GCP Incident Runbooks for Engineers
These runbooks are designed for the first 30 to 60 minutes of response, where containment quality matters most. Use detect, contain, eradicate, recover, and prevent as the default execution model.
1. First 15 Minutes Checklist
- Declare severity and start incident channel.
- Assign incident commander and communications owner.
- Preserve evidence before making destructive changes.
- Start containment on highest blast-radius vectors.
- Create a running timeline with timestamps.
2. Incident Decision Flow
flowchart TB
A[Alert Received] --> B[Validate Signal]
B --> C{Active Exploitation?}
C -->|Yes| D[Immediate Containment]
C -->|No| E[Scoped Investigation]
D --> F[Credential/Access Reset]
E --> F
F --> G[Patch and Verify]
G --> H[Postmortem and Prevention]
style A fill:#1976d2,color:#fff
style B fill:#1976d2,color:#fff
style C fill:#ff9800,color:#fff
style D fill:#ff9800,color:#fff
style G fill:#1976d2,color:#fff
style H fill:#1976d2,color:#fff
3. Runbook: Suspected Credential Leak
Detect
gcloud logging read \
'textPayload:("private_key" OR "BEGIN PRIVATE KEY" OR "Authorization: Bearer")' \
--freshness=24h --limit=100
Contain
# Disable leaked service account key
gcloud iam service-accounts keys delete "$LEAKED_KEY_ID" \
--iam-account "$SA_EMAIL" --quiet
Eradicate
- Remove leak source in pipeline or code.
- Rotate dependent credentials and update secret references.
- Enforce keyless auth where possible.
Recover
- Redeploy with clean credentials.
- Validate critical endpoints and workflows.
Prevent
- Add or tighten secret scanning in CI.
- Add log redaction and output hygiene checks.
4. Runbook: Public GCS Data Exposure
Detect
Contain
# Remove public access bindings
gcloud storage buckets remove-iam-policy-binding gs://$BUCKET_NAME \
--member=allUsers \
--role=roles/storage.objectViewer
Verify
- Attempt unauthenticated object access and confirm denial.
- Confirm expected principals still retain required access.
Prevent
- Add IaC policy checks to block public bucket bindings.
- Enable periodic bucket policy review in weekly ops.
5. Runbook: Over-Privileged IAM Assignment
Detect
gcloud projects get-iam-policy "$PROJECT_ID" --format=json > iam-policy.json
jq '.bindings[] | select(.role=="roles/owner" or .role=="roles/editor")' iam-policy.json
Contain
- Remove broad role from non-admin principals.
- Replace with least-privilege custom or predefined role.
Verify
- Re-run affected service workflows.
- Confirm no privileged operations outside intended scope.
6. Runbook: API Authorization Bypass
Detect
- Review logs for unusual access patterns or cross-tenant reads.
- Reproduce with negative auth test cases.
Contain
- Disable vulnerable route if needed.
- Add emergency policy at gateway or WAF layer.
Eradicate
- Implement missing scope/role checks.
- Add tenant or ownership checks in service layer.
Recover
- Redeploy patch.
- Re-run API regression pack from 06-api-security-regression-test-pack.md.
7. Evidence and Timeline Template
Incident ID:
Service:
Detected at:
Reporter:
Timeline:
- 10:02 UTC: Alert triggered
- 10:05 UTC: Incident channel created
- 10:11 UTC: Containment command executed
- 10:25 UTC: Validation complete
Impact:
Root cause:
Containment:
Recovery:
Prevention actions:
Owner + due date:
8. Post-Incident Engineering Actions
- Add regression tests that reproduce the incident class.
- Add one prevention control to CI or policy layer.
- Add detection rule updates to reduce time-to-detect.
- Share incident learnings in weekly engineering review.