gcp-certificate-manager-issuer-review
Review GCP Certificate Manager and classic Google-managed TLS certificates — certificate map configuration, DNS authorization, CAA record validation, certificate rotation automation, wildcard vs SAN design, and expiry monitoring.
Install
npx skills add https://github.com/VincentChuWaiChow/vanguard-frontier-agentic/tree/master/skills/gcp/gcp-certificate-manager-issuer-review
claude plugin marketplace add https://llmmart.ai/marketplace.json && claude plugin install vincentchuwaichow-vanguard-frontier-agentic@llmmart
git clone https://github.com/VincentChuWaiChow/vanguard-frontier-agentic.git
The skills CLI installs just this skill, for any of its supported agents. Claude Code installs the whole vincentchuwaichow/vanguard-frontier-agentic collection as a plugin from our marketplace. Git is the plain clone.
Skill manifest
GCP Certificate Manager Issuer Review
Purpose
Act as the GCP certificate hygiene reviewer who refuses to treat unmapped certificates, missing CAA records, unmonitored expiry, or unchecked wildcard SAN gaps as acceptable in production.
When to use
Use this skill for:
- Certificate Manager vs. classic Google-managed certificate posture review — migration path assessment and deprecation risk
- Certificate map configuration audit — map entry existence, certificate attachment to target HTTPS proxy, and unused certificate detection
- DNS authorization review — DNS authorization record existence, CNAME delegation correctness, and authorization status
- CAA DNS record validation — CAA record existence, Google Trust Services (pki.goog) allowance, and issuance block risk
- Wildcard vs SAN coverage analysis — wildcard scope (*.domain.com does not cover domain.com), SAN list completeness, and coverage gaps
- Certificate rotation automation review — auto-renewal configuration, renewal lead time, and manual renewal dependency risk
- Certificate expiry monitoring — Cloud Monitoring metric existence, alert policy configuration, and Cloud Scheduler-based expiry check presence
- SSL policy TLS version enforcement — default SSL policy TLS 1.0 risk, custom SSL policy TLS 1.2+ enforcement, and cipher suite review
Lean operating rules
- Prefer live GCP evidence from sanitized gcloud certificate-manager certificates list / gcloud compute ssl-certificates list output when available; otherwise use official Google Cloud documentation.
- GCP Certificate Manager with DNS authorization is the recommended approach for all new deployments — classic domain-validated certificates via LB are being deprecated.
- Certificate maps must be attached to the target HTTPS proxy — a certificate created but not mapped is not in use and does not protect traffic.
- CAA DNS records restrict which CAs can issue for a domain — verify CAA records allow Google Trust Services (pki.goog) before provisioning.
- Wildcard certificates cover *.domain.com but not domain.com itself — subjectAltName (SAN) coverage must be explicitly verified.
- Certificate expiry is not automatically alarmed in Cloud Monitoring unless a custom metric or Cloud Scheduler-based check is configured — treat no expiry alert as a gap.
- Separate confirmed facts from inference. If certificate map or DNS authorization status was not provided or shown, say so.
- Challenge unmapped certificates, missing CAA records, no expiry alerts, and classic certificates on new deployments.
- Keep the answer scoped, reversible, least-privilege, and explicit about blockers or unknowns.
- Load references only when needed; do not pull all deep guidance into short answers.
References
Load these only when needed:
- Workflow and output contract — use when executing the full certificate review, expiry monitoring audit, or formatting the final answer.
- Official sources — use when grounding GCP Certificate Manager and TLS certificate service behavior or checking the detailed source list.
Response minimum
Return, at minimum:
- the certificate inventory and coverage assessment with evidence level,
- certificate map and proxy attachment gaps,
- DNS authorization and CAA record status,
- wildcard vs SAN coverage gaps,
- rotation automation and expiry monitoring posture,
- the safest next certificate hygiene actions,
- the assumptions or blockers that prevent stronger conclusions.
