Service inventory
The GCP Baseline configures the Google Cloud services below, grouped by resource hierarchy, identity, networking, security, evidence and delivery. Most run by default; the ones with a material price or an operational cost are built into the code and switched off until a deployment needs them, each with one switch and its price beside it. The unit column names the unit that configures the service and the project it runs in.
How the services group
Resource hierarchy and governance
| Service | What the Baseline does with it | Unit (project) | Default |
|---|---|---|---|
| Resource Manager | The folders core and plat, the 14 projects and the secure tags purpose, stage and iap-target | organizations, hierarchical-firewall (core-root, core-network) | On |
| Organization Policy Service | 19 constraints at the organization, three custom label constraints, the public-object overrides of core-public and each workload project's subnet restriction | organizations, shared-vpc-service | On, labels in dry run |
| IAM deny policies | Audit protection at the organization, and two auditor policies that keep the auditor groups away from data and from the plat projects' logs | organizations, groups-iam | On |
Identity and access
| Service | What the Baseline does with it | Unit (project) | Default |
|---|---|---|---|
| Cloud Identity groups | The 14 groups of the access matrix, looked up by default or created by the Baseline when create_groups is on | groups-iam (core-identity) | On |
| Identity and Access Management (IAM) | Group bindings at the organization, on the folders and on each stage project; a deployer service account per project, Owner of that project only | groups-iam, project-baseline | On |
| Privileged Access Manager | Four entitlements for Owner and organization administration, 12 hours at most, two of them approved by another lead | pam (core-identity) | On |
| Workload Identity Federation | The pool acme-github with the GitHub OpenID Connect (OIDC) provider, and one CI service account per repository | workload-identity (core-auto) | On |
Networking
| Service | What the Baseline does with it | Unit (project) | Default |
|---|---|---|---|
| Virtual Private Cloud (VPC) | Three VPCs with global routing; per stage a nodes subnet with pods and services ranges, a data subnet, a proxy-only and a Private Service Connect subnet; flow logs and Private Google Access | vpc-hub, vpc-prod, vpc-nonprod (core-network) | On |
| Shared VPC | acme-core-network as the only host; each workload project attached as a service project with access to its own stage's subnets | host-project, shared-vpc-service | On |
| VPC Network Peering | Hub to prod and hub to nonprod, never domain to domain | peering (core-network) | On |
| Cloud Router and Cloud NAT | One router and one NAT per VPC per region, dynamic port allocation, error logging | vpc-* (core-network) | On |
| Private Service Access | One reserved range per stage, connected to the service producer network once per VPC | vpc-* (core-network) | On |
| Cloud Next Generation Firewall | The organization firewall policy (health checks, IAP) and one network firewall policy per VPC with the isolation-domain rules; threat-intelligence deny rules optional | hierarchical-firewall, firewall-* (core-network) | On, threat intelligence off |
| Cloud DNS | Public zones for the apex and the four stage subdomains, DNSSEC and query logging on apex, prod and staging; the private zone internal.company.com on all three VPCs with query logging | dns-zones (core-dns), private-dns (core-network) | On |
| Identity-Aware Proxy, OS Login | IAP TCP forwarding per group and stage project; OS Login on every VM | remote-access (core-network), project-baseline | On |
| Compute Engine | One e2-micro OS Login bastion per isolation domain in the hub, about $7/month each | remote-access (core-network) | Off |
| VPC Service Controls | An access policy and a perimeter around the workload projects, dry run first, then enforced | vpc-sc (core-security) | Off |
Security
| Service | What the Baseline does with it | Unit (project) | Default |
|---|---|---|---|
| Security Command Center | An organization notification config for active high and critical findings, and a mute rule for plat-sandbox | scc (core-security) | On, Standard tier |
| Cloud Run | The optional notifier that logs every finding and removes public bindings from buckets outside core-public | scc (core-security) | Off |
| Cloud KMS | The key ring acme-audit for the audit buckets and acme-sops with one key per stage, 365-day rotation | kms-audit (core-audit), kms-sops (core-security) | On |
