Google Cloud Setup guided flow

Before you run workloads on Google Cloud, we recommend that administrators configure a foundation using Google Cloud Setup. A foundation includes fundamental settings that help you organize, manage, and maintain Google Cloud resources.

Using the interactive guide in Google Cloud Setup, you can quickly deploy a default configuration or make adjustments to align with your business needs:

Go to Google Cloud Setup

This document outlines steps and background information to help you complete the setup process, including the following phases:

  • Select a foundation option: Based on the workload that you want to support, select a proof of concept, production, or enhanced security foundation.

  • Establish your organization, administrators, and billing: Set up the top-level node of your hierarchy, create initial administrator users and assign access, and connect your payment method.

  • Create an initial architecture: Select an initial folder and project structure, apply security settings, configure logging and monitoring, and set up your network.

  • Deploy your settings: Your initial architecture choices are compiled in Terraform configuration files. You can quickly deploy through the Google Cloud console, or download the files to customize and iterate using your own workflow. After you deploy, select a support plan.

Select a Google Cloud Setup foundation option

To get started with Google Cloud Setup, you select one of the following foundation options based on your organization's needs:

  • Proof of concept: Support proof of concept workloads with basic security in mind. This option guides you through the Organization and Billing tasks. For example, you can select this option to experiment with Google Cloud before making a larger commitment.

  • Production: Support production-ready workloads with security and scalability in mind. This option includes all Google Cloud Setup tasks in this document. For example, you can select this option to configure a secure and scalable foundation for your organization.

  • Enhanced security: Includes all tasks in the Production foundation, as well as Cloud KMS with Autokey configuration in the Security task. For example, you can select this option if your organization is subject to strict security requirements.

To select a foundation option, do the following:

  1. Go to Google Cloud Setup: Foundations.

    Go to Foundations

  2. Click Start under one of the following options:

    • Proof of concept.
    • Production.
    • Enhanced security.
  3. Do one of the following:

Create a proof of concept foundation

A proof of concept foundation helps you perform the following:

  • Organization and Billing tasks.
  • Create a lightweight deployment that includes the following:
    • A folder configured for application management where you can define and manage applications.
    • A management project which helps you manage access, billing, observability, and other administrative functions for your applications.
    • A standard project where you can deploy resources.
    • Organization and billing administrator groups.
    • Recommended organization policies.

To create a proof of concept foundation, do the following:

  1. Complete the Organization task.

    Configure an identity provider, verify your domain, and generate your organization.

  2. Sign in to the console as the super administrator user you created in the Organization task.

  3. Select the Proof of concept foundation option.

  4. Make sure the organization you created is selected, and click Continue to Billing.

    The gcp-organization-admins and gcp-billing-admins groups are created, and you are added as a member of each group.

  5. Select or create a billing account. For more information, see the Billing task.

  6. Click Continue to Review and Deploy Foundation.

  7. From the Review and deploy your configuration screen, review the following draft configurations:

    • Resource hierarchy: Review the folder and projects.

    • Organization policies: Review the list of recommended organization policies. For more information, see Apply recommended organization policies.

  8. Click Deploy. Your proof of concept foundation is deployed.

  9. To enable billing on the management project, see Link a billing account to your management project.

For information on experimenting and building, see Build your Google Cloud architecture.

Establish your organization, administrators, and billing

Create an initial architecture

In this task, you configure the following:

  • Central logging to help you analyze and gain insights from logs for all projects in your organization.
  • Central monitoring to help you visualize metrics across all projects created in this setup.

Who performs this task

To set up logging and monitoring, you must have one of the following:

  • The Logging Admin (roles/logging.admin) and Monitoring Admin (roles/monitoring.admin) roles.
  • Membership in one of the following groups that you created in the Users and groups task:
    • gcp-organization-admins@YOUR_DOMAIN
    • gcp-security-admins@YOUR_DOMAIN
    • gcp-logging-monitoring-admins@YOUR_DOMAIN

What you do in this task

You do the following in this task:

  • Centrally organize logs that are created in projects across your organization to help with security, auditing, and compliance.
  • Configure a central monitoring project to have access to monitoring metrics across the projects you created in this setup.

