google-cloud-recipe-foundation-builder

Automate Google Cloud Organization setup with security controls, resource hierarchy, and centralized logging.

17.1k|1.4k|Updated Mar 31, 2026
One-click install
npx skills add https://github.com/google/skills --skill google-cloud-recipe-foundation-builder-google
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: google-cloud-recipe-foundation-builder
Source: https://github.com/google/skills/tree/main/skills/cloud/google-cloud-recipe-foundation-builder
Command: npx skills add https://github.com/google/skills --skill google-cloud-recipe-foundation-builder-google

SYSTEM DOCUMENTATION & REQUIREMENTS

💡 This Skill includes scripts (resource) and references (resource) components.

What problem does it solve?

This Skill helps you set up a secure and standardized Google Cloud Organization with proper security controls, resource hierarchy, and centralized logging and monitoring.

Core Features & Use Cases

  • Security Guardrails: Enforces baseline Organization Policies for security.
  • Resource Hierarchy: Creates folders and projects with a predefined structure.
  • Centralized Logging: Deploys a global log bucket with audit logging.
  • Use Case: Suitable for setting up a new Google Cloud Organization or establishing a secure landing zone foundation for existing organizations.

Quick Start

Use the google-cloud-recipe-foundation-builder skill to deploy a secure landing zone foundation for your Google Cloud Organization.

Frequently Asked Questions about google-cloud-recipe-foundation-builder

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I set up a secure Google Cloud landing zone for a new organization?

To set up a secure Google Cloud landing zone, you need to establish a standardized resource hierarchy with folders and projects, enforce baseline Organization Policies for security guardrails, and configure centralized logging with a global audit log bucket.

What is included in an enterprise-grade Google Cloud organization setup?

An enterprise-grade Google Cloud organization setup includes a predefined resource hierarchy of folders and projects, enforced security controls via Organization Policies, and centralized monitoring through a global log bucket for audit logging.

Can I use this to enforce security guardrails on an existing Google Cloud Organization?

Yes, you can apply this secure landing zone foundation to existing Google Cloud Organizations to standardize resource hierarchy, enforce baseline security guardrails, and centralize audit logging.

What's the best way to centralize audit logging in Google Cloud?

The best way to centralize audit logging is to deploy a global log bucket within a structured resource hierarchy, ensuring all project logs are aggregated and monitored under predefined organization security controls.

Do I need a predefined resource hierarchy to deploy cloud security controls in Google Cloud?

Yes, establishing a predefined resource hierarchy of folders and projects is required to effectively apply baseline Organization Policies and enforce scalable cloud security controls across the organization.