Ocean's GCP integration currently only ingests Cloud Asset Inventory resources via content_type=RESOURCE, with no way to sync IAM policy bindings, the explicit role-to-member-to-resource grants that describe who can access what. This adds a new ingestion kind backed by searchAllIamPolicies, with binding arrays expanded via itemsToParse, so explicit IAM grants can be modeled generically across resource types without a dedicated blueprint per resource type. Without it, teams need an external pipeline to build service-account access inventories and can't represent IAM access reviews natively in the catalog. Scope is limited to explicit bindings for now; inherited access modeling is a potential future iteration.
Created by Dhananjai Govind
·