A company requires that all new Google Cloud projects created within their organization must have a specific set of labels applied (e.g., `environment:production`, `cost-center:finance`). This is crucial for consistent cost allocation and resource management. How can this be enforced and automated?
- AConfigure an Organization Policy to mandate the presence of specific labels on new projects.
- BProvide a `gcloud` script to all users that includes the `--labels` flag when creating projects.
- CGrant the 'Project Labeler' IAM role to all developers to ensure they apply labels manually.
- DImplement a Cloud Function that is triggered by project creation events and applies the required labels.
Show answer & explanationAnswer & explanation
Correct answer: D. Implement a Cloud Function that is triggered by project creation events and applies the required labels.
Organization Policies can enforce *restrictions* on label values (e.g., only allowing specific values for a label key), but they cannot *mandate the presence* of labels or automatically apply them. A Cloud Function triggered by new project creation events, using the Resource Manager API to apply the required labels, is the correct automated enforcement mechanism.
Why the other options are wrong
- A. Organization Policies can enforce *which* labels are allowed or disallowed, or *what values* a label can have, but not *that a label must exist* or *automatically apply* it.
- B. Relying on users to run scripts is not enforcement and can be easily bypassed or forgotten.
- C. Granting an IAM role doesn't ensure labels are applied; it only grants permission. Manual application is not enforcement.
Automated Label Application on Project Creation
Automating the application of specific labels to new Google Cloud projects is typically achieved using a Cloud Function (triggered by Resource Manager events) that calls the Resource Manager API to set the desired labels.
- Organization Policies restrict, but don't auto-apply labels.
- Cloud Functions are event-driven for post-creation actions.
- Resource Manager API is used to manage project labels programmatically.
Memory trick: Function-al triggers are key to label projects automatically, not just policies.