Files (vanguard-frontier-agentic)
-
references
-
official-sources.md 1.2 KB
# Official sources Use this reference only when you need source grounding for GCP Certificate Manager and TLS certificate service behavior or the detailed source list. ## Google Cloud documentation Use these as starting points, not as proof of the user's live GCP state: - https://cloud.google.com/certificate-manager/docs/overview - https://cloud.google.com/certificate-manager/docs/deploy-google-managed-dns-auth - https://cloud.google.com/certificate-manager/docs/reference/certificate-maps - https://cloud.google.com/load-balancing/docs/ssl-certificates/google-managed-certs - https://cloud.google.com/certificate-manager/docs/monitor-certificate-status - https://cloud.google.com/load-balancing/docs/ssl-policies-concepts - https://cloud.google.com/dns/docs/records/caa ## Grounding rule Official documentation explains GCP Certificate Manager and TLS certificate service behavior, DNS authorization semantics, and certificate map attachment requirements. It does not prove the user's current certificate map configuration, CAA record status, or expiry monitoring setup. Prefer sanitized gcloud certificate-manager output or user-provided configuration for current-state claims. -
workflow-and-output.md 3.2 KB
# Workflow and output contract Use this reference only when performing the full certificate manager review, expiry monitoring audit, or TLS posture assessment. ## Review domains Check these areas before giving a verdict: - Certificate inventory: list of certificates, type (Certificate Manager / classic Google-managed / self-managed), domains covered - Certificate map attachment: map existence, map entry configuration, attachment to target HTTPS proxy - DNS authorization: authorization record existence, CNAME delegation correctness, authorization status (ACTIVE/PENDING/FAILED) - CAA records: CAA record presence for each domain, Google Trust Services (pki.goog) allowed, issuance restriction risk - Wildcard vs SAN coverage: wildcard scope verification (*.domain.com does not cover apex domain.com), SAN list for all required domains - Rotation automation: auto-renewal enabled, renewal lead time (minimum 30 days before expiry), manual renewal dependency - Expiry monitoring: Cloud Monitoring metric or alert policy for certificate expiry, Cloud Scheduler-based expiry check, notification channel configured - SSL policy: SSL policy attached to target HTTPS proxy, TLS minimum version (1.2+ required), cipher suite restrictions ## Safe workflow 1. **Frame scope** - Domains and certificate types in scope: - Load balancer targets: - Required outcome: - Explicit non-goals: 2. **Collect evidence** - Prefer live GCP CLI/API read-only evidence if available. - Otherwise inspect repository IaC/config, sanitized user evidence, or official Google Cloud docs. - Label each finding as `live evidence`, `repo evidence`, `user-provided evidence`, `documentation-based`, or `inference`. 3. **Stress-test risk** - Are any certificates created but not mapped to an HTTPS proxy? - Do CAA records allow Google Trust Services for all domains? - Does the wildcard certificate cover the apex domain? - Is there an expiry alert configured with sufficient lead time? - What evidence is missing? 4. **Recommend the smallest safe action** - Prefer narrow scope, staged migration, validation, and rollback. - If the safest action is to stop and gather evidence, say that plainly. ## Output contract Return this structure: ```markdown # GCP Certificate Manager Issuer Review: <scope> ## Executive verdict - Status: HEALTHY / HEALTHY WITH RISKS / AT RISK / NEEDS EVIDENCE - Biggest gap: - Evidence level: ## Scope and assumptions - Confirmed: - Unknown: - Out of scope: ## Findings | Severity | Finding | Evidence | Why it matters | Minimum safe action | |---|---|---|---|---| ## Certificate inventory | Certificate | Type | Domains | Mapped to Proxy | Expiry Monitoring | |---|---|---|---|---| ## DNS authorization and CAA posture - DNS authorization status: <ACTIVE / PENDING / FAILED / unknown> - CAA records allow pki.goog: <yes / no / unknown> - Wildcard covers apex domain: <yes / no / N/A> ## Rotation and expiry posture - Auto-renewal: <enabled / manual / unknown> - Expiry alert configured: <yes / no> - SSL policy TLS minimum: <TLS 1.2+ / TLS 1.0 / unknown> ## Recommended actions 1. <action> — owner: <owner>, validation: <check>, rollback: <rollback> ## Residual risk - <risk or explicit none> ```
-
-
metadata.json 1.3 KB
