
For GCP connection concepts and supported features, refer to GCP Connection Concepts.
3.0 Start the Connection Setup
Before configuring a GCP connection, ensure you can access Fortanix Key Insight.
For information about signing up for Fortanix Armor, creating an Armor account, and accessing Fortanix Key Insight, refer to Getting Started with Key Insight.
You can start the connection setup when you first access Fortanix Key Insight or after you have entered the application.
First-time users: When you access Fortanix Key Insight for the first time, the connection setup wizard is displayed automatically. Proceed to Section 5: Select Cloud Provider to select GCP and configure the connection.
Existing users: In Fortanix Key Insight, go to Configuration → Connections → CLOUD → ADD CLOUD CONNECTION. Proceed to Section 5: Select Cloud Provider to select GCP and configure the connection.
4.0 Prerequisites
The following are the prerequisites before configuring a GCP connection on Fortanix Key Insight:
4.1 Set Up a GCP Role in the GCP Organization
Before onboarding a GCP connection, perform the steps described in GCP Connection Scanning Configuration to set up the required GCP role in your GCP organization.
4.2 IP Whitelisting Requirements in GCP
To enable secure and reliable communication between Fortanix Key Insight and your GCP cloud environment, certain network connections may need to be allowed.
If IP whitelisting is required, retrieve the current Fortanix IP ranges from the Fortanix SaaS IP Ranges endpoint and allow the applicable IP ranges in your firewall or network infrastructure.
For information about Fortanix SaaS IP ranges and how to determine the applicable IP addresses based on traffic direction, region, and service, refer to Fortanix SaaS IP Whitelisting.
IP whitelisting is not mandatory. It is required only if there are network restrictions on your GCP projects for inbound traffic.
5.0 Select Cloud Provider
Perform the following steps to select the scan type, connection type, and GCP cloud provider:
On the Select Cloud Provider step, select Automated Scan as the scan type.
Under Select connection type, select Cloud Connections. Under Select cloud provider, select Google Cloud Platform.
Click NEXT.

Figure 1: Select the GCP cloud provider
6.0 Set Up Authentication
GCP supports secret-based and federated authentication methods to control how users and applications obtain credentials to access GCP services.
6.1 Configure Secret-Based Authentication
This method uses a Google Cloud service account to authenticate Fortanix Key Insight with your GCP environment securely. You must provide the service account email and a private key to access GCP resources for scanning securely.
Perform the following steps to add a secret-based GCP authentication:
On the Set Up Authentication step, the Secret based authentication option is selected by default.
Service Account Email: Enter your service account email address.
Private Key: Enter the private key associated with the service account.
For more information on how to fetch these credentials, refer to GCP Connection Scanning Configuration.
Click NEXT.

Figure 2: Configure authentication in GCP
6.2 Configure Federated Authentication - Client Credentials Flow
An authentication method where users or workloads access GCP resources using existing credentials from an external identity provider (IdP), such as Ping Identity and PingFederate. This eliminates the need to store long-lived service account keys by using Workload Identity Federation and short-lived credentials.
GCP commonly uses the following OAuth flows in federated authentication scenarios:
Client credentials flow: Used for machine-to-machine communication. The application authenticates directly with the IdP using its client ID and secret to obtain tokens, with no user interaction required.
Fortanix Key Insight supports configuring GCP connections using the Client credentials flow with Kong as the API Gateway and Ping Identity and PingFederate as supported IdPs.
For information on configuring the IdP and obtaining the required credentials, refer to the following:
Set Up Kong API Gateway for GCP (API Gateway URL)
GCP Configuration Using Ping Identity as an OpenID Connect Identity Provider (Client ID, Client Secret, Well-known URL, and GCP Audience)
GCP Configuration Using PingFederate as an OpenID Connect Identity Provider (Client ID, Client Secret, Well-known URL, and GCP Audience)
Perform the following steps to add an IdP configuration using the Client credentials flow:
On the Set Up Authentication step, select Federated authentication.
Service account email: Enter the service account email address.For more information on how to obtain this value, refer to GCP Connection Scanning Configuration.
GCP Audience: Enter the GCP Audience value. This value must match the Default Audience configured in your GCP environment.
In the Select Configuration section, click ADD CONFIGURATION to add a new IdP configuration.
In the Add New Authentication Configuration dialog box:
Client credentials flow: Select this option to authenticate to GCP services using client credentials.
Name: Enter a name for the configuration.
Client ID: Enter the Client ID of your IdP.
Client Secret: Enter the Client Secret of your IdP.
Well-known URL: Enter the Well-known URL of your IdP.
Scope(optional): Add custom scopes if required.
Add API Gateway URL (Required for GCP connections) (optional):Select this check box to enter the API gateway URL. This is the public URL of the API Gateway (for example, Kong Gateway) deployed in your environment. You can obtain this value from your API Gateway deployment or from the administrator managing the gateway.
Example:
https://ki-kong.westus2.cloudapp.azure.com:8443/pingClick AUTHORIZE to complete the authorization.

