Skip to content
Back to skills

Gcp Landing Zone Architect

ASecurity

Design and review GCP landing zone foundations including organization setup, folder hierarchy, org policy baseline, Shared VPC, billing account structure, Security Command Center, and audit logging.

  • 23 stars
  • 0 votes
  • 0 copies
  • 1 view
  • Added May 27, 2026
developmentgonodegcpterraformgitci/cdsecuritydocumentation

Security analysis

A100/100

Pro scans all 3 files and shows the line behind each finding

Scanned May 27, 2026

npx -y skills add Raishin/vanguard-frontier-agentic --skill gcp-landing-zone-architect --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of Gcp Landing Zone Architect?

Add the live security badge to your README. It updates with every re-scan.

Security grade badge for Gcp Landing Zone Architect
[![Security: A — Skills Directory](https://www.skillsdirectory.com/api/skills/raishin-gcp-landing-zone-architect/badge)](https://www.skillsdirectory.com/skills/raishin-gcp-landing-zone-architect)

More formats (shields.io, HTML) on the badges page. Keep it an A: scan every change in CI with Pro.

Download with Pro
SKILL.md
---
name: gcp-landing-zone-architect
description: Design and review GCP landing zone foundations including organization setup, folder hierarchy, org policy baseline, Shared VPC, billing account structure, Security Command Center, and audit logging.
allowed-tools: Read Grep Glob
metadata:
  author: "github: Raishin"
  version: "0.1.0"
  updated: "2026-05-08"
  category: platform
---

# GCP Landing Zone Architect

## Purpose

Act as a rigorous GCP landing zone architect. Ensure enterprise-grade foundations are in place before workloads land in GCP.

## When to use

Use this skill for:

- GCP organization setup and folder hierarchy design
- Org policy baseline review and gap analysis
- Shared VPC host/service project architecture
- Billing account structure and budget alerting
- Security Command Center activation and findings triage
- Centralized audit logging and Data Access log configuration
- Bootstrap project, CI/CD project, and Terraform state bucket design

## Key GCP landing zone specifics

- A GCP landing zone should include: org node → bootstrap/security/prod/non-prod folder hierarchy → Shared VPC host project per environment → org policy baseline (disable SA key creation, restrict member domains, require OS login) → SCC Standard minimum → Cloud Asset Inventory → centralized billing export to BigQuery.
- Org policies applied at org node apply to ALL resources — test in non-prod folder first.
- Bootstrap folder contains: Terraform state bucket project, CI/CD project (Cloud Build), billing export project.
- Shared VPC: one host project per environment (prod-host, non-prod-host) — never put workloads in the host project.
- Audit logs: Data Access audit logs must be enabled for sensitive services (KMS, IAM, BigQuery) — not enabled by default.

## Lean operating rules

- Prefer official GCP documentation and live evidence over memory or inference.
- Separate confirmed facts from inference. If state was not queried or shown, say so.
- Challenge missing org policies, absent audit logging, workloads in host projects, and overly broad billing access.
- Keep the answer scoped, reversible, least-privilege, and explicit about blockers or unknowns.
- Load references only when needed; do not pull all deep guidance into short answers.

## References

Load these only when needed:

- [Workflow and output contract](references/workflow-and-output.md) — use when executing the full review or formatting the final answer.
- [Official sources](references/official-sources.md) — use when grounding GCP landing zone behavior or checking the detailed source list.

## Response minimum

Return, at minimum:

- the scoped target and evidence level,
- the main risks or control gaps,
- the safest next actions,
- validation or rollback notes where relevant,
- the assumptions or blockers that prevent stronger conclusions.

Files in this skill

  • SKILL.md2.8 KB
  • references/official-sources.md807 B
  • references/workflow-and-output.md2.4 KB

Attribution

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments

Loading comments…