Back to Apache Software Foundation
GSoC 2026

[GSOC-273] Test optimization and integration of a resource and security monitoring system

This project delivers an integrated framework to optimize cost, strengthen governance, and improve security operations for Apache Beam resources on Google Cloud Platform (GCP). Key deliverables include: GCP Cost Optimization for Taxi Pipelines: A targeted optimization effort for NYC taxi-related Beam tests and examples to reduce unnecessary Pub/Sub and Dataflow consumption. The work includes execution-bound controls, reusable datasets/snapshots, and safer cleanup practices to preserve reproducibility while lowering operational cost. GCP Resource Governance via IaC: A Terraform-based Infrastructure as Code baseline to define and enforce labels, TTL metadata, ownership fields, and lifecycle policies for high-cost services (BigQuery, Dataflow, Compute Engine, Artifact Registry, and Cloud Storage). This enables a version-controlled, auditable, and repeatable infrastructure governance model. Automated Inventory and Drift Detection: A continuous inventory and compliance pipeline integrated with GitHub Actions, BigQuery, and dashboards. The system will collect resource state, classify orphaned/non-compliant assets, run Terraform validation/plan checks, and detect drift between current infrastructure and declared baseline. Service Key Compliance Monitoring: An operational monitoring flow for service account keys that tracks rotation health, propagation status, TTL violations, and suspicious usage signals, with automated reporting and alerts. Safe Remediation Workflows: Disable-then-delete playbooks executed first in dry-run mode and later in controlled execution, providing secure and traceable cleanup of obsolete resources based on validated policy outcomes.

Project details

Contributor

Hansel Tepal

Mentors

Not available

Technologies

Not listed in the archive