# Configuring Cloud Logging and Monitoring for Google Cloud Services: A Complete Foundation Builder Guide

> Configure Cloud Logging and Monitoring for Google Cloud services using the Foundation Builder skill. Centralize logs, audit logs, and metrics for robust oversight.

- Repository: [Google/skills](https://github.com/google/skills)
- Tags: how-to-guide
- Published: 2026-08-09

---

**You can configure centralized Cloud Logging and Monitoring for Google Cloud services by deploying a central log bucket, organization-wide audit log sink, cross-project metrics scope, and IAM bindings using the reusable Foundation Builder skill in the google/skills repository.**

The `google/skills` repository provides a production-ready, reusable skill that automates the deployment of a **centralized logging-and-monitoring landing zone** across your entire Google Cloud organization. By implementing the **Google Cloud Recipe: Foundation Builder** skill, you establish a secure, auditable observability foundation that aggregates logs and metrics from development, non-production, and production environments into a single, centrally managed location.

## Core Components of Centralized Observability

The architecture defined in [`skills/cloud/google-cloud-recipe-foundation-builder/SKILL.md`](https://github.com/google/skills/blob/main/skills/cloud/google-cloud-recipe-foundation-builder/SKILL.md) consists of four tightly coupled components that work together to ensure comprehensive visibility across all projects.

### Central Log Bucket

The **central log bucket** serves as the single destination for all audit logs, providing a globally located storage point with a default **30-day retention period**. This bucket is created using the `gcloud logging buckets create` command and is designed to consolidate logs from every project in your organization.

```bash
gcloud logging buckets create myorg-logging \
    --project=logging-abcd1234 \
    --location=global \
    --retention-days=30 \
    --description="Central logging and monitoring bucket"

```

As documented in the [logging-monitoring.md reference](https://github.com/google/skills/blob/main/skills/cloud/google-cloud-recipe-foundation-builder/references/logging-monitoring.md), this bucket acts as the immutable backend for your organization's audit trail.

### Organization-Wide Log Sink

An **organization-level log sink** routes every Cloud Audit log from all projects to the central bucket. The sink captures four critical log types: activity, system events, data access, and access transparency logs.

```bash
gcloud logging sinks create 1234567890-logbucketsink-1a2b \
    logging.googleapis.com/projects/logging-abcd1234/locations/global/buckets/myorg-logging \
    --organization=1234567890 \
    --log-filter='logName: /logs/cloudaudit.googleapis.com%2Factivity OR logName: /logs/cloudaudit.googleapis.com%2Fsystem_event OR logName: /logs/cloudaudit.googleapis.com%2Fdata_access OR logName: /logs/cloudaudit.googleapis.com%2Faccess_transparency'

```

The sink name pattern and filter syntax are specified in the reference documentation to ensure complete audit coverage across your organization.

### Cross-Project Metrics Scope

**Cloud Monitoring metrics scopes** link environment-specific projects (dev, non-prod, prod) to a central monitoring project, allowing you to view metrics from all environments in a single pane of glass.

```bash
gcloud beta monitoring metrics-scopes create projects/dev-abcd1234 --project=logging-abcd1234
gcloud beta monitoring metrics-scopes create projects/non-prod-abcd1234 --project=logging-abcd1234
gcloud beta monitoring metrics-scopes create projects/prod-abcd1234 --project=logging-abcd1234

```

This configuration enables centralized alerting and dashboarding without requiring separate monitoring setups for each project.

### IAM Permissions for Log Routing

The sink's service account requires explicit permission to write logs into the central bucket. The skill automates the binding of the `roles/logging.bucketWriter` role to ensure secure, authenticated log delivery.

```bash
gcloud projects add-iam-policy-binding logging-abcd1234 \
    --member=serviceAccount:log-sink-svc@myorg.iam.gserviceaccount.com \
    --role=roles/logging.bucketWriter

```

This IAM binding is executed via `gcloud projects add-iam-policy-binding` as part of the skill's deployment flow.

## Implementation Walkthrough

The Foundation Builder skill orchestrates the configuration through a declarative, four-phase workflow defined in [`SKILL.md`](https://github.com/google/skills/blob/main/SKILL.md).

