All skills
davila7 avatar

/google-cloud-onboarding

@82b0fb3

Guides developers through their first steps on Google Cloud, covering account creation, billing setup, project management, CLI installation, and deploying a first resource.

Use this Skill: https://skilld.dev/gh/davila7/claude-code-templates/google-cloud-onboarding

This session only. Nothing lands on disk.

referencegoogle-cloud-setup.md

≈1.4k tokens on demand. Your agent reads this file only when SKILL.md points to it.

Google Cloud Setup

This guide provides an overview of the enterprise-level setup process for Google Cloud, focusing on creating a secure, scalable foundation.

Overview

Enterprise onboarding requires more than just a single project. It involves establishing an Organization resource, setting up a resource hierarchy (Folders and Projects), managing identities centrally, and configuring shared networking and security policies.

Phases of Enterprise Setup

1. Establish Your Organization

The Organization resource is the root node of your resource hierarchy.

2. Configure Billing

3. Identity and Access (IAM)

  • Centralized Management: Use Google Groups to manage permissions rather than assigning roles directly to individual users.
  • Administrative Access: Assign core IAM roles:
    • Organization Administrator: Full control over all resources.
    • Billing Administrator: Manage billing accounts and link projects.
    • Network Administrator: Manage VPC networks, firewalls, and VPNs.
    • Security Administrator: Manage security policies and SCC.

4. Resource Hierarchy

Organize your projects using Folders to reflect your business structure or environments (e.g., Production, Development).

  • Folders: Group projects by department or environment.
  • Projects: The base unit for resource management.

5. Networking (VPC)

  • Shared VPC: Allows multiple service projects to share a common VPC network managed by a host project.
  • Subnets: Create regional subnets with non-overlapping IP ranges.
  • Connectivity: Set up High Availability (HA) VPN or Cloud Interconnect for hybrid connectivity to on-premises data centers.

6. Security and Compliance

  • Organization Policies: Apply constraints at the organization or folder level (e.g., restrict allowed regions, disable public IP creation).
  • Security Command Center (SCC): Enable SCC for threat detection and security health analytics.
  • Encryption: Use Cloud KMS (Key Management Service) for managing encryption keys.

7. Centralized Logging and Monitoring

  • Cloud Logging: Use Log Sinks to export logs from across the organization to a central BigQuery dataset or Pub/Sub topic. Routing logs to a centralized bucket helps users centrally manage compliance with data retention and data residency requirements.
  • Cloud Monitoring: Set up a scoping project to monitor metrics from multiple projects in one place.

Best Practices

  • Infrastructure as Code (IaC): Use Terraform to manage and deploy your foundation. Google Cloud provides Terraform blueprints for enterprise setup.
  • Principle of Least Privilege: Start with minimal permissions and expand as needed.
  • Separation of Duties: Ensure that network, security, and application administrators have distinct roles.

Links

Source: SKILL.md on GitHub

No alerts3mo3 checks · Risk SAFE
  • Gen Agent Trust Hub4mo

    This skill provides a standard onboarding guide for Google Cloud Platform, including official documentation links and common setup commands. All external references point to official Google domains, and no malicious patterns or data exfiltration attempts were detected.

  • Socket3mo

    No alerts

  • Snyk4mo

    Risk: LOW · No issues

Signed by skilld at 82b0fb3. This ties the file your Agent reads to that commit on GitHub. It does not review the instructions.

Last checked against GitHub 19 hours ago.

Activeupdated 5 months ago
source
google/skills (Apache 2.0)

README badge

README badge for davila7/claude-code-templates/google-cloud-onboarding