Google CloudLive-testedattested

Cloud Monitoring, Alerting & Log Export

A self-contained observability bundle: a metric-threshold alert policy, a Monitoring dashboard, and a log-export sink to a locked-down GCS bucket with the sink writer-identity IAM grant wired in.

terraformGoogle Cloudgcp

Compare Monitoring & Observability across clouds →

Part of: GCP Production Landing Zone

gcp-monitoringvizier v1.2.0

Verification

Live-tested

Really deployed to a cloud sandbox, verified against its outputs and assertions, then destroyed - with the teardown confirmed.

Conformance

  • Static validation (fmt · validate · tflint)
  • Security scan clean (Checkov)
  • Plan test superseded by live test

Provenance

Functional

  • Live-tested - applied, verified, destroyed

Last verified 2026-06-30 · how we verify

Verify this download

cosign · sha-256

Don't take our word for it. Every release is signed with cosign - check the bytes against our pinned public key before you trust them.

# 1. Our pinned public key - fetch once, trust out-of-band
curl -O https://www.iac-bazaar.com/cosign.pub

# 2. This module's Sigstore bundle
curl -o gcp-monitoring-1.0.0.sigstore.json \
  https://www.iac-bazaar.com/api/artifacts/gcp-monitoring/signature

# 3. Verify the tarball you downloaded
cosign verify-blob \
  --key cosign.pub \
  --bundle gcp-monitoring-1.0.0.sigstore.json \
  gcp-monitoring-1.0.0.tar.gz
# → Verified OK

# 4. (optional) confirm the checksum too
echo "59be3463a2b991bc1c62908c23e4c8f3c23de403da4774ae788d6bf66c13247f  gcp-monitoring-1.0.0.tar.gz" | sha256sum -c

Use it from the registry

terraform · opentofu
module "monitoring" {
  source  = "www.iac-bazaar.com/iac-bazaar/gcp-monitoring/gcp"
  version = "1.0.0"
}

Needs a registry token from /account/tokens. The module itself is free; the account is what identifies you. Full setup: registry docs.

Cite it in your README

badge · attribution

Paste this beside the module in the repository that uses it. The badge is rendered from this artifact's verification record, so it reads live-tested because the record says so, and the link lands on this page.

README.md, GitLab, Gitea
[![IaC Bazaar: live-tested](https://www.iac-bazaar.com/api/artifacts/gcp-monitoring/badge)](https://www.iac-bazaar.com/catalog/gcp-monitoring?utm_source=syndication&utm_medium=readme&utm_campaign=artifact)

Terraform module 1.0.0, live-tested on IaC Bazaar: [Cloud Monitoring, Alerting & Log Export](https://www.iac-bazaar.com/catalog/gcp-monitoring?utm_source=syndication&utm_medium=readme&utm_campaign=artifact)

```hcl
module "monitoring" {
  source  = "www.iac-bazaar.com/iac-bazaar/gcp-monitoring/gcp"
  version = "1.0.0"
}
```

Preview:IaC Bazaar: live-tested

Inputs & outputs

Create a free account to read this module's contract

The declared contract - every input name, type, default and description, plus every output - is shown to signed-in accounts, not to anonymous visitors.

A free account sees the contract of every module in the catalogue. There is no subscription and nothing to buy - the modules are free to download, and they run under Vizier.

Documentation

gcp-monitoring

A standalone Cloud Operations (observability) bundle that applies on its own with nothing pre-existing: a metric-threshold alert policy, a Cloud Monitoring dashboard, and a log-export sink that ships matching log entries to a dedicated, locked-down GCS bucket the module creates. Works with Terraform and OpenTofu (>= 1.6), Google provider >= 7.0, < 8.0.

The grant hand-rolled sink configs always miss is wired in: the sink runs as its own unique writer identity, and that identity is granted objectCreator on the destination bucket — without it the export silently writes nothing. The bucket has uniform bucket-level access, public-access prevention, and a lifecycle rule so exported logs age out.

What you get per module call:

  • A GCS log-export bucket (UBLA, public access prevented, lifecycle expiry)
  • A project log sink with a unique writer identity + the bucket IAM grant
  • A metric-threshold alert policy (CPU-utilization by default; fully overridable)
  • A dashboard (minimal CPU dashboard by default; supply your own dashboard_json)

Requirements

RequirementVersion
Terraform / OpenTofu>= 1.6
hashicorp/google>= 7.0, < 8.0

The Monitoring (monitoring.googleapis.com) and Logging (logging.googleapis.com) APIs must be enabled on the project.

License

Commercial — IaC Bazaar EULA. © IaC Bazaar. Original work (not derived from a third-party module).

Usage code & full reference need an account

The complete copy-paste usage, the full input/output reference, and operational notes are free with an account - shown here and bundled in the download. Sign in and this section fills in.

  • Usage
  • Inputs
  • Outputs

Related modules

Static validatedLive test pending

gcp-log-sink

Creating a sink creates a service account for it and grants that account nothing, so until it holds a role on the destination every export fails - the sink shows active, the destination stays empty, and the errors are logged into the project that was supposed to be exported. Grants the role with the sink, refuses an empty filter, and can manage _Default retention past 30 days.

View module
Static validatedLive test pending

gcp-uptime-check

A Cloud Monitoring uptime check from static-address checkers in several regions, over TLS with the certificate validated (off by default), asserting on the body when you give it text, with failures logged, and the alert policy on check_passed that sends to your notification channels. Plain HTTP and a policy with no channels are each accepted by name.

View module
Static validatedLive test pending

gcp-audit-logging

Data Access logs are off by default for every service but BigQuery, so a project that never turned them on has no record of who read the bucket, queried the table or fetched the secret. Enables all three log types for allServices, narrows per service where read volume is a real cost, and requires a reason for every exempted member - the setting an intruder with IAM rights would add.

View module
Static validatedLive test pending

gcp-vpc-flow-logs

VPC Flow Logs configs through the Network Management API, one per network, subnet, VPN tunnel or Interconnect attachment. A config for a target that does not exist is accepted and logs nothing, so a check block warns on it. Filters and sampling are reported by name, and the defaults stay Google's most complete: every flow, 5-second aggregation, all metadata.

View module
Static validatedLive test pending

oci-monitoring-alarms

An email subscription delivers nothing until somebody clicks its confirmation link, and until then every alarm publishes to a subscriber who is not there; repeat_notification_duration is null by default, so an alarm fires once at 3am and is never mentioned again. Creates the topic, subscriptions and alarms together, repeats while firing, and lists the subscriptions still waiting on a click.

View module
Static validatedLive test pending

do-monitoring

An alert policy with no email and no Slack webhook is valid, evaluated and triggers to nobody; CPU, memory and disk metrics exist only where the agent runs; and an uptime check without its alert resource is a status page. A recipient required, CPU/memory/disk defaults by tag, the agent-dependent alerts listed, and a down alert plus optional latency and certificate-expiry alerts on every check.

View module