Help secure the Cloud Workstations API using Chrome Enterprise Premium

Overview

Chrome Enterprise Premium is Google Cloud's zero trust solution that enables an organization's workforce to access web applications securely from anywhere, without the need for VPN, and to help prevent malware, phishing, and data loss.

With the power of Google Chrome, Chrome Enterprise Premium enables users to access applications from any device. Chrome Enterprise Premium is expanding its capabilities to address some key security challenges in the developer environment. Using context-aware access control for Google Cloud console and APIs, Chrome Enterprise Premium enables additional security for the Cloud Workstations API.

The following table lists whether Chrome Enterprise Premium supports context-aware access control for the specified Cloud Workstations access method.

  • The check mark indicates Chrome Enterprise Premium limits this Cloud Workstations access method.
  • The not supported icon indicates Chrome Enterprise Premium does not limit this Cloud Workstations access method.

Objectives

This document describes the steps that an administrator follows to set up Chrome Enterprise Premium access control for the Cloud Workstations API and to provide additional mechanisms that help prevent source code exfiltration from browser-based Cloud Workstations IDEs.

Costs

As part of this tutorial, you may need to get other teams involved (for billing or IAM) and you also test access-control to demonstrate that Chrome Enterprise Premium guardrails are in place.

In this document, you use the following billable components of Google Cloud:

To generate a cost estimate based on your projected usage, use the pricing calculator.

New Google Cloud users might be eligible for a free trial.

When you finish the tasks that are described in this document, you can avoid continued billing by deleting the resources that you created. For more information, see Clean up.

Before you begin

  1. Sign in to your Google Cloud account. If you're new to Google Cloud, create an account to evaluate how our products perform in real-world scenarios. New customers also get $300 in free credits to run, test, and deploy workloads.
  2. In the Google Cloud console, on the project selector page, select or create a Google Cloud project.

    Roles required to select or create a project

    • Select a project: Selecting a project doesn't require a specific IAM role—you can select any project that you've been granted a role on.
    • Create a project: To create a project, you need the Project Creator role (roles/resourcemanager.projectCreator), which contains the resourcemanager.projects.create permission. Learn how to grant roles.

    Go to project selector

  3. Verify that billing is enabled for your Google Cloud project.

  4. Enable the Workstations API.

    Roles required to enable APIs

    To enable APIs, you need the serviceusage.services.enable permission. If you created the project, then you likely already have this permission through the Owner role (roles/owner). Otherwise, you can get this permission through the Service Usage Admin role (roles/serviceusage.serviceUsageAdmin). Learn how to grant roles.

    Enable the API

  5. Make sure that you have the following role or roles on the project: Cloud Workstations > Cloud Workstations Admin.

    Check for the roles

    1. In the Google Cloud console, go to the IAM page.

      Go to IAM
    2. Select the project.
    3. In the Principal column, find all rows that identify you or a group that you're included in. To learn which groups you're included in, contact your administrator.

    4. For all rows that specify or include you, check the Role column to see whether the list of roles includes the required roles.

    Grant the roles

    1. In the Google Cloud console, go to the IAM page.

      Go to IAM
    2. Select the project.
    3. Click Grant access.
    4. In the New principals field, enter your user identifier. This is typically the email address for a Google Account.

    5. Click Select a role, then search for the role.
    6. To grant additional roles, click Add another role and add each additional role.
    7. Click Save.
  6. In the Google Cloud console, on the project selector page, select or create a Google Cloud project.

    Roles required to select or create a project

    • Select a project: Selecting a project doesn't require a specific IAM role—you can select any project that you've been granted a role on.
    • Create a project: To create a project, you need the Project Creator role (roles/resourcemanager.projectCreator), which contains the resourcemanager.projects.create permission. Learn how to grant roles.

    Go to project selector

  7. Verify that billing is enabled for your Google Cloud project.

  8. Enable the Workstations API.

    Roles required to enable APIs

    To enable APIs, you need the serviceusage.services.enable permission. If you created the project, then you likely already have this permission through the Owner role (roles/owner). Otherwise, you can get this permission through the Service Usage Admin role (roles/serviceusage.serviceUsageAdmin). Learn how to grant roles.

