A team migrating from AWS to Google Cloud creates a project the same way they'd create an AWS account, expecting IAM permissions and billing to work the same way underneath - then hits confusing surprises about Projects, Service Accounts, and why deleting a project doesn't actually delete it for 30 days. This pillar covers the foundational structure every other GCP skill depends on - the resource hierarchy, identity and access management, and the governance tools that turn a chaotic set of projects into a well-managed environment.
What This Pillar Covers
- Understanding the Organization, Folder, Project, and Resource hierarchy
- Using the gcloud CLI and Cloud Shell for daily administration and automation
- Configuring IAM with basic, predefined, and custom roles correctly
- Using Service Accounts securely, including impersonation instead of downloaded key files
- Setting up Billing Accounts, budgets, and cost alerts before overspending happens
- Enforcing Organization Policies and managing resource quotas across projects
Who This Is For
Cloud administrators, DevOps engineers, and IT professionals responsible for organizing Google Cloud projects, controlling who can access what, and keeping cloud spend predictable across growing engineering teams.
Why This Matters in Production
At a fast-growing fintech, a Service Account key file downloaded once for convenience and never rotated becomes exactly the kind of long-lived, leakable credential that causes a real security incident. Without Organization Policies restricting risky defaults and a properly scoped IAM role structure, one overly broad permission grant can let a single compromised identity touch far more of the environment than it should.
Prerequisites
- Basic familiarity with command-line tools
- General understanding of cloud computing concepts (IaaS, PaaS, SaaS)
- A Google Cloud Free Tier account for hands-on practice