Google Cloud Account Auto Sync

SpaceONE automatically synchronizes Google Cloud’s organizational hierarchy structure through a Trusted Account. It synchronizes by identifying the hierarchy based on each subscription, and synchronization occurs for SpaceONE’s workspaces, project groups, projects, and service accounts.

Hierarchy Structure Synchronization

Auto Sync Criteria

Google CloudSpaceONE(Cloudforet)
OrganizationWorkspace
FolderWorkspace, Project Group
ProjectProject
Service AccountService Account

Google Cloud Hierarchy Structure Reference

Google Cloud’s management structure follows an Organization > Folder > Project hierarchy, which is identical to SpaceONE’s structure. Similarly, Google Cloud accounts have Service Accounts with identical names.

ℹ️
With this identical management structure, any changes to Google Cloud projects and accounts can be automatically reflected in SpaceONE.

Permission Grant

To use the auto-sync feature in SpaceONE, you must add Organization Viewer and Folder Viewer roles to the Google Cloud service account used in the Trusted Account settings. This must be executed at the Organization Level.

Auto Sync Results

SpaceONE’s account auto-sync feature applies differently depending on the Trusted Account’s Scope.

Domain Scope Trusted Account

Trusted Accounts created in the Domain can be created in Admin Mode and can be configured in two ways:

  1. The Organization becomes a single SpaceONE Workspace, enabling synchronization of all underlying projects and accounts.
    Google CloudSpaceONE(Cloudforet)
    OrganizationWorkspace
    FolderProject Group
    ProjectProject
    Service AccountService Account

  1. Top-level Google Cloud Folders can be synchronized as multiple Workspaces. This optimizes performance and management by organizing the management system at the organizational level.
    Google CloudSpaceONE(Cloudforet)
    Top-level FolderWorkspace
    Sub FolderProject Group
    ProjectProject
    Service AccountService Account
💡
For creating Trusted Accounts in Admin Mode, please refer to this guide.

Workspace Scope Trusted Account

For Trusted Accounts created in a Workspace, synchronization applies below the Workspace level.

Google CloudSpaceONE(Cloudforet)
FolderProject Group
ProjectProject
Service AccountService Account