canada-ca / accelerators_accelerateurs-gcp

[GCP] Tools and templates to accelerate GC service delivery. Outils et modèles pour accélérer la prestation de services du GC.
MIT License
10 stars 8 forks source link

Adjust Guardrails Onboarding Documentation for recent changes - ongoing shared billing procedures #67

Open fmichaelobrien opened 1 year ago

fmichaelobrien commented 1 year ago

The 30 day guardrails version is still the terraform accelerator at https://github.com/canada-ca/accelerators_accelerateurs-gcp We have a version running in KCC/KRM in progress but I would rerun the TF version. There have been additions to scripting to assist with the installation around IAM roles. There are a couple of known limitations around GoC cloud broker shared billing accounts - where you will need to have the Billing Account Administrator or Billing Account User role set on the owning organization to complete the TF part of the install - refer to https://github.com/canada-ca/accelerators_accelerateurs-gcp/issues/64 and https://github.com/GoogleCloudPlatform/pbmm-on-gcp-onboarding/blob/main/docs/google-cloud-onboarding.md#shared-billing-accounts There was a factory change in terraform 1.2.8 that was fixed - an example full clean guardrails install is in https://github.com/canada-ca/accelerators_accelerateurs-gcp/issues/47 There was a terraform 1.3.7 upgrade in gcloud shell that caused some adjustments to the terraform yamls - reverivied in Nov 22 via https://github.com/canada-ca/accelerators_accelerateurs-gcp/issues/55 There is an evidence capture guide in the following security doc. https://github.com/GoogleCloudPlatform/pbmm-on-gcp-onboarding/blob/main/docs/google-cloud-security-controls.md#guardrails-subset