A highly regulated enterprise needs to implement a stringent security policy where data residency is a critical concern. They want to ensure that all their Google Cloud resources, including Compute Engine instances and Cloud Storage buckets, are created only within specific geographical regions (e.g., 'europe-west1' and 'europe-west2') and that no resources can ever be created outside these approved regions. This policy must apply to all projects under their organization. Which Google Cloud service and specific constraint should they use?
- AVPC Service Controls with a service perimeter enforced across specified regions.
- BResource Manager with the `constraints/iam.allowedPolicyMemberDomains` constraint.
- CCloud IAM with custom roles restricting region-specific resource creation permissions.
- DOrganization Policy Service with the `constraints/gcp.resourceLocations` constraint.
Show answer & explanationAnswer & explanation
Correct answer: D. Organization Policy Service with the `constraints/gcp.resourceLocations` constraint.
Organization Policy Service allows administrators to define constraints across an entire Google Cloud organization. The `constraints/gcp.resourceLocations` constraint specifically restricts the geographical locations where new resources can be created, directly addressing the data residency requirement for all projects. VPC Service Controls create security perimeters but don't prevent resource creation in unauthorized regions; IAM custom roles can be bypassed or misconfigured more easily than an organization policy.
Why the other options are wrong
- A. VPC Service Controls defines perimeters to prevent data exfiltration but does not prevent the creation of resources in unauthorized regions outside the perimeter.
- B. `constraints/iam.allowedPolicyMemberDomains` restricts which identities can be added to IAM policies, not resource locations.
- C. While IAM custom roles could restrict permissions, an organization policy is a stronger, organization-wide enforcement mechanism that is harder to bypass and provides a single source of truth for such a critical compliance requirement.
Organization Policy: Resource Locations
A Google Cloud Organization Policy constraint (`constraints/gcp.resourceLocations`) that restricts the geographical locations where an organization's cloud resources can be created, ensuring data residency compliance.
- Applies at Organization, Folder, or Project level.
- Prevents resource creation outside specified regions/zones.
- Critical for data residency and regulatory compliance.
Memory trick: Org Policy Location: The Cloud's Geofence.