    Enable the API

  9. Make sure that you have the following role or roles on the project: Cloud Workstations > Cloud Workstations Admin.

    Check for the roles

    1. In the Google Cloud console, go to the IAM page.

      Go to IAM
    2. Select the project.
    3. In the Principal column, find all rows that identify you or a group that you're included in. To learn which groups you're included in, contact your administrator.

    4. For all rows that specify or include you, check the Role column to see whether the list of roles includes the required roles.

    Grant the roles

    1. In the Google Cloud console, go to the IAM page.

      Go to IAM
    2. Select the project.
    3. Click Grant access.
    4. In the New principals field, enter your user identifier. This is typically the email address for a Google Account.

    5. Click Select a role, then search for the role.
    6. To grant additional roles, click Add another role and add each additional role.
    7. Click Save.
  10. Make sure that you have assigned a Chrome Enterprise Premium Standard license to each of your users. Only users with a license have access controls enforced. For more information, see Assign, remove, and reassign licenses.

Part 1: Set up Chrome Enterprise Premium for Cloud Workstations

This section takes you through the steps to help you secure context-aware access to the Cloud Workstations API:

  1. Set up Cloud Workstations.
  2. Create a demo user and a demo group.
  3. Create an access level in Access Context Manager.
  4. Enable Chrome Enterprise Premium CAA.
  5. Add required Google groups with access levels.
  6. Test developer access to Cloud Workstations.

Set up Cloud Workstations

To integrate with Chrome Enterprise Premium, your Cloud Workstations cluster must use Identity-Aware Proxy (IAP). Skip this section if you have these resources already configured.

To set up Cloud Workstations:

  1. Create a workstation cluster with a custom domain.
  2. Enable IAP.
  3. Create a workstation configuration in the cluster.

If you're new to Cloud Workstations, see the Overview and Architecture.

Create a demo user and a demo group

From the Google Workspace Admin console, create a demo user and a new user group. When enabled, context-aware access (CAA) for Google Cloud console applies to all users and Google groups because it is a global setting.

  1. Sign in to the Google Workspace Admin console with your administrator account: Menu > Directory > Users > Add New User.

  2. Create a demo user: demo-user@<domain>.

  3. Sign in to the Google Cloud console and navigate to Menu > IAM & Admin > Groups.

  4. Create an IAM group for Cloud Workstations access, name it Cloud Workstations Users, and assign the previously created demo user, demo-user@<domain>.

  5. Click Save.

  6. Also create an IAM administrator group, and name it Cloud Admin Users. Assign your project and organization administrators to this group.

  7. Add the demo user, demo-user@<domain>, to the Cloud Workstations user group that you created:

    1. In the Google Cloud console, go to Cloud Workstations > Workstations.
    2. Select the workstation and then click more_vertMore > Add Users.
    3. Select the demo user, demo-user@<domain> and select Cloud Workstations User as the Role.
    4. To give the demo user access to the workstation, select demo-user@<domain>, select Cloud Workstations Users as the Role, and click Save.

Create an access level

Go back to the Google Cloud console to create an access level in Access Context Manager.

Follow these instructions to test access:

  1. From the Google Cloud console, navigate to Security > Access Context Manager to configure a corporate-managed device policy.

  2. Click Create access level and fill in the following fields:

    1. In the Access level title field, enter corpManagedDevice.
    2. Select Basic mode.
    3. Under Conditions select True to enable the condition.
    4. Click + Device policy to expand the options and check Require corp owned device.
    5. Click Save to save the access policy.

Enable Chrome Enterprise Premium CAA for Google Cloud console

To assign context-aware access controls (CAA) to workstations, start by enabling CAA for Google Cloud console:

  1. From the Google Cloud console, navigate to Security > BeyondCorp Enterprise.

  2. Click Manage access to Google Cloud console and API. This takes you to the Chrome Enterprise Premium Organization level page.

  3. In the Secure Google Cloud console & APIs section, click Enable.

Add required Google groups with access levels

Add required administrator groups with relevant members and the correct access policy.

Console

  1. Create an administrator access policy named CloudAdminAccess with the location set to regions where your administrators work. This makes sure that administrators can access resources even when another policy blocks them.

  2. Create an IAM group with administrator access at IAM & Admin > Groups.

    1. Select the organization.
    2. Create a group, name it Cloud Admin Users.
    3. Assign yourself and any other administrators to this group.
    4. Click Save.
  3. Go to Security > Chrome Enterprise Premium. Click Manage access and review the list of groups and access levels that appear.