Resource Manager
Resource Manager holds the Google Cloud resource hierarchy: the organization, its folders, its projects and the tags bound to them. The GCP Enterprise Baseline builds a two-folder tree with 14 single-purpose projects and gives every project the same baseline.
What it does
Every Google Cloud organization sits at the top of one hierarchy. Folders group projects beneath it, and a project is the unit that owns resources, enables APIs, is linked to a billing account and carries its own IAM policy. Organization policies and IAM (Identity and Access Management) bindings set high in the tree are inherited by everything below. Secure tags (Resource Manager tags) are key-value pairs bound to a node of the tree; unlike labels they are inherited, and IAM deny policies and firewall policies can match them.
How BuiltForProd uses it
The organizations unit (environments/core/root/global) creates the tree in modules/organizations:
Both folders carry deletion protection. Project IDs are deterministic, acme-<folder>-<name>, and permanent once used; project_id_suffix in common.hcl adds a short suffix to every ID when one is already taken elsewhere. The seed project acme-core-root, which holds the state bucket, exists before the code runs: the unit adopts it with an import block and moves it into core. The other 13 projects are created when the unit's enable_projects input is on, since the billing account's project quota must first allow 14 projects. Every project is linked to the billing account in common.hcl and created without a default network.
| Projects | deletion_policy |
|---|---|
The ten core projects, acme-plat-staging, acme-plat-prod | PREVENT |
acme-plat-sandbox, acme-plat-dev | DELETE |
Tags. The unit creates two tag keys at the organization. purpose has the value audit, bound to acme-core-audit, which the audit-protection IAM deny policy matches. stage has the values prd, stg, dev, sbx and core, one bound to every project. After each change the unit's hook writes org_projects.hcl (organization, folder and project IDs and numbers, no secrets), which is committed and which root.hcl reads to target every unit at its project by name.
The project baseline. Every project then runs the project-baseline unit:
- 39 APIs from one list in
modules/project-baseline/variables.tf, so a project never enables a service by hand; the seed project also keeps the organization-level APIs it is the quota project for. - The default Compute Engine service account de-privileged (Editor removed).
- The deployer
sa-acme-terraform-deployer, Owner of its own project only, which the pipelines impersonate (see service accounts). _Defaultlog bucket retention: 365 days in the core projects; 30, 30, 90 and 365 days in sandbox, dev, staging and prod.- The project metadata
enable-oslogin = TRUE. - Essential Contacts on the organization's domain: a technical contact for technical, suspension and billing notices, and the security mailbox for security notices once it is set.
- An optional monthly budget alert (Cloud Billing).
Terms you will see
| Term | Meaning |
|---|---|
| Folder | A node between the organization and its projects: core and plat. |
| Seed project | acme-core-root, which exists before the code and is adopted into the core folder. |
| Secure tag | An inherited key-value pair bound to a project: purpose and stage. |
org_projects.hcl | The committed file of folder and project IDs that root.hcl uses to target units. |
project_id_suffix | An optional suffix on every project ID, set once in common.hcl. |
| Essential Contacts | The mailboxes Google Cloud notifies about a project, limited to the organization's domain. |
Where to read more
- GCP Enterprise Baseline overview and its architecture overview for the 14 projects and what each one holds.
- Organization Policy Service for the guardrails set at the organization node.
- Landing zones for why the foundation is split into isolated projects.