Skip to content

compute.instances.addAccessConfig

GCP

compute.instances.addAccessConfig

service: GCP - Compute Engine
tactics:
techniques:

Event

Adds an access configuration to the selected VM network interface. With ONE_TO_ONE_NAT and no natIP, Compute Engine assigns an ephemeral external IPv4 address if the operation succeeds.

Security Context

An unexpected external IP can create a new network path, but firewall policies, routing, listening services, and host authentication still apply. This configuration event does not show use of an external remote service, so the standalone T1133 mapping has been removed.

Log Source

Google Cloud Audit Logs, Admin Activity, for compute.googleapis.com and v1.compute.instances.addAccessConfig. Check logging scope, access, routing, and retention. Correlate long-running operation records by operation ID. This first record with a RUNNING response is not completion evidence; a last record or DONE status must still be checked for errors and the resulting resource state.

Key Fields

FieldInvestigation value
protoPayload.authenticationInfo, requestMetadataPrincipal, delegation where present, caller context, and request timing.
protoPayload.methodName, resourceNameExact service method and target resource.
protoPayload.authorizationInfoRecorded permission checks; granted does not establish operation completion.
protoPayload.request, response, metadataRequested settings and available operation/delta details; presence and serialization vary.
operation.id, first, last; protoPayload.statusCorrelate start/completion records and inspect errors.
protoPayload.response.status, errorRUNNING is incomplete; DONE must still be checked for operation errors.

What to Investigate

  1. Confirm the actor, target, timing, and outcome against the approved change.
  2. Confirm the VM, interface, requested access configuration, external-IP organization policy, and approved need for public addressing.
  3. Inspect final operation outcome and the resulting interface address; distinguish ephemeral allocation from a requested static address.
  4. Evaluate effective ingress controls and service exposure, then correlate actual connection and authentication logs before claiming initial access.

Sample Event

Synthetic scenario. The sample starts adding an access configuration to nic0 on demiguise-infer-001. It omits natIP and shows no assigned address or successful connection. The networkInterface/accessConfig request wrapper is illustrative, not a verified native export.

Exact field presence, protobuf wrappers, and request/response serialization require captured-log validation. Numeric IDs and timing are illustrative; these examples are not parser fixtures.

{
"protoPayload": {
"@type": "type.googleapis.com/google.cloud.audit.AuditLog",
"authenticationInfo": {
"principalEmail": "draco@fantasticlogs.cloud"
},
"requestMetadata": {
"callerIp": "203.0.113.66",
"callerSuppliedUserAgent": "google-cloud-sdk gcloud/465.0.0 command/gcloud.compute.instances.add-access-config invocation-id/90000000000000000000001111101100 environment/None environment-version/None client-os/LINUX client-os-ver/(5,15,0) client-pltf-arch/x86_64 interactive/False from-script/False python/3.11.6 term/xterm-256color (Linux 5.15.0-1052-aws),gzip(gfe)",
"requestAttributes": {
"time": "2026-04-15T14:33:18.221987654Z",
"auth": {}
},
"destinationAttributes": {}
},
"serviceName": "compute.googleapis.com",
"methodName": "v1.compute.instances.addAccessConfig",
"authorizationInfo": [
{
"permission": "compute.instances.addAccessConfig",
"granted": true,
"resourceAttributes": {
"service": "compute",
"name": "projects/fantasticlogs-prod/zones/us-central1-a/instances/demiguise-infer-001",
"type": "compute.instances"
}
},
{
"permission": "compute.subnetworks.useExternalIp",
"granted": true,
"resourceAttributes": {
"service": "compute",
"name": "projects/fantasticlogs-prod/regions/us-central1/subnetworks/default",
"type": "compute.subnetworks"
}
}
],
"resourceName": "projects/fantasticlogs-prod/zones/us-central1-a/instances/demiguise-infer-001",
"request": {
"@type": "type.googleapis.com/compute.instances.addAccessConfig",
"networkInterface": "nic0",
"accessConfig": {
"type": "ONE_TO_ONE_NAT",
"name": "external-nat",
"networkTier": "PREMIUM"
}
},
"response": {
"@type": "type.googleapis.com/operation",
"id": "8200000000000000022",
"name": "operation-1776267198000-62fa274d8e201-ab001100-cd001100",
"operationType": "addAccessConfig",
"targetId": "6100000000000000011",
"targetLink": "https://www.googleapis.com/compute/v1/projects/fantasticlogs-prod/zones/us-central1-a/instances/demiguise-infer-001",
"selfLink": "https://www.googleapis.com/compute/v1/projects/fantasticlogs-prod/zones/us-central1-a/operations/operation-1776267198000-62fa274d8e201-ab001100-cd001100",
"zone": "https://www.googleapis.com/compute/v1/projects/fantasticlogs-prod/zones/us-central1-a",
"user": "draco@fantasticlogs.cloud",
"status": "RUNNING",
"progress": 0,
"insertTime": "2026-04-15T07:33:18.301-07:00",
"startTime": "2026-04-15T07:33:18.318-07:00"
},
"resourceLocation": {
"currentLocations": [
"us-central1-a"
]
}
},
"insertId": "evt001111101100",
"resource": {
"type": "gce_instance",
"labels": {
"project_id": "fantasticlogs-prod",
"zone": "us-central1-a",
"instance_id": "6100000000000000011"
}
},
"timestamp": "2026-04-15T14:33:18.550000000Z",
"severity": "NOTICE",
"logName": "projects/fantasticlogs-prod/logs/cloudaudit.googleapis.com%2Factivity",
"operation": {
"id": "operation-1776267198000-62fa274d8e201-ab001100-cd001100",
"producer": "compute.googleapis.com",
"first": true
},
"receiveTimestamp": "2026-04-15T14:33:18.567890123Z"
}

Sources

Documentation reviewed: October 5, 2026. Samples are synthetic illustrations, not captured production logs or lab-validated fixtures.