Skip to main content

Resource Manager

Resource Manager holds the Google Cloud resource hierarchy: the organization, its folders, its projects and the tags bound to them. The GCP Enterprise Baseline builds a two-folder tree with 14 single-purpose projects and gives every project the same baseline.

What it does​

Every Google Cloud organization sits at the top of one hierarchy. Folders group projects beneath it, and a project is the unit that owns resources, enables APIs, is linked to a billing account and carries its own IAM policy. Organization policies and IAM (Identity and Access Management) bindings set high in the tree are inherited by everything below. Secure tags (Resource Manager tags) are key-value pairs bound to a node of the tree; unlike labels they are inherited, and IAM deny policies and firewall policies can match them.

How BuiltForProd uses it​

The organizations unit (environments/core/root/global) creates the tree in modules/organizations:

Both folders carry deletion protection. Project IDs are deterministic, acme-<folder>-<name>, and permanent once used; project_id_suffix in common.hcl adds a short suffix to every ID when one is already taken elsewhere. The seed project acme-core-root, which holds the state bucket, exists before the code runs: the unit adopts it with an import block and moves it into core. The other 13 projects are created when the unit's enable_projects input is on, since the billing account's project quota must first allow 14 projects. Every project is linked to the billing account in common.hcl and created without a default network.

Projectsdeletion_policy
The ten core projects, acme-plat-staging, acme-plat-prodPREVENT
acme-plat-sandbox, acme-plat-devDELETE

Tags. The unit creates two tag keys at the organization. purpose has the value audit, bound to acme-core-audit, which the audit-protection IAM deny policy matches. stage has the values prd, stg, dev, sbx and core, one bound to every project. After each change the unit's hook writes org_projects.hcl (organization, folder and project IDs and numbers, no secrets), which is committed and which root.hcl reads to target every unit at its project by name.

The project baseline. Every project then runs the project-baseline unit:

  • 39 APIs from one list in modules/project-baseline/variables.tf, so a project never enables a service by hand; the seed project also keeps the organization-level APIs it is the quota project for.
  • The default Compute Engine service account de-privileged (Editor removed).
  • The deployer sa-acme-terraform-deployer, Owner of its own project only, which the pipelines impersonate (see service accounts).
  • _Default log bucket retention: 365 days in the core projects; 30, 30, 90 and 365 days in sandbox, dev, staging and prod.
  • The project metadata enable-oslogin = TRUE.
  • Essential Contacts on the organization's domain: a technical contact for technical, suspension and billing notices, and the security mailbox for security notices once it is set.
  • An optional monthly budget alert (Cloud Billing).

Terms you will see​

TermMeaning
FolderA node between the organization and its projects: core and plat.
Seed projectacme-core-root, which exists before the code and is adopted into the core folder.
Secure tagAn inherited key-value pair bound to a project: purpose and stage.
org_projects.hclThe committed file of folder and project IDs that root.hcl uses to target units.
project_id_suffixAn optional suffix on every project ID, set once in common.hcl.
Essential ContactsThe mailboxes Google Cloud notifies about a project, limited to the organization's domain.

Where to read more​