A multi-national corporation uses Google Cloud across several regions. They have a strict compliance requirement that mandates all data for projects related to their European operations must reside exclusively within the `europe-west1` region. How can this be enforced for all new resources created within specific projects designated for European operations?
- ACreate a custom IAM role that only grants permissions to create resources in `europe-west1`.
- BUse Cloud Functions to monitor resource creation and delete any resources outside `europe-west1`.
- CSet the default region for each European project using `gcloud config set region europe-west1`.
- DImplement an Organization Policy using the `constraints/gcp.resourceLocations` constraint.
Show answer & explanationAnswer & explanation
Correct answer: D. Implement an Organization Policy using the `constraints/gcp.resourceLocations` constraint.
The Organization Policy Service, specifically using the `constraints/gcp.resourceLocations` constraint, is designed to restrict where new physical resources (like Compute Engine instances, Cloud Storage buckets, etc.) can be created. This policy can be applied at the organization, folder, or project level.
Why the other options are wrong
- A. IAM roles grant permission to *perform* actions, not to *restrict the location* where those actions can take place. There isn't a granular IAM permission for 'create resource in X region only'.
- B. Cloud Functions would be a reactive solution (after creation), leading to deletion of non-compliant resources, which is less efficient and potentially disruptive compared to prevention.
- C. Setting the default region with `gcloud config` is a user preference, not an enforced policy. Users can still explicitly specify other regions.
Organization Policy: Resource Location Restriction
The Organization Policy Service, using the `constraints/gcp.resourceLocations` constraint, allows administrators to define and enforce geographic restrictions on where Google Cloud resources can be created, ensuring compliance with data residency requirements.
- Enforces data residency requirements.
- Prevents creation of resources outside specified locations.
- Applied at Organization, Folder, or Project level.
- Uses `constraints/gcp.resourceLocations`.
Memory trick: Org Policies constrain where your resources can be, for geo-compliance, it's the key.