Senior Cloud Infrastructure (GCP)

0 of 18 lessons complete (0%)

Module One — Resource Hierarchy and the GCP Landing Zone

Organisation Folders and Projects as a Governance Tool

This is a preview lesson

Register or sign in to take this lesson.

On Google Cloud the resource hierarchy is where policy inherits from. Get it right and IAM, organisation policies and billing all follow the structure; get it wrong and every team invents its own exceptions.

The three levels that matter

The organisation node sits at the top, folders group by business unit or environment, and projects hold the actual resources. Policies set higher flow down, so the folder layout is a policy design decision.

Projects as blast-radius boundaries

A project is the unit of billing, quota, API enablement and most IAM bindings. One project per workload per environment is the common pattern because it keeps failures and permissions contained.

Folders for environments or teams

Choose whether the first folder layer is teams or environments and stay consistent. Mixing both at the same level makes inherited policy unpredictable and hard to audit.

Action step

Draw your current or proposed hierarchy to three levels. For each folder, write the one policy that justifies its existence. Remove any folder with no such policy.

Tech Skills Library is independent and is not affiliated with, accredited by, or endorsed by any employer, government agency, standards body or vendor referenced in this course. This course is for education and skill-building only. It does not guarantee a job, promotion, security clearance or clearance eligibility, and no certification, credential or licence is issued on completion; learners who finish receive a Certificate of Completion badge only. Standards, frameworks and regulatory requirements change; always confirm current details with the issuing body and a qualified professional.