Skip to main content

Service inventory

The GCP Baseline configures the Google Cloud services below, grouped by resource hierarchy, identity, networking, security, evidence and delivery. Most run by default; the ones with a material price or an operational cost are built into the code and switched off until a deployment needs them, each with one switch and its price beside it. The unit column names the unit that configures the service and the project it runs in.

How the services group​

Resource hierarchy and governance​

ServiceWhat the Baseline does with itUnit (project)Default
Resource ManagerThe folders core and plat, the 14 projects and the secure tags purpose, stage and iap-targetorganizations, hierarchical-firewall (core-root, core-network)On
Organization Policy Service19 constraints at the organization, three custom label constraints, the public-object overrides of core-public and each workload project's subnet restrictionorganizations, shared-vpc-serviceOn, labels in dry run
IAM deny policiesAudit protection at the organization, and two auditor policies that keep the auditor groups away from data and from the plat projects' logsorganizations, groups-iamOn

Identity and access​

ServiceWhat the Baseline does with itUnit (project)Default
Cloud Identity groupsThe 14 groups of the access matrix, looked up by default or created by the Baseline when create_groups is ongroups-iam (core-identity)On
Identity and Access Management (IAM)Group bindings at the organization, on the folders and on each stage project; a deployer service account per project, Owner of that project onlygroups-iam, project-baselineOn
Privileged Access ManagerFour entitlements for Owner and organization administration, 12 hours at most, two of them approved by another leadpam (core-identity)On
Workload Identity FederationThe pool acme-github with the GitHub OpenID Connect (OIDC) provider, and one CI service account per repositoryworkload-identity (core-auto)On

Networking​

ServiceWhat the Baseline does with itUnit (project)Default
Virtual Private Cloud (VPC)Three VPCs with global routing; per stage a nodes subnet with pods and services ranges, a data subnet, a proxy-only and a Private Service Connect subnet; flow logs and Private Google Accessvpc-hub, vpc-prod, vpc-nonprod (core-network)On
Shared VPCacme-core-network as the only host; each workload project attached as a service project with access to its own stage's subnetshost-project, shared-vpc-serviceOn
VPC Network PeeringHub to prod and hub to nonprod, never domain to domainpeering (core-network)On
Cloud Router and Cloud NATOne router and one NAT per VPC per region, dynamic port allocation, error loggingvpc-* (core-network)On
Private Service AccessOne reserved range per stage, connected to the service producer network once per VPCvpc-* (core-network)On
Cloud Next Generation FirewallThe organization firewall policy (health checks, IAP) and one network firewall policy per VPC with the isolation-domain rules; threat-intelligence deny rules optionalhierarchical-firewall, firewall-* (core-network)On, threat intelligence off
Cloud DNSPublic zones for the apex and the four stage subdomains, DNSSEC and query logging on apex, prod and staging; the private zone internal.company.com on all three VPCs with query loggingdns-zones (core-dns), private-dns (core-network)On
Identity-Aware Proxy, OS LoginIAP TCP forwarding per group and stage project; OS Login on every VMremote-access (core-network), project-baselineOn
Compute EngineOne e2-micro OS Login bastion per isolation domain in the hub, about $7/month eachremote-access (core-network)Off
VPC Service ControlsAn access policy and a perimeter around the workload projects, dry run first, then enforcedvpc-sc (core-security)Off

Security​

ServiceWhat the Baseline does with itUnit (project)Default
Security Command CenterAn organization notification config for active high and critical findings, and a mute rule for plat-sandboxscc (core-security)On, Standard tier
Cloud RunThe optional notifier that logs every finding and removes public bindings from buckets outside core-publicscc (core-security)Off
Cloud KMSThe key ring acme-audit for the audit buckets and acme-sops with one key per stage, 365-day rotationkms-audit (core-audit), kms-sops (core-security)On
Secret ManagerSecrets whose values are entered by hand (the GitHub App credentials of the optional runners); the syncer's access in each workload projectplatform-params (core-auto), secrets-syncerOn
Cloud ArmorA hierarchical security policy at the plat folder with threat-intelligence deny lists, and Cloud Armor Enterprise for the workload projects, $3,000/monthcloud-armor-org (core-security)Off
Artifact AnalysisVulnerability scanning on push, about $0.26 per imageartifact-registry (core-artifacts)On

