Closed fmichaelobrien closed 2 months ago
Start foundation setup on a relatively new org - one where no terraform or kcc config controller lz has been deployed yet
hit "Set Up Foundation"
start 1125
IAM state before
super-admin has
Folder Admin
Organization Administrator
domain has
Billing Account Creator
Project Creator
check errors
Check groups https://admin.google.com/ac/groups https://console.cloud.google.com/iam-admin/groups?organizationId=630259462753&supportedpurview=project
Output: 8 of 10 IAM groups
missing gcp-logging-viewers@obrienlabs.app gcp-billing-admins@obrienlabs.app
Triage gcp-logging-viewers@obrienlabs.app gcp-billing-admins@obrienlabs.app
before
add Billing Admin and Project Billing Manager
to
retry
ignore warning - buganizer sent Still getting a warning - checking groups
skip - just add yourself
i am already in the groups - continuing
missing groups - even though they exist
Groups exist (see left and right) - but are not getting picked up in the wizard in the middle screen
Fix: looks like IAM roles were not added to the groups - hence at least one role is required for them to show up in IAM
except that we have not done that step yet of adding roles attempting to add a role will work
I cannot discard though and continue
Discard IAM policies for missing groups
If you continue, access recommendations for the following missing groups will be discarded:
gcp-organization-admins@obrienlabs.app
gcp-vpc-network-admins@obrienlabs.app
gcp-logging-admins@obrienlabs.app
gcp-security-admins@obrienlabs.app
gcp-devops@obrienlabs.app
By discarding these IAM policies, you need to manually configure similar access we recommended for comparable groups in order to complete your foundation setup.
Buglist 2 - users and groups
add Billing Admin and Project Billing Manager
to
fixing
later in step 3 Groups exist (see left and right) - but are not getting picked up in the wizard in the middle screen
Fix: looks like IAM roles were not added to the groups - hence at least one role is required for them to show up in IAM
except that we have not done that step yet of adding roles attempting to add a role will work
I cannot discard though and continue
Discard IAM policies for missing groups
If you continue, access recommendations for the following missing groups will be discarded:
gcp-organization-admins@obrienlabs.app
gcp-vpc-network-admins@obrienlabs.app
gcp-logging-admins@obrienlabs.app
gcp-security-admins@obrienlabs.app
gcp-devops@obrienlabs.app
By discarding these IAM policies, you need to manually configure similar access we recommended for comparable groups in order to complete your foundation setup.
This issue is stale because it has been open 60 days with no activity. Remove stale label or comment or this will be closed in 7 days
20240402 TEF work not in https://github.com/terraform-google-modules/terraform-example-foundation/issues/1133 20240206 #345 superceeds this one Historical Follow previous cloud-setup investigation runs at
Artifacts
Requirements: We have a a required for a light landing zone
The enterprise setup is a Google supported LZ The fortigate TF overlay is a Fortinet supported example
1 - use the foundations setup https://github.com/CloudLandingZone/google-cloud-enterprise-setup-checklist Describing https://cloud.google.com/docs/enterprise/setup-checklist 2 - overlay the working unmodified fortigate cluster (reattach peering to the setup above…) https://github.com/fortinet/fortigate-tutorial-gcp/tree/main/terraform
Architecture
Base Landing Zone
Merged with Fortigate LB sandwich cluster - re-peer with above
This superseeds #345 20240206 #345 superceeds this one