All integrations

Google Cloud Integration with DefectDojo

Google Cloud Integration with DefectDojo

Google Cloud is Google's public cloud platform. Its resource hierarchy starts at an organization, which contains folders (which can nest) and projects, and every resource lives inside a project. The Cloud Resource Manager API exposes that hierarchy, including names, IDs, lifecycle state, and labels. The DefectDojo Pro connector for Google Cloud is an asset connector: it reads the hierarchy and creates a matching tree of Assets in DefectDojo, and it imports no findings.

Google Cloud Integration with DefectDojo

We connected Google Cloud to DefectDojo so our project list would stop being something we copied by hand. The connector walks our organization and creates an Asset for every project, grouped into Organizations by the folder each project sits in, with the folders themselves as Assets too. When we run the Google Cloud SCC connector alongside it, Security Command Center findings land on the same project Assets, inside the same folder structure we see in the Cloud console.

Why Google Cloud Matters

In Google Cloud, projects are where workloads, billing, and permissions meet, and folders usually mirror teams, business units, or environments.

  • Projects are the natural Asset for cloud findings, because almost every resource and every finding belongs to exactly one project.
  • Folders capture ownership boundaries that security leads want to report against.
  • Projects are created and deleted constantly. A hand-maintained Asset list goes stale quickly, and findings land on Assets nobody recognizes.
  • The hierarchy already exists and is authoritative. Rebuilding it in a security tool is wasted effort.

Advantages of This Integration

What the Google Cloud asset connector adds to DefectDojo Pro:

  • An Asset per project. Every ACTIVE project beneath the parent you configure becomes a Record, named after its project ID.
  • Folders as Organizations and Assets. Each project's Organization is the folder it sits in (or the Google Cloud organization for projects directly under it), and each folder becomes an Asset as well.
  • No duplicates with SCC. Both this connector and the Google Cloud SCC connector identify a project the same way and name its Asset after the project ID, so running both does not duplicate anything.
  • Order doesn't matter. If this connector runs first, SCC findings land on the Assets it created. If SCC ran first, this connector adopts those Assets and adds the folder hierarchy around them.
  • Deletions handled safely. A deleted project moves to DELETE_REQUESTED, drops out of the import, and its Record is flagged MISSING on the next Sync. DefectDojo never silently deletes an Asset.
  • Read-only metadata access. The connector reads folder and project names, IDs, lifecycle state, and labels. It reads no resource contents and no findings.

How This Integration Works

The connector is a DefectDojo Pro feature, configured under Connect > Upstream, and authenticates with a Google service account.

1. Create a service account. A dedicated service account for DefectDojo is recommended.

2. Grant the Browser role. Grant roles/browser at the organization or folder you want to import. The hierarchy walk needs resourcemanager.folders.list and resourcemanager.projects.list. A custom role must also include resourcemanager.folders.get and resourcemanager.organizations.get, or the top-level Asset is named after its resource ID instead of its display name. Grant the role at the top of the scope you configure: the connector walks the whole subtree, and a folder it cannot read fails the sync rather than silently importing a partial inventory. If your account has no organization, grant roles/browser on each project you want to import.

3. Create a key and enable the API. Create a JSON key for the service account and download it. Enable the Cloud Resource Manager API (cloudresourcemanager.googleapis.com) on the project that owns the service account.

4. Configure the connector. Leave the Location at https://cloudresourcemanager.googleapis.com unless you use a non-standard endpoint. In Parent Resource, enter the root of the hierarchy to import as organizations/ or folders/ followed by the ID. A single project is not accepted here; use the Google Cloud SCC connector for a single-project scope. If your account has no organization, leave the field blank and the connector imports every project the service account can read as a flat list. Paste the full contents of the JSON key into the Service Account Key field.

5. Discover and Sync. Every ACTIVE folder and project beneath the parent becomes a Record. With Auto-Map, Assets and Organizations are created to match.

Data Granularity: What Gets Mapped

This connector maps inventory only. Here is what it creates, per the connector documentation.

DefectDojo Object Source in Google Cloud Notes
Asset (project) Project Record named after the project ID
Organization Folder containing the project Or the Google Cloud organization for projects directly beneath it
Asset (folder) Folder Folders appear as Assets so the tree matches the console
Asset hierarchy Organization, folders, projects Same tree as the Cloud console
Record state Lifecycle state Only ACTIVE is imported; DELETE_REQUESTED leads to MISSING
Metadata read Names, IDs, lifecycle state, labels No resource contents
Findings None Use the Google Cloud SCC connector for findings

When the Google Cloud SCC connector creates a project Asset first, that Asset keeps its existing Organization, and this connector only adds the folder hierarchy around it.

Use Cases

Pairing with Security Command Center: A team enables this connector and the Google Cloud SCC connector together. Project Assets are created once, folder structure is added around them, and SCC findings land on the right project without anyone mapping Records twice.

Reporting by folder: An organization with folders for each business unit gets matching Organizations in DefectDojo, so open findings and SLA performance can be compared by business unit from the first sync.

Catching project churn: New projects appear as Records on the next Discover, which gives the security team a simple list of new projects to confirm are covered by scanning. Deleted projects turn MISSING instead of disappearing with their history.

Accounts without an organization: Smaller setups with no Google Cloud organization can still import every project the service account can read, as a flat list.

Operational Tips

  • Grant the Browser role at the top of the scope you configure. A folder the service account cannot read fails the whole sync, by design.
  • If you use a custom role, include the folders.get and organizations.get permissions so the top-level Asset gets its display name rather than a numeric ID.
  • Once a Record is mapped, this connector never refreshes its metadata. Renaming a folder or moving a project in Google Cloud leaves the old name or folder in DefectDojo, so check affected Assets by hand after a reorganization.
  • Expect one extra Asset if you run SCC as well. SCC findings that belong to no project, such as organization-level policy findings, land on a separate Asset the SCC connector creates for its configured parent.
  • Treat MISSING Records as a review queue for projects that were deleted or lost access.
  • Turn on the Connector Health Warning notification so a revoked key or permission change reaches you as a message.