Figure 3: Add a configuration using Client Credentials flow
After adding and selecting the IdP configuration, click NEXT.
NOTE
When adding or editing the configuration, an Authorization Failed error message may appear if authorization cannot be completed due to incorrect credentials, invalid scope, or other configuration issues.
You can also add an IdP using the Client credentials flow by clicking ADD CONFIGURATION in the top-right corner of the Authentication page. For more information on managing the Federated Authentication IdP configurations, refer to Federated Authentication Identity Provider Configurations.
Currently, GCP does not support configuring Federated authentication using the Authorization code flow.
7.0 Set Up Cloud Connections
Perform the following steps on the Set Up Cloud Connections step:
Enter a GCP connection name. For example, GCP connection.
On the Select scope section:
Organization: Select this option if you want to onboard all GCP projects.
Organization ID: Enter your Organization ID.For more information on how to obtain the Organization ID, refer to GCP Connection Scanning Configuration.

Figure 4: Set up GCP connection
Project: Select this option if you want to onboard a single GCP project.
Click NEXT.
8.0 Select GCP Projects
Perform the following steps to select your GCP project(s):
On the Select GCP Project step:
If you selected Organization scope in the previous step, choose Select All Projects in Your Organization to onboard all projects in the organization, or manually select the projects you want to onboard.
If you selected Project scope, enter the Project ID. For more information on how to fetch the Project ID, refer to GCP Connection Scanning Configuration.
Click NEXT.
NOTE
Fortanix Key Insight scans only the GCP metadata and does not access any GCP key material.

Figure 5: Select GCP projects
9.0 Select Key Insight Policy
The System Defined Policy is selected by default on the Key Insight Policy step. This policy is designed to facilitate the scanning of keys and services based on predefined key sizes and permitted operations, ensuring compliance with standard security configurations.
Click NEXT to proceed.

Figure 6: GCP Key Insight policy
Additionally,
Click ADD POLICY to add a new user-defined policy to the policy center.
Click
to copy and modify a system-defined policy, converting it into a user-defined policy.
For more information on Fortanix Key Insight policies and features, refer to Cryptographic Policy Management.
NOTE
If you change or update the policy instead of theSystem Defined Policy, you mustRescanthe GCP connection to apply the new policy.
10.0 Select External Key Source
On the Select External Key Source step, you can integrate Fortanix Key Insight with an external key source such as Fortanix DSM to enable key correlation and improve key management.
Select any of the following options:
Yes, connect now: This option allows you to add the external key source for your GCP cloud connection to correlate keys using the ADD EXTERNAL KEY SOURCE feature. For more information, refer to Getting Started with External Key Source Connection. After adding the Fortanix DSM connection, select it from the list.

Figure 7: Add external key source
No, I’ll connect later: This option allows you to onboard the GCP connection without adding an external key source. You can add it later if needed.

Figure 8: Onboard GCP connection without an external key source
Click FINISH to complete the GCP connection onboarding.
NOTE
After onboarding the GCP connection:
View the GCP connection UI (Overview, Assessment, Keys, and so on). You can also switch the region at any time using the region switcher drop down located on the top navigation bar. When the region is changed, the UI updates automatically to show the data, connections, and scan results for that region.
For more information about the GCP connection UI, refer to GCP Connection - User Interface Components.
Users with theAccount AdministratorandGroup Administratorroles can manage (edit, delete, rescan) the connection from theConfiguration → Connections → CLOUD.
Deleting the GCP connection cannot be undone.
A group with the same name will be created on the Fortanix IAM Groups page. For more information, refer to Fortanix Armor Identity and Access Management (IAM).
11.0 Troubleshooting
For information about common issues and troubleshooting steps when configuring Fortanix Key Insight in cloud environments, refer to Cloud Connection Troubleshooting.