Skip to main content

What you receive

You receive four things: the Baseline's Git repository customized for your organization, the documentation to run it, a Google Cloud organization of 14 projects deployed by the BuiltForProd team, and a handover after which your engineers own and change all of it. Blueprints, if you buy them, arrive the same way.

How delivery works​

The Baseline is customized from BuiltForProd's base repository, deployed directly into your Google Cloud organization by BuiltForProd engineers, and handed over ready for your teams to deploy workloads or customize further. The work is fully executed by BuiltForProd in every deployment option.

The repository​

The core deliverable is the landing-zone repository, acme-gcp-platform-baseline in the sample naming, where acme becomes your organization's namespace. It holds the whole foundation as code:

PartWhat it contains
Deployment tree (environments/)One folder per Google Cloud folder, project and region (or global), each with a stack file that lists the units deployed there
Unit definitions (units/)32 definitions, one per unit type, shared by every project that lists it
Stack templates (stacks/)plat-project, the four units every workload project runs, and includes/project-common, the two units every core project runs
Modules (modules/)31 OpenTofu modules, one resource category each, all custom and all in the repository
Address plan (network_map.yaml)The only place IP ranges are written
Switch filessecurity.hcl, network.hcl, identity.hcl and plat.hcl: the feature choices of the organization, each with its price beside it
Guard scripts (scripts/)Six checks that pre-commit and CI run before any plan, and the generator of org_projects.hcl
Workflows (.github/)Plan, apply and drift detection for GitHub Actions, two image builds for the optional components, and the code-owner rules

Every value your deployment must set (namespace, domains, organization and billing account IDs, Cloud Identity customer ID, GitHub organization, mailboxes) is marked in the code with a TODO: comment, and every optional choice (feature switches, cost-bearing options) with an @optional: comment that names the price where there is one. Nothing deployment-specific is hidden in logic. Two searches list them all:

git grep "TODO: "
git grep "@optional: "

The documentation​

The handover includes architecture decision records, how-to guides, troubleshooting manuals, FAQs and scaling guidance. In practice that is this documentation set, which covers the Baseline's architecture, projects, security, networking, compliance, delivery pipelines and day-2 operation, plus the documentation overview for the concepts behind it. Sign-in unlocks the full set for your organization, and pages show your own values (namespace, domain, organization ID) in place of the samples.

The deployed environment​

When BuiltForProd finishes, your Google Cloud organization runs:

  • 14 projects in the folders core and plat: the seed project acme-core-root, nine other core projects and four workload projects (sandbox, dev, staging, prod), each with the project baseline applied.
  • The network: acme-core-network as the Shared VPC host of the hub, prod and nonprod VPCs, hub-to-domain peering, Cloud NAT, the organization and per-VPC firewall policies, the private zone internal.company.com, the public zones of company.com and its stage subdomains, and IAP TCP forwarding for engineers.
  • Guardrails and evidence: the organization policies, label constraints in dry run, the secure tags and the audit-protection deny policy; Data Access audit logs and the two aggregated sinks into the audit project; Security Command Center notifications, the CIS log-based alerts and Artifact Analysis.
  • Identity: the 14 groups bound at the organization, folder and project levels, with Privileged Access Manager entitlements for Owner access.
  • Delivery: Workload Identity Federation for GitHub Actions, the CI service accounts and project deployers, the state bucket, the Artifact Registry repositories and the three workflows in your GitHub organization.
  • The landing-zone contract: Parameter Manager parameters in each workload project that the blueprints read.

Options with a material price or an operational cost are built into the code and switched on when your deployment needs them: Cloud Armor Enterprise with a hierarchical edge policy, VPC Service Controls, one bastion per isolation domain, the Security Command Center notifier and self-hosted GitHub runners. Security Command Center runs at the Standard tier, and at Premium when your organization subscribes to it. The architecture overview shows how the pieces connect, and the service inventory lists every Google Cloud service involved.

The handover​

At handover you own the repository and the environment. Changes go through pull requests: CI plans them, code owners approve, and merging applies them after a lead approves the production environment. Console changes are reported as drift.

The repository is licensed under the PolyForm Internal Use License 1.0.0: you may deploy, manage and scale your internal Google Cloud infrastructure with the code, modify it and share it with employees and contractors working for your organization, but you may not resell or sub-license it, host it in a public repository, use it to provide managed services to third parties, or remove its notices. The terms are summarized under purchasing and licensing.

The blueprints that build on it​

Blueprints deploy into the four workload projects from their own repositories and read the landing-zone contract the Baseline publishes:

BlueprintRepositories
Web App Blueprintacme-gcp-blueprint-webapp-infra, acme-gcp-blueprint-webapp-code, acme-gcp-blueprint-webapp-gitops
Data and ETL Blueprintacme-gcp-blueprint-etl-infra, acme-gcp-blueprint-etl-code
Secrets Blueprintacme-gcp-blueprint-secrets

The blueprints page describes the catalog.

Deployment options​

OptionWhat it includes
Standard DeploymentThe Baseline: the Google Cloud organization set up by BuiltForProd, the customized repository and the documentation
Full Deployment with BlueprintsEverything in Standard, plus any two blueprints deployed and working
Blueprint DeploymentFor customers who already run the Baseline: additional blueprints deployed by BuiltForProd

Ongoing help after handover is a separate, optional service, BuiltForProd Managed, in three options: On-Demand, Support SLA and Team Augmentation. The Baseline product page compares the editions and the GCP page introduces this one.