DevOpsArk + Google Cloud
GKE, Compute Engine, Artifact Registry and billing
Vendor: Google
What does the DevOpsArk Google Cloud integration do?
The DevOpsArk Google Cloud integration connects projects so GKE clusters, Compute Engine instances, Artifact Registry, IAM and billing data are managed alongside your other providers.
What the Google Cloud integration provides
- Manage Google Kubernetes Engine clusters, including Autopilot, in one multi-cloud inventory.
- Inventory Compute Engine instances with patch state and baseline adherence.
- Publish container images to Artifact Registry by immutable digest.
- Evaluate project configuration against CIS Google Cloud Foundations and your own policy.
- Attribute BigQuery billing export data to clusters, namespaces and teams.
- Include Google Cloud IAM in the unified effective-access model.
- Manage Cloud DNS zones through the reviewed change path.
Exactly what is read, and what can be written
Read and write are separate grants. Nothing in the write column happens unless you explicitly allow it.
- GKE cluster, node pool and Autopilot configuration
- Compute Engine instance inventory and labels
- Artifact Registry repositories and images
- Google Cloud IAM policy bindings
- Cloud Monitoring metrics and Cloud Logging entries
- BigQuery billing export data
- Cloud DNS managed zones
- VPC and firewall rule configuration
- Kubernetes workloads deployed to GKE through ArkCD
- Container images pushed to Artifact Registry
- Cloud DNS record changes through the reviewed change path
- Approved remediation where write scope is granted
Connecting Google Cloud
- 1Create a service account
Create a Google Cloud service account for DevOpsArk with the supplied viewer roles.
- 2Choose the scope
Grant at organisation, folder or project level depending on how much should be visible.
- 3Connect
Register the service account with workload identity federation, avoiding a long-lived key.
- 4Attach billing export
Point DevOpsArk at the BigQuery billing export dataset.
Which modules use Google Cloud
Kubernetes
Multi-cluster Kubernetes management
Servers
Fleet inventory, patching and access
Cost Management
Cloud and Kubernetes cost attribution
Security
Posture, policy and continuous verification
ArkCD
Continuous delivery and progressive rollout
DNS Management
Records, zones and change safety
Google Cloud integration: frequently asked questions
It connects Google Cloud projects so GKE clusters, Compute Engine instances, Artifact Registry, IAM and billing appear in the same inventory and are governed by the same delivery, security and cost models as your other providers.
Yes. Autopilot clusters are managed through the same Kubernetes API path; the difference is simply that node-level operations are not applicable.
A service account with viewer-level roles covers inventory, posture and cost. Write access is separate and scoped. Workload identity federation is supported so no long-lived service account key is required.
The BigQuery billing export is joined with live inventory so node and instance cost is distributed to namespaces, workloads and teams in the same normalised model used for AWS and Azure.
Connect Google Cloud and see your own data
Read-only connection takes minutes. Most demos start with the customer estate rather than a sample one.