Configuring Cloud Logging and Monitoring for Google Cloud Services: A Complete Foundation Builder Guide

You can configure centralized Cloud Logging and Monitoring for Google Cloud services by deploying a central log bucket, organization-wide audit log sink, cross-project metrics scope, and IAM bindings using the reusable Foundation Builder skill in the google/skills repository.

The google/skills repository provides a production-ready, reusable skill that automates the deployment of a centralized logging-and-monitoring landing zone across your entire Google Cloud organization. By implementing the Google Cloud Recipe: Foundation Builder skill, you establish a secure, auditable observability foundation that aggregates logs and metrics from development, non-production, and production environments into a single, centrally managed location.

Core Components of Centralized Observability

The architecture defined in skills/cloud/google-cloud-recipe-foundation-builder/SKILL.md consists of four tightly coupled components that work together to ensure comprehensive visibility across all projects.

Central Log Bucket

The central log bucket serves as the single destination for all audit logs, providing a globally located storage point with a default 30-day retention period. This bucket is created using the gcloud logging buckets create command and is designed to consolidate logs from every project in your organization.

gcloud logging buckets create myorg-logging \
    --project=logging-abcd1234 \
    --location=global \
    --retention-days=30 \
    --description="Central logging and monitoring bucket"

As documented in the logging-monitoring.md reference, this bucket acts as the immutable backend for your organization's audit trail.

Organization-Wide Log Sink

An organization-level log sink routes every Cloud Audit log from all projects to the central bucket. The sink captures four critical log types: activity, system events, data access, and access transparency logs.

gcloud logging sinks create 1234567890-logbucketsink-1a2b \
    logging.googleapis.com/projects/logging-abcd1234/locations/global/buckets/myorg-logging \
    --organization=1234567890 \
    --log-filter='logName: /logs/cloudaudit.googleapis.com%2Factivity OR logName: /logs/cloudaudit.googleapis.com%2Fsystem_event OR logName: /logs/cloudaudit.googleapis.com%2Fdata_access OR logName: /logs/cloudaudit.googleapis.com%2Faccess_transparency'

The sink name pattern and filter syntax are specified in the reference documentation to ensure complete audit coverage across your organization.

Cross-Project Metrics Scope

Cloud Monitoring metrics scopes link environment-specific projects (dev, non-prod, prod) to a central monitoring project, allowing you to view metrics from all environments in a single pane of glass.

gcloud beta monitoring metrics-scopes create projects/dev-abcd1234 --project=logging-abcd1234
gcloud beta monitoring metrics-scopes create projects/non-prod-abcd1234 --project=logging-abcd1234
gcloud beta monitoring metrics-scopes create projects/prod-abcd1234 --project=logging-abcd1234

This configuration enables centralized alerting and dashboarding without requiring separate monitoring setups for each project.

IAM Permissions for Log Routing

The sink's service account requires explicit permission to write logs into the central bucket. The skill automates the binding of the roles/logging.bucketWriter role to ensure secure, authenticated log delivery.

gcloud projects add-iam-policy-binding logging-abcd1234 \
    --member=serviceAccount:log-sink-svc@myorg.iam.gserviceaccount.com \
    --role=roles/logging.bucketWriter

This IAM binding is executed via gcloud projects add-iam-policy-binding as part of the skill's deployment flow.

Implementation Walkthrough

The Foundation Builder skill orchestrates the configuration through a declarative, four-phase workflow defined in SKILL.md.

  1. Pre-flight validation – The skill collects your organization ID, billing account, and optional resource suffixes while verifying prerequisites documented in [references/setup-prerequisites.md](https://github.com/google/skills/blob/main/skills/cloud/google-cloud-recipe-foundation-builder/references/setup-prerequisites.md).

  2. Folder and project creation – It provisions the Common, Production, Non-Production, and Development folders, then creates associated projects with the required APIs enabled (logging.googleapis.com, monitoring.googleapis.com).

  3. Centralized logging and monitoring deployment – The skill executes the bucket creation, sink configuration, IAM binding, and metrics scope linking commands in sequence.

  4. Validation – A comprehensive checklist verifies that policies, folder hierarchies, billing links, the log bucket, sink routing, and metrics scopes are all correctly configured.

Each phase includes failure-recovery logic and references the detailed command syntax found in [references/logging-monitoring.md](https://github.com/google/skills/blob/main/skills/cloud/google-cloud-recipe-foundation-builder/references/logging-monitoring.md).

Key Configuration Files in the Repository

Understanding the file structure helps you customize the deployment for specific organizational requirements:

Summary

  • The Foundation Builder skill provides a reusable, AI-enabled recipe for deploying production-grade observability infrastructure.
  • Centralized logging requires a global log bucket, organization-wide sink, and roles/logging.bucketWriter IAM bindings.
  • Cross-project monitoring is achieved by linking development, non-production, and production projects to a central metrics scope.
  • All configuration steps are codified in the google/skills repository with validation checks and failure-recovery logic.

Frequently Asked Questions

What is the default retention period for the central log bucket?

The Foundation Builder skill configures the central log bucket with a 30-day retention period by default. You can modify this value using the --retention-days flag when running the gcloud logging buckets create command, though 30 days represents the standard baseline for audit compliance in the reference implementation.

Which audit log types does the organization sink capture?

The organization-wide log sink captures four distinct audit log types: activity logs (admin, data, and system events), system event logs, data access logs, and access transparency logs. The sink's filter explicitly includes all four logName patterns to ensure comprehensive audit coverage across every project in your organization.

The metrics scope links projects by establishing a bidirectional relationship between the central monitoring project and each environment project using the gcloud beta monitoring metrics-scopes create command. Once linked, metrics from the development, non-production, and production projects become queryable and viewable within the central project's Cloud Monitoring interface, enabling unified dashboards and alerting policies.

What IAM role is required for the log sink service account?

The log sink service account requires the roles/logging.bucketWriter role on the central log bucket project. This role grants the specific permission set needed to write log entries to the bucket resource, and the skill automates this binding via gcloud projects add-iam-policy-binding immediately after sink creation.

Have a question about this repo?

These articles cover the highlights, but your codebase questions are specific. Give your agent direct access to the source. Share this with your agent to get started:

Share the following with your agent to get started:
curl -s "https://instagit.com/install.md"

Works with
Claude Codex Cursor VS Code OpenClaw Any MCP Client

Maintain an open-source project? Get it listed too →