{"product_id":"gcp-landing-zone-architecture-blueprint","title":"GCP Landing Zone Architecture Blueprint","description":"\u003ch3\u003eThe Problem This Blueprint Solves\u003c\/h3\u003e\n\u003cp\u003eYour team chose Google Cloud Platform, but the setup guide from your first sprint left you with a flat project structure, default VPC networks, and primitive IAM bindings at the project level. BigQuery datasets have no access controls beyond project-level roles, and your Compute Engine instances run with default service accounts that have Editor permissions on the entire project. One compromised workload can access everything.\u003c\/p\u003e\n\n\u003cp\u003eThis blueprint is the GCP enterprise foundation I deployed for a media analytics company processing 4.7PB of video metadata monthly across BigQuery, Vertex AI, and GKE — supporting 180 engineers with proper resource isolation and a 97% Security Command Center compliance score.\u003c\/p\u003e\n\n\u003ch3\u003eWhat You Get\u003c\/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\n\u003cstrong\u003eArchitecture diagrams\u003c\/strong\u003e — Organization\/folder\/project hierarchy, Shared VPC topology, Cloud NAT egress path, Private Google Access configuration, and centralized logging with Cloud Logging (Draw.io)\u003c\/li\u003e\n\u003cli\u003e\n\u003cstrong\u003eTerraform modules\u003c\/strong\u003e — Organization structure with folders, project factory for automated project provisioning, Shared VPC host and service projects, custom IAM roles, Organization Policy constraints, and VPC Service Controls perimeter\u003c\/li\u003e\n\u003cli\u003e\n\u003cstrong\u003eSecurity baseline\u003c\/strong\u003e — 45 Organization Policy constraints enforced (disable default networks, restrict public IPs, enforce OS login, disable service account key creation), Security Command Center configuration, and Chronicle SIEM integration\u003c\/li\u003e\n\u003cli\u003e\n\u003cstrong\u003eData governance\u003c\/strong\u003e — BigQuery dataset and table-level IAM, column-level security with policy tags, Data Catalog classification, and DLP API integration for PII detection\u003c\/li\u003e\n\u003c\/ul\u003e\n\n\u003ch3\u003eKey Architecture Decisions\u003c\/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\n\u003cstrong\u003eShared VPC over per-project VPCs\u003c\/strong\u003e — Per-project VPCs create network silos that require VPN or VPC peering for communication. Shared VPC centralizes network management in a host project while granting service projects access to specific subnets. One network team manages IP allocation, firewall rules, and routing for the entire organization.\u003c\/li\u003e\n\u003cli\u003e\n\u003cstrong\u003eVPC Service Controls for data exfiltration prevention\u003c\/strong\u003e — IAM controls who can call an API. VPC Service Controls add where and how — restricting BigQuery access to requests originating from within your VPC perimeter. Even a compromised service account with BigQuery Admin role cannot exfiltrate data to an external project outside the perimeter.\u003c\/li\u003e\n\u003cli\u003e\n\u003cstrong\u003eWorkload Identity Federation over service account keys\u003c\/strong\u003e — Service account keys are the GCP equivalent of permanent credentials — they do not expire, cannot be audited for usage location, and if leaked, grant indefinite access. Workload Identity Federation provides short-lived, automatically rotated credentials for external workloads (GitHub Actions, AWS, on-premises) without distributing secrets.\u003c\/li\u003e\n\u003cli\u003e\n\u003cstrong\u003eOrganization Policy constraints in deny mode\u003c\/strong\u003e — 45 constraints block insecure configurations at the organization level. \u003ccode\u003econstraints\/compute.vmExternalIpAccess\u003c\/code\u003e denies public IPs on all VMs. \u003ccode\u003econstraints\/iam.disableServiceAccountKeyCreation\u003c\/code\u003e prevents anyone from creating long-lived credentials. These are architectural guardrails, not policies that rely on engineer compliance.\u003c\/li\u003e\n\u003c\/ul\u003e\n\n\u003ch3\u003eWho This Blueprint Is For\u003c\/h3\u003e\n\u003cul\u003e\n\u003cli\u003eGCP Cloud Architects building enterprise foundations beyond the quickstart guide\u003c\/li\u003e\n\u003cli\u003ePlatform Engineers designing multi-project structures for growing engineering teams\u003c\/li\u003e\n\u003cli\u003eSecurity Engineers implementing GCP security baselines for compliance requirements\u003c\/li\u003e\n\u003cli\u003eData Engineers who need governance controls around BigQuery datasets containing sensitive data\u003c\/li\u003e\n\u003c\/ul\u003e\n\n\u003ch3\u003eYour First 48 Hours\u003c\/h3\u003e\n\u003cp\u003eDeploy the folder structure and Organization Policy constraints Terraform module into a sandbox organization. Create a test project under the \"Development\" folder and attempt to create a VM with an external IP — the Organization Policy should block it. On day two, deploy the Shared VPC module with one host project and one service project. Create a GKE cluster in the service project using a subnet from the host project. Verify that the cluster pods can reach Private Google Access endpoints without a public IP or Cloud NAT.\u003c\/p\u003e\n\n\u003ch3\u003eLimitations and Trade-offs\u003c\/h3\u003e\n\u003cp\u003eVPC Service Controls add complexity to multi-cloud architectures — external API calls from within a perimeter require access levels and ingress rules that can be difficult to debug. Shared VPC limits service projects to 1,000 per host project. Organization Policies apply to all projects under the org node; exceptions require per-folder or per-project overrides. GCP's IAM model differs from AWS's in that deny policies are a separate feature (IAM Deny Policies) — the blueprint includes these but they are still in GA preview for some resource types.\u003c\/p\u003e","brand":"Citadel Cloud Management","offers":[{"title":"Default Title","offer_id":54890407756067,"sku":"CCM-ARC-003","price":42.0,"currency_code":"USD","in_stock":true}],"thumbnail_url":"\/\/cdn.shopify.com\/s\/files\/1\/0979\/8539\/7027\/files\/citadel-architecture-product_8e1012ac-eefe-4984-b9db-482232e44d59.jpg?v=1775138076","url":"https:\/\/citadel-cloud-management.myshopify.com\/products\/gcp-landing-zone-architecture-blueprint","provider":"Citadel Cloud Management","version":"1.0","type":"link"}