If you're worried about access, you can establish a service account with Owner level access. Or you can add other Google Accounts to the project. (Here are the docs on that: https://cloud.google.com/iam/docs/overview)
I personally have all my Google stuff separated into 3 accounts (work, personal email, and personal Google-y things). My work account has access to the projects on GCP, along with some coworkers. That puts up enough of a firewall between various services so that if Google throws down the banhammer, it's not totally game over for me.
My understanding from the recent Pixel-orders-account-banning incidents that Google had nuked even marginally related accounts, including gmail accounts whose only relation was being the recovery e-mail for one of the offending accounts. I just read this in one of the articles, so I don't know if it is true, but if so that seems to devalue the possible solution of just linking a number of different Google accounts to your Google Cloud account with owner access to the project. In fact that might be a larger concern if any one of those accounts raises the ire of whatever Google department does the nuking, they might extend the action to all accounts associated through the Google Cloud project. Hopefully not likely, but this stuff worries me.
And it is a telling indictment of the corporate character displayed by Google:
- Exploitable for minor personal convenience ("Use Gmail! Use Gcal! Simple and free!")
- Not to be trusted under any circumstances with important matters ("We can evaporate your existence from the internet for all practical purposes and there's not a damn thing you can do about it.")
Some day, it will become important for us to own our own lives again. And I say this as someone who runs his business on GApps. I'm as guilty as everyone else.
Are you planning to run your own email servers (or any other service that Google provides)? Or just switch to another vendor?
For search and maps, I use Google, for personal hardware, Apple, for cloud servers, AWS, for email, Fastmail on my own domain, and so on.
It is slightly more inconvenient than having one Google account to rule everything, but it helps me at leas feel a bit saner..
But it irks me that I follow the easier, softer way -- knowing that I am causing trouble to myself by doing so.
Eventually, this may be true.
In practice, I believe Sandstorm still requires nontrivial amounts of handholding when updates occur.
I just checked back with them, and they confirmed that I'm entirely mistaken.
Never realized I could do this. Is my understanding correct that Google Cloud won't suspend a project as long as there's a service account associated with it?
A year ago while planning to move from AWS to GCE, I created some instances to test under a company email id. Our emails were hosted under google apps. At some point, the email id got deleted for other reasons. I was in for a rude surprise. The instances disappeared, as I found out when the test urls didn't respond. Apparently, GCE deleted the instances without warning. I was later told by support staff that I should add another admin email to prevent mishaps like this. Seriously.
Anyway, we use GCE these days along with AWS and I quite like GCE. Of course, we now don't delete any email ids :-)
I know this seems harsh, but there's really not a whole lot of other sensible options. The former owner can't be contacted, since the only email we have for them no longer works, and the project is literally unmaintainable, since nobody has admin rights to it anymore.
So TL;DR, for anything remotely important, please assign multiple owners and use role accounts (admin@corp) instead of users (bob@corp).
By far the most common scenario for this to happen is that Bob leaves Corp, and Corp intentionally deletes his account. If Corp has set up billing sensibly, the project will have a central billing account whose admin will be notified, but if Bob signed up on his personal credit card, there is nobody to contact here either.
You have knowledge the account belongs to BAR.COM company, why not contact them? How about a warning to the person deleting the account, telling them that a particular GC service is dependent on it? You know exactly what you plan to delete, after all. How about requiring at least two emails on the GC account so that there is an escape hatch? Can you think of any other ways of preventing this disaster?
Yeah, I get it, the user should have avoided that mistake. People make mistakes, it's the fact of life. You have built a minefield for your customers and left them to sort through the carnage of the explosion.
The alternative implying 100 separate accounts is so much worse.
Issue resolved with a call to a Googler friend :/
Googlers are very active in many forums, including HN, Stack Overflow, mailing lists, and other forums, not just via paid support.
If a customer is having trouble reaching someone at Google regarding Google Cloud Platform issue, I'm sorry to hear that, and would love to hear what was tried and did not work so we can improve the process, but we are listening and paying attention, and happy to hear constructive criticism.
It's definitely NOT the intent that you must personally know someone at Google to resolve an issue with your Google Cloud Platform account.
Sorry to hear you ran into this issue, and glad that it was resolved.
Just curious: did you try any channels of getting in touch with anyone at Google before reaching out to your friend? And if you did, and they did not work, we'd definitely like to know so that we can fix this.
We'd certainly like to make it easy for anyone to resolve issues with their GCP accounts easily, without requiring you to have a friend or acquaintance at Google to help fix this.
For example, if my business email were hosted with G Suite, and my admin G Suite account got suspended for some random reason.
To my knowledge there is nothing preventing an automated banning machine to start firing at random on someone's accounts. And since, it appears, you have absolutely no recourse (except having friends working at google), and they are not held accountable for these "false positives"... You better start planning for it.
Their "Terms of Service" clearly says that the main account and "all related accounts" will be suspended
I finally had to call my rep at AWS and said - you are putting your business with us in jeopardy (On other accounts that we spend significant money on) because its taken me so long to resolve this. Got it unlocked in 24 hours, but the whole thing left a sour taste in my mouth.
I suspect Google WILL have this issue as well, it has the potential to be a huge issue for your business.
Alternatively never had this issue when I've COLO'd - food for thought.
Taking it one step further in precaution (and from experience): We have some servers colo'd at a small datacenter. We use it strictly for our operating website and don't put anything for customers in that data center at all even though it would be convenient and save money. The reason is we don't want any bad actors that we might have as customers potentially impacting our main operations. This is in addition to vetting customers as well actually.
With google, you have to be extremely cautious (no pun intended), especially after they have become big. AWS is far more reliable in this sense, and even Azure may seem better.