Google Cloud architecture consulting
Google Cloud projects, folders and Shared VPC host projects do not map 1:1 to AWS accounts. This engagement uses the Google Cloud resource hierarchy and IAM as documented.
Who this engagement is for
Teams whose production projects sit under a Google Cloud organization and who need hierarchy, Shared VPC or identity decisions written against Google Cloud docs.
Information required to begin
- Organization, folder and project layout
- Shared VPC host and service projects
- Workforce or Workload Identity Federation in use
- Billing account and committed use contracts
Engineering process
- Consultation scoped to the Google Cloud organization
- Review against current Google Cloud architecture and IAM docs
- Written ADRs using Google Cloud names
Deliverables
- Current-state assessment in Google Cloud terms
- Target architecture and ADRs
- Risk register
Provider-specific scope
- Resource Manager hierarchy, Organization Policy
- VPC, Shared VPC, Cloud VPN, Cloud Interconnect, Private Service Connect
- Cloud IAM, Workforce and Workload Identity Federation
- Cloud Billing export and committed use discounts
Limitations
- We do not replace Google Cloud Support.
- Assured Workloads and sovereign controls require your compliance owner in the room.
What is not included
- Workspace administration except where identity is shared
Author
Written by Ankit Mehta. Methods used in this engagement are documented in the related guides below.