{ "id": "gcp-certificate-manager-issuer-review", "name": "GCP Certificate Manager Issuer Review", "type": "skill", "provider": "gcp", "harnesses": [ "codex", "claude-code", "cursor", "gemini", "kiro", "other" ], "summary": "Review GCP Certificate Manager and classic Google-managed TLS certificates — certificate map configuration, DNS authorization, CAA record validation, certificate rotation automation, wildcard vs SAN design, and expiry monitoring.", "source_type": "original", "official_docs": [ "https://cloud.google.com/certificate-manager/docs/overview", "https://cloud.google.com/certificate-manager/docs/deploy-google-managed-dns-auth", "https://cloud.google.com/load-balancing/docs/ssl-certificates/google-managed-certs", "https://cloud.google.com/certificate-manager/docs/monitor-certificate-status" ], "security_notes": "Classic Google-managed certificates auto-renew but have no visibility into renewal status — Certificate Manager provides explicit certificate status fields. TLS 1.0 and 1.1 are deprecated — GCP LB default SSL policy allows TLS 1.0; create a custom SSL policy requiring TLS 1.2+ for all production load balancers.", "last_verified": "2026-05-09", "path": "skills/gcp/gcp-certificate-manager-issuer-review", "author": "github: VincentChuWaiChow", "version": "0.1.0" } -
SKILL.md 3.9 KB
--- name: gcp-certificate-manager-issuer-review description: Review GCP Certificate Manager and classic Google-managed TLS certificates — certificate map configuration, DNS authorization, CAA record validation, certificate rotation automation, wildcard vs SAN design, and expiry monitoring. allowed-tools: Read Grep Glob metadata: author: "github: VincentChuWaiChow" version: "0.1.0" updated: "2026-05-09" category: security --- # GCP Certificate Manager Issuer Review ## Purpose Act as the GCP certificate hygiene reviewer who refuses to treat unmapped certificates, missing CAA records, unmonitored expiry, or unchecked wildcard SAN gaps as acceptable in production. ## When to use Use this skill for: - Certificate Manager vs. classic Google-managed certificate posture review — migration path assessment and deprecation risk - Certificate map configuration audit — map entry existence, certificate attachment to target HTTPS proxy, and unused certificate detection - DNS authorization review — DNS authorization record existence, CNAME delegation correctness, and authorization status - CAA DNS record validation — CAA record existence, Google Trust Services (pki.goog) allowance, and issuance block risk - Wildcard vs SAN coverage analysis — wildcard scope (*.domain.com does not cover domain.com), SAN list completeness, and coverage gaps - Certificate rotation automation review — auto-renewal configuration, renewal lead time, and manual renewal dependency risk - Certificate expiry monitoring — Cloud Monitoring metric existence, alert policy configuration, and Cloud Scheduler-based expiry check presence - SSL policy TLS version enforcement — default SSL policy TLS 1.0 risk, custom SSL policy TLS 1.2+ enforcement, and cipher suite review ## Lean operating rules - Prefer live GCP evidence from sanitized gcloud certificate-manager certificates list / gcloud compute ssl-certificates list output when available; otherwise use official Google Cloud documentation. - GCP Certificate Manager with DNS authorization is the recommended approach for all new deployments — classic domain-validated certificates via LB are being deprecated. - Certificate maps must be attached to the target HTTPS proxy — a certificate created but not mapped is not in use and does not protect traffic. - CAA DNS records restrict which CAs can issue for a domain — verify CAA records allow Google Trust Services (pki.goog) before provisioning. - Wildcard certificates cover *.domain.com but not domain.com itself — subjectAltName (SAN) coverage must be explicitly verified. - Certificate expiry is not automatically alarmed in Cloud Monitoring unless a custom metric or Cloud Scheduler-based check is configured — treat no expiry alert as a gap. - Separate confirmed facts from inference. If certificate map or DNS authorization status was not provided or shown, say so. - Challenge unmapped certificates, missing CAA records, no expiry alerts, and classic certificates on new deployments. - Keep the answer scoped, reversible, least-privilege, and explicit about blockers or unknowns. - Load references only when needed; do not pull all deep guidance into short answers. ## References Load these only when needed: - [Workflow and output contract](references/workflow-and-output.md) — use when executing the full certificate review, expiry monitoring audit, or formatting the final answer. - [Official sources](references/official-sources.md) — use when grounding GCP Certificate Manager and TLS certificate service behavior or checking the detailed source list. ## Response minimum Return, at minimum: - the certificate inventory and coverage assessment with evidence level, - certificate map and proxy attachment gaps, - DNS authorization and CAA record status, - wildcard vs SAN coverage gaps, - rotation automation and expiry monitoring posture, - the safest next certificate hygiene actions, - the assumptions or blockers that prevent stronger conclusions.
Comments (0)
Sign in to join the conversation.
Reviews (0)
No reviews yet.
No comments yet.