Skip to content

docs(connectors): document the Google Cloud asset connector - #16113

Open
svader0 wants to merge 5 commits into
DefectDojo:devfrom
svader0:sc-14524-gcloud-docs
Open

svader0 wants to merge 5 commits into
DefectDojo:devfrom
svader0:sc-14524-gcloud-docs

Conversation

@svader0

@svader0 svader0 commented Sep 28, 2026 •

Copy link
Copy Markdown
Collaborator

Documents the Google Cloud asset connector (sc-14524): what it imports, the service-account role it needs, the optional Parent Resource field, how it behaves alongside the Google Cloud SCC connector, and the two limits it ships with. Five languages, an index link in the upstream tool reference, and a bullet in the supported-tools list.

Runtime connector: DefectDojo-Inc/connectors#991.

Add the tool-reference page for the new Google Cloud asset connector
(English plus de/es/fr/ja translations), and list it in the upstream
connector index and the asset-connector call-outs so it shows up next
to Google Cloud SCC.
- The ACTIVE filter applies to folders and projects both; reword the
  sentence so it does not read as projects-only.
- State the SCC handoff correctly: when the google-scc connector
  creates the Asset first, that Asset keeps its existing Organization,
  and this connector only adds the folder relationship above it.
- Document that a mapped Record's metadata never refreshes, so a
  folder rename or a project move in Google Cloud does not reach
  DefectDojo after the first sync.

Same three corrections applied to the de/es/fr/ja translations.
…label needs

roles/browser carries resourcemanager.folders.get and
resourcemanager.organizations.get, but the page told readers a custom role
with only the two list permissions works too. It does for the walk, and the
top-level Asset then falls back to its resource id as its name because the
connector cannot read the root's display name.
google-scc files a finding it cannot attribute to a project under a record
for its configured parent, named after that resource. That is a different
Asset from the organization or folder Asset the Google Cloud connector
creates, so a customer running both sees one extra Asset for those findings.
Keeping the display-name label on our root record was chosen over matching
the bare resource name; this paragraph sets the expectation instead.
The Parent Resource field is now optional. Blank means every project the
service account can read, as a flat list. With no organization there is no
parent to grant the Browser role at, so it goes on each project instead.
@svader0 svader0 added this to the 3.4.0 milestone Sep 28, 2026
@github-actions github-actions Bot added the docs label Sep 28, 2026

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant