GCP deployment guide

Overview
Glean provides customers the ability to deploy Glean software inside their own Google Cloud Platform (GCP) project. This deployment requires your GCP admin to:
- Create a new GCP project.
- Associate a valid billing account.
- Review the organization policies required for Glean's deployment.
- Create a Service Account with Project Owner role and associate a JSON account key.
- Notify Glean of the GCP zone selected, the Project Name, Project ID, Project Number, and the service account JSON key.
After completing the above, Glean's systems will automatically build and deploy the required compute, workflows, and software into your GCP project.
At this stage, Glean will advise you that your tenant is ready; allowing your admins to proceed with the setup process in our Getting Started guide.
This document will cover the steps required by your GCP admins to prepare a GCP project that is ready for your Glean build.
Prerequisites
Before you begin, make sure you have a GCP project, an associated billing account, and access to the GCP settings needed to enable APIs and request quota increases.
1. Select a GCP region
You must first select a supported GCP region for Glean to build your environment in.
- More information: Supported GCP Regions
You must notify Glean of the GCP zone selected, for example, asia-northeast1-a
The region selected cannot be changed once your tenant has been built. Changing region will require a complete rebuild of your tenant.
2. Create the GCP project
-
Go to the Manage resources page in the GCP console and click Create Project.
-
In the New Project window that appears, add a project name, organization, and location.
- For the project name, the preferred format is
glean-{customer name}orglean-{customer name}-{prod/sandbox} - For example,
glean-companyorglean-company-prod
- For the project name, the preferred format is
-
Make sure that your project is created under the same organization as your Google Workplace account, and not "No Organization".
Glean is not able to proceed with the build if the project is created under "No Organization". If you are unsure of how to resolve this, please contact your GCP account team or GCP support.
-
Save the Project ID (which is directly below the Project name) and Project Number.
-
Click Create.
-
Notify Glean of the following information:
a. Project name, eg
glean-company→ This was set in Step 2 above.b. Project ID, eg
glean-company→ This was saved in Step 4 above.c. Project number, eg
715000000000→ This was saved in Step 4 above.d. Region and Zone where you want to deploy Glean, for example,
us-central1-a
3. Configure billing
-
Go to Billing in the GCP console.
-
Click Link a billing account to set up billing for this project.
Ensure that the billing account has a corporate credit card attached to it. Using the "free trial billing tier" will not work.
4. Review organization policies
Organization policies can prevent Glean's project setup from creating resources or granting required permissions. Review these policies with your organization administrator before setup. The project setup script manages the policies listed below. After setup completes, you can restore policies marked Yes only after confirming that the deployment succeeds. Restoring a policy can block future deployments or changes.
For more information, see Google Cloud organization policy constraints.
Policies with hard requirements
The following policies are hard requirements in the deployment configuration. The Restore after setup? column reflects the can_be_restored_after_setup setting; do not restore policies marked No after setup.