1. **Pre-flight validation** – The skill collects your organization ID, billing account, and optional resource suffixes while verifying prerequisites documented in [[`references/setup-prerequisites.md`](https://github.com/google/skills/blob/main/references/setup-prerequisites.md)](https://github.com/google/skills/blob/main/skills/cloud/google-cloud-recipe-foundation-builder/references/setup-prerequisites.md).

2. **Folder and project creation** – It provisions the `Common`, `Production`, `Non-Production`, and `Development` folders, then creates associated projects with the required APIs enabled (`logging.googleapis.com`, `monitoring.googleapis.com`).

3. **Centralized logging and monitoring deployment** – The skill executes the bucket creation, sink configuration, IAM binding, and metrics scope linking commands in sequence.

4. **Validation** – A comprehensive checklist verifies that policies, folder hierarchies, billing links, the log bucket, sink routing, and metrics scopes are all correctly configured.

Each phase includes failure-recovery logic and references the detailed command syntax found in [[`references/logging-monitoring.md`](https://github.com/google/skills/blob/main/references/logging-monitoring.md)](https://github.com/google/skills/blob/main/skills/cloud/google-cloud-recipe-foundation-builder/references/logging-monitoring.md).

## Key Configuration Files in the Repository

Understanding the file structure helps you customize the deployment for specific organizational requirements:

- **[`skills/cloud/google-cloud-recipe-foundation-builder/SKILL.md`](https://github.com/google/skills/blob/main/skills/cloud/google-cloud-recipe-foundation-builder/SKILL.md)** – The main recipe file that orchestrates the entire foundation building process, including the logging and monitoring provisioning workflow.

- **[`skills/cloud/google-cloud-recipe-foundation-builder/references/logging-monitoring.md`](https://github.com/google/skills/blob/main/skills/cloud/google-cloud-recipe-foundation-builder/references/logging-monitoring.md)** – Contains the exact `gcloud` commands for bucket creation, sink configuration, and metrics scope management.

- **[`skills/cloud/google-cloud-recipe-foundation-builder/references/admin-iam.md`](https://github.com/google/skills/blob/main/skills/cloud/google-cloud-recipe-foundation-builder/references/admin-iam.md)** – Maps IAM roles and provides lazy-remediation logic for permission errors encountered during deployment.

- **[`skills/cloud/google-cloud-recipe-foundation-builder/references/setup-prerequisites.md`](https://github.com/google/skills/blob/main/skills/cloud/google-cloud-recipe-foundation-builder/references/setup-prerequisites.md)** – Lists prerequisite checks including service enablement, billing account validation, and required IAM permissions.

## Summary

- The **Foundation Builder skill** provides a reusable, AI-enabled recipe for deploying production-grade observability infrastructure.
- **Centralized logging** requires a global log bucket, organization-wide sink, and `roles/logging.bucketWriter` IAM bindings.
- **Cross-project monitoring** is achieved by linking development, non-production, and production projects to a central metrics scope.
- All configuration steps are codified in the `google/skills` repository with validation checks and failure-recovery logic.

## Frequently Asked Questions

### What is the default retention period for the central log bucket?

The Foundation Builder skill configures the central log bucket with a **30-day retention period** by default. You can modify this value using the `--retention-days` flag when running the `gcloud logging buckets create` command, though 30 days represents the standard baseline for audit compliance in the reference implementation.

### Which audit log types does the organization sink capture?

The organization-wide log sink captures four distinct audit log types: **activity logs** (admin, data, and system events), **system event logs**, **data access logs**, and **access transparency logs**. The sink's filter explicitly includes all four `logName` patterns to ensure comprehensive audit coverage across every project in your organization.

### How does the metrics scope link projects for centralized monitoring?

The metrics scope links projects by establishing a bidirectional relationship between the central monitoring project and each environment project using the `gcloud beta monitoring metrics-scopes create` command. Once linked, metrics from the development, non-production, and production projects become queryable and viewable within the central project's Cloud Monitoring interface, enabling unified dashboards and alerting policies.

### What IAM role is required for the log sink service account?

The log sink service account requires the **`roles/logging.bucketWriter`** role on the central log bucket project. This role grants the specific permission set needed to write log entries to the bucket resource, and the skill automates this binding via `gcloud projects add-iam-policy-binding` immediately after sink creation.