Techtide gcp live iam policy change guard
Skill TechTideOhio/techtide-harness-kit/skills/gcp/techtide-gcp-live-iam-policy-change-guard
Gate IAM binding mutations, org policy changes, and Service Account key creation against the GCP resource hierarchy. IAM bindings at org level propagate to all folders and projects - this guard enforces blast-radius assessment, audit-trail confirmation, and explicit authority approval before any policy mutation is executed.From its SKILL.md
npx -y skills add TechTideOhio/techtide-harness-kit --skill techtide-gcp-live-iam-policy-change-guardAssembled from the repository path, not quoted from the project. Check it against their README if it does not work.
One thing to look at
- 0 stars0 stars. Stars are a popularity signal and not a quality one, but at this level it is likely that nobody has read this closely except its author, and you would be relying on your own review.
SKILL.md
6.2 KB, ~1.3k tokens by cl100k_base, as published. Nobody here has run it
GCP Live IAM Policy Change Guard
Purpose
Act as the guarded live GCP operator for techtide-gcp-live-iam-policy-change-guard work. Gate every IAM binding mutation, org policy change, and Service Account key creation with explicit blast-radius assessment and authority approval. Treat org-level changes as the highest-risk category - they propagate to every resource in the hierarchy.
When to Use
Use this skill when:
- An IAM binding must be added, modified, or removed at org, folder, or project level
- An Organization Policy constraint is being enabled, disabled, or overridden
- A new Service Account key is being requested or created
- A custom role is being created or modified
- An operator needs to audit the current IAM policy for a resource before making changes
- Detecting and remediating over-privileged bindings or stale service account keys
When NOT to Use
Do not use this skill when:
- The task is a read-only IAM audit with no mutation intent (use
roles/iam.securityRevieweralone) - The task involves Kubernetes RBAC within GKE only (no GCP IAM changes)
- The task is creating a new GCP project with default IAM (no pre-existing bindings at risk)
- The task is unrelated to GCP identity and access management
Pre-Flight Checklist
Before executing any IAM mutation, verify all of the following:
- Resource hierarchy level confirmed - explicitly state whether the target is organization, folder, or project level. Run
gcloud organizations list,gcloud resource-manager folders list, orgcloud projects describe <PROJECT>as appropriate. - Active principal confirmed - run
gcloud auth listandgcloud config get-value accountto confirm the identity executing the change. - Current IAM policy captured - run
gcloud [projects|resource-manager folders|organizations] get-iam-policy <TARGET>and document the current bindings before any change. - Blast-radius assessed - for org-level changes, enumerate all child folders and projects that will inherit the binding.
- Change justification documented - the operator must state the business reason, the specific principal(s) affected, and the role being added or removed.
- Service Account key inventory - if a key is being created, run
gcloud iam service-accounts keys list --iam-account <SA>and confirm no unexpired keys already exist for this purpose. - Rollback plan documented - identify which existing binding will be restored if the change must be reverted. For removals, confirm the operator has a path to restore access if needed.
Required Confirmation
The operator must explicitly state all of the following before any mutation is executed:
- "I confirm the target resource is
<ORG_ID / FOLDER_ID / PROJECT_ID>at the<org/folder/project>level." - "I confirm the principal is
<PRINCIPAL_EMAIL>and the role change is<ADD/REMOVE> <ROLE>." - "I understand that org-level bindings propagate to all child resources and I have authority to make this change."
- "I approve this IAM change."
- For Service Account key creation: "I acknowledge this creates a long-lived credential and confirm Workload Identity is not available for this use case."
Execution Steps
- Capture pre-change IAM policy snapshot.
- Confirm active principal has
roles/resourcemanager.organizationAdmin(for org changes) orroles/resourcemanager.projectIamAdmin(for project changes). - Present the planned change, blast-radius assessment, and key inventory to the operator for explicit approval.
- Execute the mutation:
- Add binding:
gcloud [projects|resource-manager folders|organizations] add-iam-policy-binding <TARGET> --member=<MEMBER> --role=<ROLE> - Remove binding:
gcloud [projects|resource-manager folders|organizations] remove-iam-policy-binding <TARGET> --member=<MEMBER> --role=<ROLE> - Create SA key:
gcloud iam service-accounts keys create <KEY_FILE> --iam-account=<SA> - Set org policy:
gcloud resource-manager org-policies set-policy <POLICY_FILE> --organization=<ORG_ID>
- Add binding:
- Capture post-change policy snapshot and diff against pre-change snapshot.
Rollback Procedure
- Binding addition (reversible): Remove the binding with
remove-iam-policy-binding. Take effect is immediate. - Binding removal (reversible but risky): Re-add the binding with
add-iam-policy-binding. If the removal caused a lockout, use a break-glass identity to restore. - Service Account key creation (NOT reversible on creation - revoke is the mitigation): Disable and delete the key immediately with
gcloud iam service-accounts keys disableandgcloud iam service-accounts keys delete. - Org policy change (reversible): Delete the policy override to restore inherited behavior:
gcloud resource-manager org-policies delete <CONSTRAINT> --organization=<ORG_ID>.
Post-Change Verification
- Run
gcloud [projects|resource-manager folders|organizations] get-iam-policy <TARGET>- confirm the policy reflects the intended change and no unintended bindings were added. - Test access for the affected principal using
gcloud auth application-default loginorgcloud projects test-iam-permissionsto verify the change has the expected effect. - Check Cloud Audit Logs for the change:
gcloud logging read 'resource.type="project" AND protoPayload.methodName="SetIamPolicy"' --limit=10 --project=<PROJECT>. - For org policy changes, confirm constraint enforcement is active using
gcloud resource-manager org-policies describe <CONSTRAINT> --organization=<ORG_ID>.
Response Shape
- Resource hierarchy level and target confirmed
- Current IAM policy inventory
- Proposed binding change and blast-radius assessment
- Service Account key inventory if applicable
- Approval status
- Applied IAM change
- Post-change access verification
What ships with it: 3 files
6.7 KB alongside SKILL.md
references/
- official-sources.md1.8 KB
- workflow-and-output.md3.8 KB
- metadata.json1.1 KB