All skills
google avatar

/google-cloud-recipe-foundation-builder

@becc4b8
by googlegoogle/skills21k stars
1,698

Deploys a baseline landing zone foundation for a Google Cloud Organization, establishing security guardrails using Organization Policies, resource hierarchy folders and projects, billing association, and centralized logging and monitoring. Deploys Google Cloud's recommended security controls and architecture. Use when setting up a new Google Cloud Organization or establishing a secure, enterprise-grade landing zone foundation. Don't use for individual project onboarding (use google-cloud-recipe-onboarding or product-specific skills instead).

Use this Skill: https://skilld.dev/gh/google/skills/google-cloud-recipe-foundation-builder

This session only. Nothing lands on disk.

referenceslogging-monitoring.md

≈665 tokens on demand. Your agent reads this file only when SKILL.md points to it.

Centralized Logging and Monitoring

This reference guide details the step-by-step commands to configure centralized audit logging and cross-project monitoring scope in the central logging-[SUFFIX] project.

1. Create Central Log Bucket

Create a log bucket named [ORG_NAME]-logging (substituting your organization name domain, e.g., example-com-logging) in the logging-[SUFFIX] project. The default location is global and retention is set to 30 days:

gcloud logging buckets create [ORG_NAME]-logging \
    --project=logging-[SUFFIX] \
    --location=global \
    --retention-days=30 \
    --description="Central logging and monitoring bucket"

2. Create Organization Log Sink

Create the organization-level audit log sink. Format the sink name as [ORGANIZATION_ID]-logbucketsink-[RANDOM_4_HEX] (replace with a random 4-digit hex string):

gcloud logging sinks create [ORGANIZATION_ID]-logbucketsink-[RANDOM_4_HEX] \
    logging.googleapis.com/projects/logging-[SUFFIX]/locations/global/buckets/[ORG_NAME]-logging \
    --organization=[ORGANIZATION_ID] \
    --log-filter='logName: /logs/cloudaudit.googleapis.com%2Factivity OR logName: /logs/cloudaudit.googleapis.com%2Fsystem_event OR logName: /logs/cloudaudit.googleapis.com%2Fdata_access OR logName: /logs/cloudaudit.googleapis.com%2Faccess_transparency'

Save the writerIdentity (service account) returned in the command output.

3. Grant IAM Permissions to the Log Sink

[!IMPORTANT] This step grants security-sensitive bucket writing permissions at the project level. Review the service account identity carefully.

Grant the sink's service account the bucketWriter role on the logging project:

gcloud projects add-iam-policy-binding logging-[SUFFIX] \
    --member=[SINK_SERVICE_ACCOUNT_IDENTITY] \
    --role=roles/logging.bucketWriter

4. Configure Monitoring Metrics Scope

Initialize and link projects to the central monitoring metrics scope. Use describe first to avoid attempting to link already scoped projects:

# Check existing metrics scope linkages
gcloud beta monitoring metrics-scopes describe locations/global/metricsScopes/logging-[SUFFIX]

# Review the monitoredProjects list. If missing, link the environment projects:

# Link Development project
gcloud beta monitoring metrics-scopes create projects/dev-[SUFFIX] --project=logging-[SUFFIX]

# Link Non-Production project
gcloud beta monitoring metrics-scopes create projects/non-prod-[SUFFIX] --project=logging-[SUFFIX]

# Link Production project
gcloud beta monitoring metrics-scopes create projects/prod-[SUFFIX] --project=logging-[SUFFIX]

Source: SKILL.md on GitHub

1 warning10d3 checks · Risk SAFE
  • Gen Agent Trust Hub10d

    This skill provides a recipe for deploying a Google Cloud landing zone foundation. It includes a 'lazy role remediation' strategy that instructs the agent to automatically grant itself extensive administrative privileges if it encounters permission errors during deployment. While designed for initializing new environments, this automated privilege escalation logic represents a significant security consideration for automated agents.

  • Socket10d

    2 alerts: gptSecurity

  • Snyk10d

    Risk: LOW · No issues

Signed by skilld at becc4b8. This ties the file your Agent reads to that commit on GitHub. It does not review the instructions.

Last checked against GitHub yesterday.

Activeupdated 2 weeks ago
metadata
{
  "version": "1.0.0",
  "category": "GettingStarted"
}

README badge

README badge for google/skills/google-cloud-recipe-foundation-builder