Prerequisites

Requirements before installing the protector.

    Google Cloud Services

    The following table describes the Google Cloud services that may a part of your Protegrity installation.

    ServiceDescription
    Cloud Run FunctionsProvides serverless compute for Protegrity protection operations and the ESA integration to fetch policy updates.
    Key Management ServiceProvides cryptographic keys for envelope encryption/decryption of the policy.
    Secret Manager ServiceStores secrets required during deployment, e.g., ESA credentials.
    Cloud Storage ServiceStorage location for the encrypted ESA policy package.
    Identity and Access ManagementEnforces access policies for deployed resources.
    Cloud Logging ServiceApplication and audit logs, performance monitoring, and alerts.
    Cloud VPCRequired for securing network access to On-Prem or cloud-based ESA.
    Pub/SubProvides a messaging service when forwarding audit logs to ESA is enabled.
    BIgQuery Connection APIAllows creating connection from BigQuery to Protect Cloud Function.

    ESA Version Requirements

    The Protector and Log Forwarder functions require a security policy from a compatible ESA version.

    The table below shows compatibility between different Protector and ESA versions.

    Protector VersionESA Version
    8.x9.09.1 & 9.210.0
    2.xNoYes*No
    3.0.x & 3.1.xNoNoYesNo
    3.2.xNoNoYes*
    4.0.xNoNoNoYes

    Legend

    Yes

    Protector was designed to work with this ESA version

    No

    Protector will not work with this ESA version

    *

    Backward compatible policy download supported:

    • Data elements and features which are common between this and previous ESA versions will be downloaded
    • Data elements and features which are new to this ESA version and do not exist in previous ESA version will not be downloaded

    Prerequisites

    RequirementDetail
    Protegrity distribution and installation scriptsThese artifacts are provided by Protegrity
    Protegrity ESA 10.0+The Cloud VNet must be able to obtain network access to the ESA
    Google Cloud AccountRecommend creating a new project for Protegrity Serverless
    Terraform CLI v0.14 or higherTerraform is used to deploy resources to Google Cloud Account

    Required Skills and Abilities

    RequirementsDescription
    GCP Cloud AdministratorRun Terraform (or perform steps manually), create/configure a VPC and IAM permissions.
    Protegrity AdministratorThe ESA credentials required to extract the policy for the Policy Agent
    Network AdministratorOpen firewall to access ESA and evaluate Google Cloud network setup


    Last modified : April 27, 2026