Identity and access
- Require phishing-resistant passkeys or TOTP for operators.
- Grant organization and project permissions independently.
- Create one API key per workload and environment.
- Disable or delete credentials when their owner or workload changes.
- Keep API secrets in a server-side secret manager and prevent them from entering logs.
Cloud CDN
- Use HTTPS to the origin and enable origin TLS validation.
- Restrict direct origin access where your architecture permits it.
- Do not publicly cache responses that vary by
Authorization, cookies, or user identity. - Review custom cache keys and ignored query parameters for cross-tenant collisions.
- Validate CORS, request headers, and response-header hiding policies in staging.
- Treat signed-URL keys as secrets and rotate them through a controlled process.
Cloud DNS
- Lower TTLs before a planned cutover, not during it.
- Verify the complete record set before changing nameservers.
- Preserve mail, verification, CAA, and delegation records during migration.
- Use health checks only for endpoints whose failure behavior you have tested.
- Confirm what happens when every eligible endpoint is unhealthy.