Control: GCP > Project > Organization Policy > Restrict Shared VPC Subnetworks
Manage the GCP Organization Policy "Restrict Shared VPC Subnetworks" for the project.
This list constraint defines the set of shared VPC subnetworks that eligible resources can use. This constraint does not apply to resources within the same project. By default, eligible resources can use any shared VPC subnetwork.
The allowed/denied list of subnetworks must be specified in the form: under:organizations/ORGANIZATION_ID, under:folders/FOLDER_ID, under:projects/PROJECT_ID, or projects/PROJECT_ID/regions/REGION/subnetworks/SUBNETWORK-NAME.
Resource Types
This control targets the following resource types:
Primary Policies
The following policies can be used to configure this control:
- Restrict Shared VPC Subnetworks
- Restrict Shared VPC Subnetworks > Action
- Restrict Shared VPC Subnetworks > Custom Values
Category
In Your Workspace
Developers
- tmod:@turbot/gcp-orgpolicy#/control/types/computeRestrictSharedVpcSubnetworks
- tmod:@turbot/turbot#/control/categories/policy
- turbot graphql controls --filter "controlTypeId:tmod:@turbot/gcp-orgpolicy#/control/types/computeRestrictSharedVpcSubnetworks"
Get Controls
Control Type URI
Category URI
GraphQL
CLI