Why we recommend this task

Log storage and retention simplifies analysis and preserves your audit trail. Central monitoring gives you a view of metrics in one place.

Before you begin

Complete the following tasks:

Centrally organize logging

Cloud Logging helps you store, search, analyze, monitor, and alert on log data and events from Google Cloud. You can also collect and process logs from your applications, on-premises resources, and other clouds. We recommend that you use Cloud Logging to consolidate logs into a single log bucket.

For more information, see the following:

To store your log data in a central log bucket, do the following:

  1. Sign in to the Google Cloud console as a user that you identified in Who performs this task.

  2. Select your organization from the Select from drop-down list at the top of the page.

  3. Go to Google Cloud Setup: Central logging and monitoring.

    Go to Central logging and monitoring

  4. Review the task overview and click Start central logging & monitoring.

  5. Review the task details.

  6. To route logs to a central log bucket, ensure that Store organization-level audit logs in a logs bucket is selected.

  7. Expand Route logs to a Logging log bucket and do the following:

    1. In the Log bucket name field, enter a name for the central log bucket.

    2. From the Log bucket region list, select the region where your log data is stored.

      For more information, see Log bucket locations.

    3. By default logs are stored for 30 days. We recommend that large enterprises store logs for 365 days. To customize the retention period, enter the number of days in the Retention period field.

      Logs stored for longer than 30 days incur a retention cost. For more information, see Cloud Logging pricing summary.

Export logs outside of Google Cloud

If you want to export logs to a destination outside of Google Cloud, you can export using Pub/Sub. For example, if you use multiple cloud providers, you might decide to export log data from each cloud provider to a third-party tool.

You can filter the logs you export to meet your unique needs and requirements. For example, you might choose to limit the types of logs you export to control costs or to reduce noise in your data.

For more information about exporting logs, see the following:

To export logs, do the following:

  1. Click Stream your logs to other applications, other repositories, or third parties.

  2. In the Pub/Sub topic ID field, enter an identifier for the topic that contains your exported logs. For information on subscribing to a topic, see Pull subscriptions.

  3. To select logs to export, do the following:

    1. For information about each log type, see Understand Cloud Audit Logs.

    2. To prevent one of the following recommended logs from being exported, click the Inclusion filter list and clear the log checkbox:

      • Cloud Audit logs: Admin Activity: API calls or actions that modify resource configuration or metadata.
      • Cloud Audit logs: System Event: Google Cloud actions that modify resource configuration.
      • Access Transparency: Actions that Google personnel take when accessing customer content.
    3. Select the following additional logs to export them:

      • Cloud Audit logs: Data Access: API calls that read resource configuration or metadata, and user-driven API calls that create, modify, or read user-provided resource data.
      • Cloud Audit logs: Policy Denied: Google Cloud service access denials to user or service accounts, based on security policy violations.
    4. The logs you select in this step are exported only if they are enabled in your projects or resources. For steps to change the log filter for your projects and resources after you deploy your configuration, see Inclusion filters.

    5. Click OK.

  4. Click Continue to Monitoring.

Set up central monitoring

Central monitoring helps you analyze system health, performance, and security for multiple projects. In this task, you add the projects that you created during the Hierarchy and access task to a scoping project. You can then monitor those projects from the scoping project. After you complete Cloud setup, you can configure other projects to be monitored by the scoping project.

For more information, see Metrics scope overview.

To set up central monitoring, do the following:

  1. To configure projects created during Google Cloud Setup for central monitoring, ensure that Use central monitoring is selected.

    Projects that you created during Google Cloud Setup are added to the metrics scope of the listed Scoping project.

  2. Cloud Monitoring includes a free monthly allotment. For more information, see Cloud Monitoring pricing summary.

  3. For steps to configure projects that you create outside of Google Cloud Setup, see the following:

Complete the configuration

To complete the logging and monitoring task, do the following:

  1. Click Confirm Configuration.

  2. Review your logging and monitoring configuration details. Your configuration isn't deployed until you deploy your settings in a later task.

What's next

Set up your initial networking configuration.