If you discover a security vulnerability, please report it responsibly:
- Do NOT open a public issue
- Email: security@example.com
- Include steps to reproduce
- Never commit credentials, tokens, or account IDs
- Use
terraform.tfvars(gitignored) for sensitive values - Rotate Service Account keys if accidentally exposed
- Enable org policy
iam.disableServiceAccountKeyCreation