Google Cloud architecture consulting

Google Cloud projects, folders and Shared VPC host projects do not map 1:1 to AWS accounts. This engagement uses the Google Cloud resource hierarchy and IAM as documented.

Who this engagement is for

Teams whose production projects sit under a Google Cloud organization and who need hierarchy, Shared VPC or identity decisions written against Google Cloud docs.

Information required to begin

  • Organization, folder and project layout
  • Shared VPC host and service projects
  • Workforce or Workload Identity Federation in use
  • Billing account and committed use contracts

Engineering process

  1. Consultation scoped to the Google Cloud organization
  2. Review against current Google Cloud architecture and IAM docs
  3. Written ADRs using Google Cloud names

Deliverables

  • Current-state assessment in Google Cloud terms
  • Target architecture and ADRs
  • Risk register

Provider-specific scope

  • Resource Manager hierarchy, Organization Policy
  • VPC, Shared VPC, Cloud VPN, Cloud Interconnect, Private Service Connect
  • Cloud IAM, Workforce and Workload Identity Federation
  • Cloud Billing export and committed use discounts

Limitations

  • We do not replace Google Cloud Support.
  • Assured Workloads and sovereign controls require your compliance owner in the room.

What is not included

  • Workspace administration except where identity is shared

Author

Written by Ankit Mehta. Methods used in this engagement are documented in the related guides below.

Related technical guides

Official sources