Menu

Post image 1
Post image 2
1 / 2
0

GCP Has No Automatic Kill Switch for Leaked API Keys. Here's What I Built.

DEV Community·Cloudsentinel.dev·about 1 month ago
#IpDsiZbh
Reading 0:00
15s threshold

And what you can do right now to protect yourself — whether you use my tool or not. I kept seeing posts like this on Reddit: "Woke up to a $128,000 Google Cloud bill. Key was compromised overnight. Google denied the adjustment request." "3-person startup. Gemini API key silently reauthorized. Normal monthly spend was $180. Bill: $82,314 in 48 hours." "Student. Pushed API key to a private GitHub repo that was accidentally public. Was on summer break. Never saw the alerts. $55,444." I'm a developer building on GCP myself. After reading enough of these, I realized I had zero automatic protection. If one of my keys got leaked tonight, the only thing standing between me and a five-figure bill was: Hoping I'd see a budget alert email in time Being awake Logging in fast enough Finding the right key Deleting it manually That's a terrible safety net. So I built CloudSentinel — an automatic kill switch for GCP API keys. But this article isn't a pitch.…

Continue reading — create a free account

Join HashtagPLUS to read full articles, follow hashtags, vote, and join the conversation.

Read More