Cloud

DevOpsArk + Google Cloud

GKE, Compute Engine, Artifact Registry and billing

Vendor: Google

Short answer

What does the DevOpsArk Google Cloud integration do?

The DevOpsArk Google Cloud integration connects projects so GKE clusters, Compute Engine instances, Artifact Registry, IAM and billing data are managed alongside your other providers.

Capabilities

What the Google Cloud integration provides

  • Manage Google Kubernetes Engine clusters, including Autopilot, in one multi-cloud inventory.
  • Inventory Compute Engine instances with patch state and baseline adherence.
  • Publish container images to Artifact Registry by immutable digest.
  • Evaluate project configuration against CIS Google Cloud Foundations and your own policy.
  • Attribute BigQuery billing export data to clusters, namespaces and teams.
  • Include Google Cloud IAM in the unified effective-access model.
  • Manage Cloud DNS zones through the reviewed change path.
Access

Exactly what is read, and what can be written

Read and write are separate grants. Nothing in the write column happens unless you explicitly allow it.

Read
  • GKE cluster, node pool and Autopilot configuration
  • Compute Engine instance inventory and labels
  • Artifact Registry repositories and images
  • Google Cloud IAM policy bindings
  • Cloud Monitoring metrics and Cloud Logging entries
  • BigQuery billing export data
  • Cloud DNS managed zones
  • VPC and firewall rule configuration
Write, only if granted
  • Kubernetes workloads deployed to GKE through ArkCD
  • Container images pushed to Artifact Registry
  • Cloud DNS record changes through the reviewed change path
  • Approved remediation where write scope is granted
Setup

Connecting Google Cloud

  1. 1
    Create a service account

    Create a Google Cloud service account for DevOpsArk with the supplied viewer roles.

  2. 2
    Choose the scope

    Grant at organisation, folder or project level depending on how much should be visible.

  3. 3
    Connect

    Register the service account with workload identity federation, avoiding a long-lived key.

  4. 4
    Attach billing export

    Point DevOpsArk at the BigQuery billing export dataset.

FAQ

Google Cloud integration: frequently asked questions

Connect Google Cloud and see your own data

Read-only connection takes minutes. Most demos start with the customer estate rather than a sample one.