Google Cloud Account Auto Sync

CloudOps automatically synchronizes Google Cloud’s organizational hierarchy structure through a Trusted Account. It synchronizes by identifying the hierarchy based on each subscription, and synchronization occurs for CloudOps’s workspaces, project groups, projects, and service accounts.

Hierarchy Structure Synchronization

Auto Sync Criteria

Google CloudCloudOps
OrganizationWorkspace
FolderWorkspace, Project Group
ProjectProject
Service AccountService Account

Google Cloud Hierarchy Structure Reference

Google Cloud’s management structure follows an Organization > Folder > Project hierarchy, which is identical to CloudOps’s structure. Similarly, Google Cloud accounts have Service Accounts with identical names.

ℹ️
With this identical management structure, any changes to Google Cloud projects and accounts can be automatically reflected in CloudOps.

Permission Grant

To use the auto-sync feature in CloudOps, you must add Organization Viewer and Folder Viewer roles to the Google Cloud service account used in the Trusted Account settings. This must be executed at the Organization Level.

Auto Sync Results

CloudOps’s account auto-sync feature applies differently depending on the Trusted Account’s Scope.

Domain Scope Trusted Account

Trusted Accounts created in the Domain can be created in Admin Mode and can be configured in two ways:

  1. The Organization becomes a single CloudOps Workspace, enabling synchronization of all underlying projects and accounts.
    Google CloudCloudOps
    OrganizationWorkspace
    FolderProject Group
    ProjectProject
    Service AccountService Account

  1. Top-level Google Cloud Folders can be synchronized as multiple Workspaces. This optimizes performance and management by organizing the management system at the organizational level.
    Google CloudCloudOps
    Top-level FolderWorkspace
    Sub FolderProject Group
    ProjectProject
    Service AccountService Account
💡
For creating Trusted Accounts in Admin Mode, please refer to this guide.

Workspace Scope Trusted Account

For Trusted Accounts created in a Workspace, synchronization applies below the Workspace level.

Google CloudCloudOps
FolderProject Group
ProjectProject
Service AccountService Account