| Constraint | Required setting | Restore after setup? | Why Glean needs it |
|---|---|---|---|
cloudfunctions.allowedIngressSettings | Allow ALLOW_ALL, ALLOW_INTERNAL_AND_GCLB, or ALLOW_INTERNAL_ONLY. | No | Glean's Continuous Deployment project invokes the deploy_build Cloud Function for weekly releases. |
cloudfunctions.allowedVpcConnectorEgressSettings | Allow ALL_TRAFFIC. | No | Glean's deploy_build Cloud Function invokes Cloud Run services with open egress. |
compute.requireOsLogin | Set enforce to false. | Yes | Glean must update virtual machine metadata during setup. |
compute.restrictNonConfidentialComputing | Set allowAll to true. | No | Glean does not currently use Confidential Computing virtual machines. |
compute.disableGlobalCloudArmorPolicy | Set enforce to false. | No | Glean's security policies are global policies. |
iam.managed.disableServiceAccountKeyCreation | Set enforce to false. | Yes | Setup requires a google-tools service-account key. |
compute.restrictVpcPeering | Allow peering with folders/832634261155 and folders/391150242170. | Yes | Glean uses Google-managed Cloud SQL and Google Kubernetes Engine services that require private peering with Google's private API services. |
compute.restrictVpnPeerIPs | Set allowAll to true. | Yes | The deployment flow creates a deployment VPC and peers it with the default VPC using a VPN tunnel. |
compute.restrictLoadBalancerCreationForTypes | Allow EXTERNAL_HTTP_HTTPS and INTERNAL_HTTP_HTTPS. | Yes | Glean uses both external and internal HTTP/HTTPS load balancers. |
compute.trustedImageProjects | Allow images from projects/cloud-dataflow, projects/cloudsql-docker, projects/cos-cloud, projects/serverless-vpc-access-images, and projects/scio-engineering. | No | Glean services use images from these projects. |
gcp.resourceLocations | Allow {{PRIMARY_MULTI_REGION}}, {{PRIMARY_REGION}}, and {{SECONDARY_REGION}}. | Yes | Glean creates resources in the primary and secondary regions for multi-region deployments. If the primary region is us-central1, also allow us-central2 because Cloud Tasks requires both regions, even when queues are created only in us-central1. |
iam.allowedPolicyMemberDomains | Allow the Glean domain ID C00vrnlo8. | Yes | Setup grants selected read-only permissions to Glean's monitoring and support group. |
iam.disableServiceAccountKeyCreation | Set enforce to false. | No | Setup creates deployer and OpenSearch service-account keys and rotates them every 90 days. |
iam.disableWorkloadIdentityClusterCreation | Set enforce to false. | No | Glean's Google Kubernetes Engine cluster requires Workload Identity. |
compute.restrictCloudNATUsage | Allow ALLOW_ALL. | No | Glean uses Cloud NAT to access the internet. |
run.allowedIngress | Allow ALLOW_ALL, ALLOW_INTERNAL_AND_GCLB, or ALLOW_INTERNAL_ONLY. | No | Glean's Continuous Deployment project invokes the deploy_build Cloud Function for weekly releases. |
run.allowedVPCEgress | Allow ALL_TRAFFIC. | No | Glean's deploy_build Cloud Function invokes Cloud Run services with open egress. |
cloudbuild.allowedWorkerPools | Allow ALLOW_ALL. | No | Glean's Cloud Functions builds require worker pools. |
compute.disablePrivateServiceConnectCreationForConsumers | Allow GOOGLE_APIS and SERVICE_PRODUCERS. | No | Glean needs to create Private Service Connect endpoints. |
5. Create a service account
The service account is used to allow Glean's systems to access the project and perform the build. You will create the service account and provide Glean with the private JSON key required to use it.
-
Go to the Service Accounts page in the GCP console and click Select a Project.
-
Click Create Service Account. Enter the service account name (
glean-admin), ID, and description (optional), then click Create. -
Click the Select a role dropdown to make your service account an Owner of the project. Click Continue.
-
Ignore the Grant users access to this service account option. It is not required.
-
Click Create Key. In the panel that appears, select the key type JSON, then Create. This will save a private JSON key to your computer.
6. Upload the service account key to the Glean Admin console
-
If you haven't already, follow the instructions from the Access the Admin console section of the Getting Started guide.
- Browse to https://app.glean.com/admin
- Enter your email to receive a link via email to sign in.
-
On the page titled Create a Google Cloud Platform project, click the box under Step 2 to upload the private JSON key to Glean.
-
Click Save. Glean will now use the JSON key to validate that all the steps above have been performed correctly.
If the save is successful, your Glean tenant is ready to be built. Contact your Glean account team to proceed.
If the save fails, you will be presented with a red error message detailing the issues to correct. The key must be saved correctly before the build of your Glean tenant can proceed.
Troubleshooting
For Error Codes and troubleshooting steps, please see the Troubleshooting section.