GCP Landing Zone Builder
$2.99OfficialUse when building or hardening a GCP organization: folder/project hierarchy, Shared VPC, org policies, least-privilege IAM, log sinks, billing guardrails.
What you get
- โ10-step procedure
- โRunnable Shell / Terraform included
- โ10-point quality checklist
- โ9 pitfalls to avoid
- โInstalls into 6 tools
- Version
- v1 โ
- Last updated
- today
- Length
- 12 min read
- Requires
- Best with a strong model (Claude Opus 5)
Works in: Claude Code, Codex, Cline, opencode, OpenClaw, Hermes ยท Built for large codebases
What you'll need to set up
Fiddly setup โ follow closely ยท 60-120 min once the organization node exists (add 1-3 business days if the Cloud Identity domain still needs DNS verification)You need an existing Google Cloud organization node (a verified Cloud Identity or Workspace domain), org-level IAM roles on the caller, an open billing account, and a hand-created 'seed' project holding the Terraform state bucket and a Workload Identity Federation pool for CI โ the skill refuses to guess org IDs, billing IDs, or CIDRs and org policy blocks service account keys, so CI must be federated rather than key-based.
ORG_IDBILLING_IDSEEDREGIONHOSTGOOGLE_APPLICATION_CREDENTIALSPreview
When to use
Invoke when the work targets a Google Cloud organization, not a single project: "stand up a landing zone / foundation", "we have 40 projects on one flat billing account with no guardrails", "move teams onto Shared VPC so they stop building their own networks", "we failed a CIS or SOC 2 control on service account keys, external IPs, or audit log retention", "spend spiked and nobody noticed".
Do not invoke for single-project IaC, GKE cluster sizing, or app-tier networking โ those are downstream. Hand off once the hierarchy, Shared VPC, sinks, and budgets exist.
Inputs to gather
Refuse to guess org IDs, CIDRs, billing accounts, or domains.
| Input | How to obtain | |-
โฆ
๐ Buy once ($2.99) to unlock the full playbook, download it, and install it in every tool you use.