Skip to content
About

Cost, identity, and tool prerequisites

A historical checkout supplies configuration, not permission to operate the original environment. Reproduction needs an account and project you own, an explicit budget, and a repository whose release authority you control. Do not use the example project ID, historical state bucket, or an upstream credential merely because it appears in source.

Before a plan, record your target GCP project, accepted region, unique state bucket name and location, governance labels (owner, project_label, cost_center), allowed control-plane client networks, and intended repository identity. The historical region is europe-west1; this is a source fact rather than a recommendation for another operator. Billing, quotas, organizational restrictions, and regional availability must be checked in the owned account before provisioning.

The production root defaults to a regional GKE cluster with private nodes, but its GKE module defaults enable_private_endpoint to false, and the root does not override it. Private nodes therefore do not establish a private Kubernetes API endpoint. Review authorized networks and endpoint design instead of relying on the label “private cluster.” See the infrastructure map.

Use an operator identity for planning infrastructure; a dedicated GitHub Actions service account for registry writes; and a dedicated Kyverno verifier account for registry reads. The CI and verifier identities are not interchangeable. The CI cloud identity obtains short-lived Google credentials through GitHub OpenID Connect federation. Cosign separately uses GitHub OIDC for a Sigstore signing certificate.

Do not create JSON service-account keys for this active path. The preserved Ratify compatibility code can create a key if explicitly enabled; enable_legacy_ratify defaults to false because Kyverno is the active verifier. That legacy exception is not a prerequisite for reproduction.

The baseline root declares Terraform >= 1.7.0; Google and Google Beta providers >= 5.30.0, < 8.0.0; Helm provider >= 2.13.0, < 3.0.0; and Kubernetes provider >= 2.30.0, < 3.0.0. These are declared compatibility ranges, not a promise that every available release in those ranges reproduces old results.

Prepare Git, Terraform, the Google Cloud CLI with the GKE authentication plugin, kubectl, Helm, Docker, jq, and Python 3.12 for the policy checks. The signing action installs Cosign v2.4.1; use the baseline action and its pinned dependencies as the version reference. Record the versions you actually use. New scanner databases and floating build inputs can change a result even when source is unchanged.

Cost comes from regional GKE management, worker nodes, balanced disks, Cloud NAT, VPC flow logs, registry storage and egress, and workload logging. The checked-in examples and variable defaults do not prove the historical node count or your future bill. Managed Prometheus, ExternalDNS, and the external alert route are disabled by default in the production root; enabled services still deserve review even when their consuming module is disabled.

Set a short evidence window and a cleanup owner before creating resources. Keep final artifact metadata and a versioned, access-controlled state bucket for as long as recovery or audit requires. State is sensitive even if no active path creates a JSON key.

The root’s github_repository validation accepts only devSatym/gcp-supply-chain-security. The policy pins that repository’s signing workflow on refs/heads/main, and Argo CD tracks its main branch. A fork or detached tag cannot satisfy those bindings automatically. In your owned reproduction copy, intentionally align federation, verifier expectations, provenance, registry paths, and GitOps source together. Review that change as a new environment contract; preserve the historical project unchanged.

Production input contract, provider ranges, and historical cost guide.