Configuring Cloud Logging and Monitoring for Google Cloud Services: A Complete Foundation Builder Guide
You can configure centralized Cloud Logging and Monitoring for Google Cloud services by deploying a central log bucket, organization-wide audit log sink, cross-project metrics scope, and IAM bindings using the reusable Foundation Builder skill in the google/skills repository.
The google/skills repository provides a production-ready, reusable skill that automates the deployment of a centralized logging-and-monitoring landing zone across your entire Google Cloud organization. By implementing the Google Cloud Recipe: Foundation Builder skill, you establish a secure, auditable observability foundation that aggregates logs and metrics from development, non-production, and production environments into a single, centrally managed location.
Core Components of Centralized Observability
The architecture defined in skills/cloud/google-cloud-recipe-foundation-builder/SKILL.md consists of four tightly coupled components that work together to ensure comprehensive visibility across all projects.
Central Log Bucket
The central log bucket serves as the single destination for all audit logs, providing a globally located storage point with a default 30-day retention period. This bucket is created using the gcloud logging buckets create command and is designed to consolidate logs from every project in your organization.
gcloud logging buckets create myorg-logging \
--project=logging-abcd1234 \
--location=global \
--retention-days=30 \
--description="Central logging and monitoring bucket"
As documented in the logging-monitoring.md reference, this bucket acts as the immutable backend for your organization's audit trail.
Organization-Wide Log Sink
An organization-level log sink routes every Cloud Audit log from all projects to the central bucket. The sink captures four critical log types: activity, system events, data access, and access transparency logs.
gcloud logging sinks create 1234567890-logbucketsink-1a2b \
logging.googleapis.com/projects/logging-abcd1234/locations/global/buckets/myorg-logging \
--organization=1234567890 \
--log-filter='logName: /logs/cloudaudit.googleapis.com%2Factivity OR logName: /logs/cloudaudit.googleapis.com%2Fsystem_event OR logName: /logs/cloudaudit.googleapis.com%2Fdata_access OR logName: /logs/cloudaudit.googleapis.com%2Faccess_transparency'
The sink name pattern and filter syntax are specified in the reference documentation to ensure complete audit coverage across your organization.
Cross-Project Metrics Scope
Cloud Monitoring metrics scopes link environment-specific projects (dev, non-prod, prod) to a central monitoring project, allowing you to view metrics from all environments in a single pane of glass.
gcloud beta monitoring metrics-scopes create projects/dev-abcd1234 --project=logging-abcd1234
gcloud beta monitoring metrics-scopes create projects/non-prod-abcd1234 --project=logging-abcd1234
gcloud beta monitoring metrics-scopes create projects/prod-abcd1234 --project=logging-abcd1234
This configuration enables centralized alerting and dashboarding without requiring separate monitoring setups for each project.
IAM Permissions for Log Routing
The sink's service account requires explicit permission to write logs into the central bucket. The skill automates the binding of the roles/logging.bucketWriter role to ensure secure, authenticated log delivery.
gcloud projects add-iam-policy-binding logging-abcd1234 \
--member=serviceAccount:log-sink-svc@myorg.iam.gserviceaccount.com \
--role=roles/logging.bucketWriter
This IAM binding is executed via gcloud projects add-iam-policy-binding as part of the skill's deployment flow.
Implementation Walkthrough
The Foundation Builder skill orchestrates the configuration through a declarative, four-phase workflow defined in SKILL.md.
-
Pre-flight validation – The skill collects your organization ID, billing account, and optional resource suffixes while verifying prerequisites documented in [
references/setup-prerequisites.md](https://github.com/google/skills/blob/main/skills/cloud/google-cloud-recipe-foundation-builder/references/setup-prerequisites.md). -
Folder and project creation – It provisions the
Common,Production,Non-Production, andDevelopmentfolders, then creates associated projects with the required APIs enabled (logging.googleapis.com,monitoring.googleapis.com). -
Centralized logging and monitoring deployment – The skill executes the bucket creation, sink configuration, IAM binding, and metrics scope linking commands in sequence.
-
Validation – A comprehensive checklist verifies that policies, folder hierarchies, billing links, the log bucket, sink routing, and metrics scopes are all correctly configured.
Each phase includes failure-recovery logic and references the detailed command syntax found in [references/logging-monitoring.md](https://github.com/google/skills/blob/main/skills/cloud/google-cloud-recipe-foundation-builder/references/logging-monitoring.md).
Key Configuration Files in the Repository
Understanding the file structure helps you customize the deployment for specific organizational requirements:
-
skills/cloud/google-cloud-recipe-foundation-builder/SKILL.md– The main recipe file that orchestrates the entire foundation building process, including the logging and monitoring provisioning workflow. -
skills/cloud/google-cloud-recipe-foundation-builder/references/logging-monitoring.md– Contains the exactgcloudcommands for bucket creation, sink configuration, and metrics scope management. -
skills/cloud/google-cloud-recipe-foundation-builder/references/admin-iam.md– Maps IAM roles and provides lazy-remediation logic for permission errors encountered during deployment. -
skills/cloud/google-cloud-recipe-foundation-builder/references/setup-prerequisites.md– Lists prerequisite checks including service enablement, billing account validation, and required IAM permissions.
Summary
- The Foundation Builder skill provides a reusable, AI-enabled recipe for deploying production-grade observability infrastructure.
- Centralized logging requires a global log bucket, organization-wide sink, and
roles/logging.bucketWriterIAM bindings. - Cross-project monitoring is achieved by linking development, non-production, and production projects to a central metrics scope.
- All configuration steps are codified in the
google/skillsrepository with validation checks and failure-recovery logic.
Frequently Asked Questions
What is the default retention period for the central log bucket?
The Foundation Builder skill configures the central log bucket with a 30-day retention period by default. You can modify this value using the --retention-days flag when running the gcloud logging buckets create command, though 30 days represents the standard baseline for audit compliance in the reference implementation.
Which audit log types does the organization sink capture?
The organization-wide log sink captures four distinct audit log types: activity logs (admin, data, and system events), system event logs, data access logs, and access transparency logs. The sink's filter explicitly includes all four logName patterns to ensure comprehensive audit coverage across every project in your organization.
How does the metrics scope link projects for centralized monitoring?
The metrics scope links projects by establishing a bidirectional relationship between the central monitoring project and each environment project using the gcloud beta monitoring metrics-scopes create command. Once linked, metrics from the development, non-production, and production projects become queryable and viewable within the central project's Cloud Monitoring interface, enabling unified dashboards and alerting policies.
What IAM role is required for the log sink service account?
The log sink service account requires the roles/logging.bucketWriter role on the central log bucket project. This role grants the specific permission set needed to write log entries to the bucket resource, and the skill automates this binding via gcloud projects add-iam-policy-binding immediately after sink creation.
Have a question about this repo?
These articles cover the highlights, but your codebase questions are specific. Give your agent direct access to the source. Share this with your agent to get started:
curl -s "https://instagit.com/install.md" Maintain an open-source project? Get it listed too →