Google Associate Cloud EngineerSetting up a cloud solution environmentHard

A company is setting up a new Google Cloud organization. They want to ensure that all newly created projects are automatically configured with a default set of API services enabled (e.g., Compute Engine API, Cloud Storage API, BigQuery API) to standardize their environment. How can they enforce this policy across their organization?

  1. AImplement a Cloud Function triggered by project creation events to enable the necessary APIs.
  2. BCreate a custom IAM role that includes permissions to enable these APIs and grant it to 'Project Creator' roles.
  3. CUtilize Organization Policies to define a constraint that enables specific APIs on new projects.
  4. DInstruct all users to manually enable the required APIs after creating each new project.
Show answer & explanation

Correct answer: A. Implement a Cloud Function triggered by project creation events to enable the necessary APIs.

While Organization Policies can enforce *restrictions* on API usage (e.g., disabling certain APIs), they cannot *enable* APIs directly upon project creation. A Cloud Function triggered by `google.cloud.resourcemanager.project.v1.create` events, which then calls the Service Usage API to enable the desired services, is the programmatic solution for this automation.

Why the other options are wrong

  • B. IAM roles grant permissions, but don't automatically *perform* actions like enabling APIs upon project creation.
  • C. Organization Policies are used for *restricting* resource configurations, not for *enabling* services automatically on creation.
  • D. Manual intervention is inefficient and prone to errors, especially in a large organization, and does not enforce standardization.

Automated API Enablement on Project Creation

Automatically enabling specific Google Cloud APIs upon new project creation is achieved programmatically, typically using a Cloud Function triggered by Resource Manager events, which then interacts with the Service Usage API.

  • Organization Policies restrict, not enable APIs.
  • Cloud Functions can react to project creation events.
  • Service Usage API is used to enable/disable APIs programmatically.

Memory trick: Function-al triggers enable APIs, not just policies and IAM keys.

More Setting up a cloud solution environment questions