Cloud Monitoring, Alerting & Log Export
A self-contained observability bundle: a metric-threshold alert policy, a Monitoring dashboard, and a log-export sink to a locked-down GCS bucket with the sink writer-identity IAM grant wired in.
Compare Monitoring & Observability across clouds →
Part of: GCP Production Landing Zone
Verification
Live-testedReally deployed to a cloud sandbox, verified against its outputs and assertions, then destroyed - with the teardown confirmed.
Conformance
- Static validation (fmt · validate · tflint)
- Security scan clean (Checkov)
- Plan test superseded by live test
Provenance
- SHA-256 checksum
- Cosign signature
Functional
- Live-tested - applied, verified, destroyed
Last verified 2026-06-30 · how we verify
Verify this download
cosign · sha-256Don't take our word for it. Every release is signed with cosign - check the bytes against our pinned public key before you trust them.
# 1. Our pinned public key - fetch once, trust out-of-band
curl -O https://www.iac-bazaar.com/cosign.pub
# 2. This module's Sigstore bundle
curl -o gcp-monitoring-1.0.0.sigstore.json \
https://www.iac-bazaar.com/api/artifacts/gcp-monitoring/signature
# 3. Verify the tarball you downloaded
cosign verify-blob \
--key cosign.pub \
--bundle gcp-monitoring-1.0.0.sigstore.json \
gcp-monitoring-1.0.0.tar.gz
# → Verified OK
# 4. (optional) confirm the checksum too
echo "59be3463a2b991bc1c62908c23e4c8f3c23de403da4774ae788d6bf66c13247f gcp-monitoring-1.0.0.tar.gz" | sha256sum -cUse it from the registry
terraform · opentofumodule "monitoring" {
source = "www.iac-bazaar.com/iac-bazaar/gcp-monitoring/gcp"
version = "1.0.0"
}Needs a registry token from /account/tokens. The module itself is free; the account is what identifies you. Full setup: registry docs.
Cite it in your README
badge · attributionPaste this beside the module in the repository that uses it. The badge is rendered from this artifact's verification record, so it reads live-tested because the record says so, and the link lands on this page.
[](https://www.iac-bazaar.com/catalog/gcp-monitoring?utm_source=syndication&utm_medium=readme&utm_campaign=artifact)
Terraform module 1.0.0, live-tested on IaC Bazaar: [Cloud Monitoring, Alerting & Log Export](https://www.iac-bazaar.com/catalog/gcp-monitoring?utm_source=syndication&utm_medium=readme&utm_campaign=artifact)
```hcl
module "monitoring" {
source = "www.iac-bazaar.com/iac-bazaar/gcp-monitoring/gcp"
version = "1.0.0"
}
```Preview:
Inputs & outputs
Create a free account to read this module's contract
The declared contract - every input name, type, default and description, plus every output - is shown to signed-in accounts, not to anonymous visitors.
A free account sees the contract of every module in the catalogue. There is no subscription and nothing to buy - the modules are free to download, and they run under Vizier.
Documentation
gcp-monitoring
A standalone Cloud Operations (observability) bundle that applies on its own
with nothing pre-existing: a metric-threshold alert policy, a Cloud
Monitoring dashboard, and a log-export sink that ships matching log
entries to a dedicated, locked-down GCS bucket the module creates. Works with
Terraform and OpenTofu (>= 1.6), Google provider >= 7.0, < 8.0.
The grant hand-rolled sink configs always miss is wired in: the sink runs as its
own unique writer identity, and that identity is granted objectCreator on
the destination bucket — without it the export silently writes nothing. The
bucket has uniform bucket-level access, public-access prevention, and a
lifecycle rule so exported logs age out.
What you get per module call:
- A GCS log-export bucket (UBLA, public access prevented, lifecycle expiry)
- A project log sink with a unique writer identity + the bucket IAM grant
- A metric-threshold alert policy (CPU-utilization by default; fully overridable)
- A dashboard (minimal CPU dashboard by default; supply your own
dashboard_json)
Requirements
| Requirement | Version |
|---|---|
| Terraform / OpenTofu | >= 1.6 |
hashicorp/google | >= 7.0, < 8.0 |
The Monitoring (monitoring.googleapis.com) and Logging
(logging.googleapis.com) APIs must be enabled on the project.
License
Commercial — IaC Bazaar EULA. © IaC Bazaar. Original work (not derived from a third-party module).
Usage code & full reference need an account
The complete copy-paste usage, the full input/output reference, and operational notes are free with an account - shown here and bundled in the download. Sign in and this section fills in.
- Usage
- Inputs
- Outputs
Related modules
gcp-log-sink
Creating a sink creates a service account for it and grants that account nothing, so until it holds a role on the destination every export fails - the sink shows active, the destination stays empty, and the errors are logged into the project that was supposed to be exported. Grants the role with the sink, refuses an empty filter, and can manage _Default retention past 30 days.
gcp-uptime-check
A Cloud Monitoring uptime check from static-address checkers in several regions, over TLS with the certificate validated (off by default), asserting on the body when you give it text, with failures logged, and the alert policy on check_passed that sends to your notification channels. Plain HTTP and a policy with no channels are each accepted by name.
gcp-audit-logging
Data Access logs are off by default for every service but BigQuery, so a project that never turned them on has no record of who read the bucket, queried the table or fetched the secret. Enables all three log types for allServices, narrows per service where read volume is a real cost, and requires a reason for every exempted member - the setting an intruder with IAM rights would add.
gcp-vpc-flow-logs
VPC Flow Logs configs through the Network Management API, one per network, subnet, VPN tunnel or Interconnect attachment. A config for a target that does not exist is accepted and logs nothing, so a check block warns on it. Filters and sampling are reported by name, and the defaults stay Google's most complete: every flow, 5-second aggregation, all metadata.
oci-monitoring-alarms
An email subscription delivers nothing until somebody clicks its confirmation link, and until then every alarm publishes to a subscriber who is not there; repeat_notification_duration is null by default, so an alarm fires once at 3am and is never mentioned again. Creates the topic, subscriptions and alarms together, repeats while firing, and lists the subscriptions still waiting on a click.
do-monitoring
An alert policy with no email and no Slack webhook is valid, evaluated and triggers to nobody; CPU, memory and disk metrics exist only where the agent runs; and an uptime check without its alert resource is a status page. A recipient required, CPU/memory/disk defaults by tag, the agent-dependent alerts listed, and a down alert plus optional latency and certificate-expiry alerts on every check.