| Secret Manager | Secrets whose values are entered by hand (the GitHub App credentials of the optional runners); the syncer's access in each workload project | platform-params (core-auto), secrets-syncer | On |
| Cloud Armor | A hierarchical security policy at the plat folder with threat-intelligence deny lists, and Cloud Armor Enterprise for the workload projects, $3,000/month | cloud-armor-org (core-security) | Off |
| Artifact Analysis | Vulnerability scanning on push, about $0.26 per image | artifact-registry (core-artifacts) | On |
Evidence: logging and monitoring
| Service | What the Baseline does with it | Unit (project) | Default |
|---|---|---|---|
| Cloud Audit Logs | Data Access logs (admin read, data read, data write) for every service of the organization, with an exemption list | org-logging (core-root) | On |
| Cloud Logging | Two aggregated organization sinks; the central log bucket acme-audit with 365-day retention, Log Analytics and a customer-managed key; _Default retention per project | org-logging, audit-log-bucket (core-audit), project-baseline | On |
| BigQuery | A linked dataset over the central log bucket, for SQL from BigQuery | audit-log-bucket (core-audit) | On |
| Cloud Storage | The state bucket acme-usw1-root-tfstate and the archive bucket acme-usw1-audit-logs, with an optional irreversible retention lock | state-backend (core-root), archive-bucket (core-audit) | On |
| Cloud Monitoring | acme-core-security as the metrics scope of every project, the security email channel, the CIS log-based metrics and their alert policies | metrics-scope (core-security), cis-alerts (core-audit) | On |
| Pub/Sub | The topic acme-security-alerts for Security Command Center findings | metrics-scope (core-security) | On |
| Cloud Trace | Enabled in the workload projects, with Cloud Trace User for each stage's engineer groups | observability (every workload project) | On |
Delivery, contract and cost
| Service | What the Baseline does with it | Unit (project) | Default |
|---|---|---|---|
| Artifact Registry | One Docker repository per image (three blueprint images, the runner and the notifier), immutable tags and cleanup policies, readers in the workload projects and writers in CI | artifact-registry (core-artifacts) | On |
| Parameter Manager | The landing-zone contract: one parameter per key in each workload project | pm-publish (every workload project) | On |
| Google Kubernetes Engine | A private GKE Autopilot cluster for self-hosted GitHub runners that scale to zero | github-runners (core-auto) | Off |
| Essential Contacts | A technical contact per project, a security contact per project once the security mailbox is set, and one at the organization | project-baseline, metrics-scope | On |
| Cloud Billing budgets | A monthly budget per project with alerts at 80% and 100% | project-baseline | Off |
APIs enabled in every project
The project baseline enables the same list of APIs in every project, so a blueprint never waits for an API to be switched on in one stage and not another. The seed project adds four organization-level APIs it is the quota project for: Cloud Asset, Cloud Identity, Organization Policy and Security Command Center.
default = [
"compute.googleapis.com",
"container.googleapis.com",
"iam.googleapis.com",
"iamcredentials.googleapis.com",
"sts.googleapis.com", # Security Token Service: Workload Identity Federation token exchange (GKE pods, the GitHub pool)
"cloudresourcemanager.googleapis.com",
"serviceusage.googleapis.com",
"logging.googleapis.com",
"monitoring.googleapis.com",
"secretmanager.googleapis.com",
"parametermanager.googleapis.com",
"cloudkms.googleapis.com",
"storage.googleapis.com",
"artifactregistry.googleapis.com",
"dns.googleapis.com",
"certificatemanager.googleapis.com",
"networkconnectivity.googleapis.com",
"networkservices.googleapis.com",
"run.googleapis.com",
"eventarc.googleapis.com",
"pubsub.googleapis.com",
"firestore.googleapis.com",
"memorystore.googleapis.com",
"dataproc.googleapis.com",
"dataplex.googleapis.com",
"bigquery.googleapis.com",
"biglake.googleapis.com",
"datacatalog.googleapis.com",
"containersecurity.googleapis.com",
"binaryauthorization.googleapis.com",
"osconfig.googleapis.com",
"essentialcontacts.googleapis.com",
"cloudbilling.googleapis.com",
"billingbudgets.googleapis.com",
"privilegedaccessmanager.googleapis.com",
"securitycenter.googleapis.com",
"orgpolicy.googleapis.com",
"servicenetworking.googleapis.com",
"iap.googleapis.com",
]
The dependency mapping page lists every unit and what it depends on, and organization-scoped units explains which of them act above a single project. Tool and provider versions are on the versions page.