M2 _ T-GCPFCI-B _ Core Infrastructure v5.1.0 _ ILT
M2 _ T-GCPFCI-B _ Core Infrastructure v5.1.0 _ ILT
02 Resources and
Access in the Cloud
Proprietary + Confidential
03 IAM roles
04 Service accounts
05 Cloud Identity
Folders
Organization
node
Projects
Resources
Proprietary + Confidential
Organization
Node Policy
Other Policies
Proprietary + Confidential
01
Projects are separate entities under
the Organization node
02
Projects hold resources, each of which
belongs to just one Project
03
Projects can have different owners
and users
Delete projects
The projects
inherit policies
assigned to a folder
Proprietary + Confidential
Organization
Node
Non-Google Workspace
New Organization Node
customer
03 IAM roles
04 Service accounts
05 Cloud Identity
Administrators can
apply policies that define
who can do what on
which resources
Proprietary + Confidential
Organization
Project
Policy
Inheritance
03 IAM roles
04 Service accounts
05 Cloud Identity
Basic
IAM role
Proprietary + Confidential
Predefined
IAM role
instanceAdmin
predefined actions
compute.instances.delete
compute.instances.get Compute Engine
compute.instances.list
compute.instances.setMachineType
compute.instances.start
compute.instances.stop instance_a instance_b
Proprietary + Confidential
Custom
IAM role
instanceOperator
predefined actions
compute.instances.get
compute.instances.list Compute Engine
compute.instances.start
compute.instances.stop
instance_a instance_b
Proprietary + Confidential
Custom
IAM role
Permissions need to be managed
03 IAM roles
04 Service accounts
05 Cloud Identity
Service account
Cloud
Storage
Virtual machine
Create a service
account to authenticate
the VM to Cloud Storage
Proprietary + Confidential
Alice Bob
(Editor) (Viewer)
Proprietary + Confidential
03 IAM roles
04 Service accounts
05 Cloud Identity
03 IAM roles
04 Service accounts
05 Cloud Identity
01 02 03 04
Includes: