gcp.compute-project

GCP resource: https://cloud.google.com/compute/docs/reference/rest/v1/projects

Filters

metrics

Supports metrics filters on resources.

All resources that have cloud watch metrics are supported.

Docs on cloud watch metrics

- name: firewall-hit-count
  resource: gcp.firewall
  filters:
    - type: metrics
      name: firewallinsights.googleapis.com/subnet/firewall_hit_count
      aligner: ALIGN_COUNT
      days: 14
      value: 1
      op: greater-than

The period-start key allows you to align the metric window in two ways. By default, using auto, the window is computed relative to the current time. Alternatively, setting it to start-of-day aligns the window to full UTC calendar days, beginning at 00:00:00 UTC and ending at current day 00:00:00 UTC.

- name: instance-low-cpu-last-full-day
  resource: gcp.instance
  filters:
    - type: metrics
      name: compute.googleapis.com/instance/cpu/utilization
      aligner: ALIGN_MEAN
      days: 1
      value: 0.05
      op: less-than
      period-start: start-of-day
properties:
  aligner:
    enum:
    - ALIGN_NONE
    - ALIGN_DELTA
    - ALIGN_RATE
    - ALIGN_INTERPOLATE
    - ALIGN_MIN
    - ALIGN_MAX
    - ALIGN_MEAN
    - ALIGN_COUNT
    - ALIGN_SUM
    - REDUCE_COUNT_FALSE
    - ALIGN_STDDEV
    - ALIGN_COUNT_TRUE
    - ALIGN_COUNT_FALSE
    - ALIGN_FRACTION_TRUE
    - ALIGN_PERCENTILE_99
    - ALIGN_PERCENTILE_95
    - ALIGN_PERCENTILE_50
    - ALIGN_PERCENTILE_05
    - ALIGN_PERCENT_CHANG
    type: string
  days:
    type: number
  filter:
    type: string
  group-by-fields:
    items:
      type: string
    type: array
  metric-key:
    type: string
  missing-value:
    type: number
  name:
    type: string
  op:
    enum:
    - eq
    - equal
    - ne
    - not-equal
    - gt
    - greater-than
    - ge
    - gte
    - le
    - lte
    - lt
    - less-than
    - glob
    - regex
    - regex-case
    - in
    - ni
    - not-in
    - contains
    - difference
    - intersect
    - mod
    type: string
  period-start:
    enum:
    - auto
    - start-of-day
    type: string
  reducer:
    enum:
    - REDUCE_NONE
    - REDUCE_MEAN
    - REDUCE_MIN
    - REDUCE_MAX
    - REDUCE_MEAN
    - REDUCE_SUM
    - REDUCE_STDDEV
    - REDUCE_COUNT
    - REDUCE_COUNT_TRUE
    - REDUCE_COUNT_FALSE
    - REDUCE_FRACTION_TRUE
    - REDUCE_PERCENTILE_99
    - REDUCE_PERCENTILE_95
    - REDUCE_PERCENTILE_50
    - REDUCE_PERCENTILE_05
    type: string
  type:
    enum:
    - metrics
  value:
    type: number
required:
- value
- name
- op

Permissions - monitoring.timeSeries.list

Actions

set-common-instance-metadata

Set or remove common instance metadata key/value pairs on a Compute Engine project.

Common instance metadata is inherited by all instances in the project. Existing metadata keys not specified in the action are preserved. The fingerprint of the current metadata is used to prevent concurrent update conflicts.

Both metadata and remove are optional and can be used independently or together in the same action.

example:

Set a common instance metadata key:

policies:
  - name: gcp-project-oslogin-remediate
    resource: gcp.compute-project
    filters:
      - type: value
        key: "commonInstanceMetadata.items[?key=='enable-oslogin'].value | [0]"
        op: ne
        value_type: normalize
        value: "true"
    actions:
      - type: set-common-instance-metadata
        metadata:
          enable-oslogin: "true"

Remove common instance metadata keys without setting any new ones:

policies:
  - name: gcp-project-remove-common-instance-metadata
    resource: gcp.compute-project
    actions:
      - type: set-common-instance-metadata
        remove:
          - key-one
          - key-two
properties:
  metadata:
    additionalProperties:
      type: string
    type: object
  remove:
    items:
      type: string
    type: array
  type:
    enum:
    - set-common-instance-metadata
required:
- type

Permissions - compute.projects.setCommonInstanceMetadata