Skip to main content

Overview

All resources live in your GCP account, and data never leaves your cloud. With Managed On-Premise, Paragon deploys, configures, and manages the Paragon installation in your GCP account. You own the infrastructure and resources. Paragon access to your environment is on-demand for support requests only, via a secure bastion. Other resources in your GCP organization remain inaccessible.

Security

We use a least-privilege access model through GCP projects and service accounts:
  • A new project for Paragon resources, separate from other projects
  • A service account in that project for Paragon deployment and management
You maintain full control over infrastructure access, can view all created resources, split billing, and audit all Paragon activity through GCP Cloud Audit Logs.

Setup

Provide the JSON configuration for the installer service account.

Directions

  1. Login to your GCP console as an admin.
  2. Create a project. a. In the top left corner (near the Google Cloud Platform logo), click the dropdown for your currently active project. b. In the modal that appears, click New Project. c. Name the project Paragon.
  3. Make sure the newly created project is the currently active one.
  4. Create a service account. a. Click IAM & Admin in the left sidebar. b. Click Service Accounts. c. Click Create Service Account. d. Make the service account an Owner of the project. e. Name the account Paragon Installer.
  5. Retrieve the auth configuration. a. Click the newly created service account. b. Navigate to Keys. c. Click Add Key. d. Generate a JSON file. e. Download the file.

Next Steps

Once all of this is done, send us the newly created service account JSON file, and we’ll set up your installation! If you have any questions, email enterprise@useparagon.com for help.