Evidence: logging and monitoring​

ServiceWhat the Baseline does with itUnit (project)Default
Cloud Audit LogsData Access logs (admin read, data read, data write) for every service of the organization, with an exemption listorg-logging (core-root)On
Cloud LoggingTwo aggregated organization sinks; the central log bucket acme-audit with 365-day retention, Log Analytics and a customer-managed key; _Default retention per projectorg-logging, audit-log-bucket (core-audit), project-baselineOn
BigQueryA linked dataset over the central log bucket, for SQL from BigQueryaudit-log-bucket (core-audit)On
Cloud StorageThe state bucket acme-usw1-root-tfstate and the archive bucket acme-usw1-audit-logs, with an optional irreversible retention lockstate-backend (core-root), archive-bucket (core-audit)On
Cloud Monitoringacme-core-security as the metrics scope of every project, the security email channel, the CIS log-based metrics and their alert policiesmetrics-scope (core-security), cis-alerts (core-audit)On
Pub/SubThe topic acme-security-alerts for Security Command Center findingsmetrics-scope (core-security)On
Cloud TraceEnabled in the workload projects, with Cloud Trace User for each stage's engineer groupsobservability (every workload project)On

Delivery, contract and cost​

ServiceWhat the Baseline does with itUnit (project)Default
Artifact RegistryOne Docker repository per image (three blueprint images, the runner and the notifier), immutable tags and cleanup policies, readers in the workload projects and writers in CIartifact-registry (core-artifacts)On
Parameter ManagerThe landing-zone contract: one parameter per key in each workload projectpm-publish (every workload project)On
Google Kubernetes EngineA private GKE Autopilot cluster for self-hosted GitHub runners that scale to zerogithub-runners (core-auto)Off
Essential ContactsA technical contact per project, a security contact per project once the security mailbox is set, and one at the organizationproject-baseline, metrics-scopeOn
Cloud Billing budgetsA monthly budget per project with alerts at 80% and 100%project-baselineOff

APIs enabled in every project​

The project baseline enables the same list of APIs in every project, so a blueprint never waits for an API to be switched on in one stage and not another. The seed project adds four organization-level APIs it is the quota project for: Cloud Asset, Cloud Identity, Organization Policy and Security Command Center.

modules/project-baseline/variables.tf
default = [
"compute.googleapis.com",
"container.googleapis.com",
"iam.googleapis.com",
"iamcredentials.googleapis.com",
"sts.googleapis.com", # Security Token Service: Workload Identity Federation token exchange (GKE pods, the GitHub pool)
"cloudresourcemanager.googleapis.com",
"serviceusage.googleapis.com",
"logging.googleapis.com",
"monitoring.googleapis.com",
"secretmanager.googleapis.com",
"parametermanager.googleapis.com",
"cloudkms.googleapis.com",
"storage.googleapis.com",
"artifactregistry.googleapis.com",
"dns.googleapis.com",
"certificatemanager.googleapis.com",
"networkconnectivity.googleapis.com",
"networkservices.googleapis.com",
"run.googleapis.com",
"eventarc.googleapis.com",
"pubsub.googleapis.com",
"firestore.googleapis.com",
"memorystore.googleapis.com",
"dataproc.googleapis.com",
"dataplex.googleapis.com",
"bigquery.googleapis.com",
"biglake.googleapis.com",
"datacatalog.googleapis.com",
"containersecurity.googleapis.com",
"binaryauthorization.googleapis.com",
"osconfig.googleapis.com",
"essentialcontacts.googleapis.com",
"cloudbilling.googleapis.com",
"billingbudgets.googleapis.com",
"privilegedaccessmanager.googleapis.com",
"securitycenter.googleapis.com",
"orgpolicy.googleapis.com",
"servicenetworking.googleapis.com",
"iap.googleapis.com",
]

The dependency mapping page lists every unit and what it depends on, and organization-scoped units explains which of them act above a single project. Tool and provider versions are on the versions page.