Hierarchy giải quyết boundary
GCP hierarchy thường là Organization → Folder → Project → Resource. Organization là root; Folder nhóm project; Project là boundary quan trọng cho API, IAM, quota, resource IDs và billing association. Resource bên dưới kế thừa một phần policy/permission từ ancestor.
Chọn project boundary
Tách prod/nonprod hoặc team khi cần isolation, billing attribution, quota/lifecycle khác nhau. Đừng tạo project cho mọi resource nếu automation/governance overhead không đáng; cũng đừng gom mọi thứ khiến blast radius quá lớn. Ghi owner, billing, APIs, quota, labels, retention và deletion policy.
IAM inheritance
Role ở organization/folder có thể ảnh hưởng rộng; project-level role thường dễ giới hạn hơn. Effective access phải được review theo inheritance, group membership và service account. Labels hỗ trợ cost/inventory nhưng không cấp quyền.
Bài tập
Thiết kế hierarchy cho prod/nonprod của hai team. Chỉ ra billing/quota/IAM scope và một scenario xóa project nhầm. Dùng gcloud read-only để kiểm tra context, sau đó viết cleanup/approval flow cho project lab.