Skip to main content
GCP is a cloud-platform data source. Switch Trust reads your Google Cloud project and discovers the AI resources deployed in it. Switch Trust reads the project through Workload Identity Federation, which issues short-lived credentials, so there is no service account key file to create or store. You set up the federation by applying a Terraform template that Switch Trust provides, then give Switch Trust the values the template outputs. To open this page, go to Settings, then Data sources, select GCP, and open the Setup tab.
Connecting or editing the GCP data source requires an administrator. With a lower role you can still open the source and read its Scans tab.

Connect your project

1

Download the Terraform template

On the GCP source, download the Terraform template. It configures a Workload Identity pool and provider and a read-only service account.
2

Open Google Cloud Shell

Open the Google Cloud Shell console at shell.cloud.google.com, signed in to the project you want to connect.
3

Create a working folder

Create a folder for the Terraform and move into it:
4

Add the template

Open a new file and paste in the Terraform template you downloaded, then save it:
5

Initialize Terraform

Download the provider plugins the template needs:
6

Create the resources

Preview the plan to confirm it only creates new resources, then apply it:
Each command prompts for var.project_id. Enter the ID of the GCP project you want to connect. When terraform apply asks you to confirm the plan, enter yes. Once it finishes, its output holds every value you need to configure the project in Switch Trust.
7

Enter the project details

On the Setup tab, copy the values from the Terraform output into the matching fields:
  • Project ID and Project number
  • Service account email
  • WIF pool ID and WIF provider ID
The WIF fields come pre-filled from the template defaults. Change them only if you customized the template.
8

Test the connection and add the project

Select Test connection. Switch Trust exchanges a token through the federation and reports whether it succeeded. If it fails, check the project details and that the Terraform applied cleanly, then try again. Then select Add project to save it.
You can connect more than one project.

What Switch Trust scans

Once connected, Switch Trust scans each Vertex AI location in the project and discovers your Vertex AI models and agents.

The Scans tab

Open the Scans tab to see the connected project, with an overall status and the date of its latest activity. While Switch Trust is scanning, the project shows Scanning. Expand the project row to see its scans, which cover Vertex AI models and agents in each location. Each scan lists its Scan name, Status, and Started and Ended times: The tab refreshes on its own while a scan is running, so you can watch a scan move from In progress to Completed without reloading.

Next steps

Read your discovery results

Work out what needs attention first, whether a finding is real, and when it’s resolved

Connect another data source

Add a repository or another cloud platform to widen your inventory