Skip to main content

Get Cloud Account Status (GCP)

POST 

/cas/v1/cloud_account/status/gcp

Lists the status of a GCP Cloud account. You can use this API to verify the status of the security capabilities which you will be onboarding on Prisma Cloud.

Request

Body

    cloudAccount objectrequired
    accountId stringrequired

    Organization resource ID if accountType is organization.

    Project ID if accountType is account or masterServiceAccount.

    Workspace domain name if accountType is workspace_domain.

    accountType stringrequired

    Possible values: [account, masterServiceAccount, organization, workspace_domain]

    Cloud Account Type.

    account: GCP Project

    organization: GCP Organization

    masterServiceAccount: Onboards all GCP projects that are accessible by the service account

    workspace_domain: GCP Workspace.

    enabled boolean

    Enable or disable this account on Prisma Cloud.

    Default value: false

    name stringrequired

    Account name for the GCP account that will be onboarded on Prisma Cloud. (must be unique)

    projectId string

    ID of the project.

    Get the project ID from the credentials json file that is generated from the GCP Terraform template.

    groupIds string[]

    List of Account Groups that must be mapped to this account. To get the account group ids,call List Account Groups API

    credentials objectrequired

    The content of the credentials object is the Service Account Key for your Google Cloud service account

    token_uri string
    private_key_id string
    client_x509_cert_url string
    project_id string
    auth_uri string
    auth_provider_x509_cert_url string
    client_email string
    private_key string
    type string
    client_id string
    compressionEnabled boolean

    Enable or disable compressed network flow log generation.

    Default value: false

    dataflowEnabledProject string

    Project ID where the Dataflow API is enabled .

    Required if compressionEnabled is set to true and if the accountType is organization.

    Optional if the accountType is account or masterServiceAccount

    flowLogStorageBucket string

    Cloud Storage Bucket name that is used store the flow logs.

    accountGroupCreationMode string

    Possible values: [MANUAL, AUTO, RECURSIVE]

    Default value: MANUAL

    MANUAL: Account will be mapped to the account group mentioned in defaultAccountGroupId.

    AUTO: Automatically creates account groups for each top-level folder in the hierarchy.

    RECURSIVE: Automatically creates account groups for the folders that are nested within the GCP organization hierarchy.

    Applicable only if the accountType is organization.

    defaultAccountGroupId stringrequired

    Applicable only

    • If accountType is organization and accountGroupCreationMode is MANUAL.

    • If accountType is masterServiceAccount.

    hierarchySelection object[]

    Applicable only if accountType is organization.

    Include/Exclude a list of GCP folders, GCP projects under the organization.

  • Array [
  • resourceId string

    To get the list of resource IDs and its details, Refer List Children of Parent (GCP)

    displayName string

    To get the display name of resource, Refer List Children of Parent (GCP). Display name is the organization name if nodeType is ORG

    nodeType string

    Member account node type. Supported values are ORG, FOLDER, or PROJECT

    selectionType string

    Possible values: [ALL, INCLUDE, EXCLUDE]

    Organization Member accounts Selection type.

    ALL: Include the resource and all its children

    INCLUDE: Include the specified resource

    EXCLUDE: Exclude the specified resource

  • ]
  • organizationName string

    GCP Organization name

    features object[]

    Features to be enabled and/ or disabled. To get a list of all the supported features, see Fetch Supported Features endpoint

  • Array [
  • name string

    Feature name obtained from Fetch Supported Features endpoint

    state string

    Possible values: [enabled, disabled]

    Feature state. Whether to be enabled or disabled

    defaultMemberState string

    Possible values: [enabled, disabled]

    Enable or disable the feature for all the member accounts linked to this organization. You can enable or disable the defaultMemberState only if the feature state is enabled for the organization. Applicable only for Serverless Function Scanning and Agentless Workload Scanning features.

  • ]

Responses

successful operation

Schema
  • Array [
  • id string
    name string
    status string
    statusMessage object
    message string
    staticMessage boolean
  • ]
Loading...