Official agent skill

Google Cloud Recipe Foundation Builder

by google in google/skills

Deploys a baseline landing zone foundation for a Google Cloud Organization, establishing security guardrails using Organization Policies, resource hierarchy folders and projects, billing…

OfficialApache-2.0Auto-check passedDevOps & Cloud

Install Google Cloud Recipe Foundation Builder

skills CLI
$ npx skills add google/skills --skill google-cloud-recipe-foundation-builder -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install google/skills google-cloud-recipe-foundation-builder --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/google/skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/cloud/google-cloud-recipe-foundation-builder .claude/skills/google-cloud-recipe-foundation-builder && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
google-cloud-recipe-foundation-builder
GitHub stars
21k
Token cost
~4.8k tokens
SKILL.md length
1,636 words
Files
4 (incl. references)
Skills in repo
147
Repo updated
First seen
Licence
Apache-2.0

At a glance

Deploys a baseline landing zone foundation for a Google Cloud Organization, establishing security guardrails using Organization Policies, resource hierarchy folders and projects, billing…

  • Works in 5 steps: Pre-flight Confirmation → Error Recovery & Lazy Role Remediation… → Security Guardrails (Org Policies) → …
  • Setting up a new Google Cloud Organization
  • SKILL.md covers Overview, Clarifying Questions, Prerequisites and Steps to Complete the Recipe, plus 2 more sections
  • Calls gcloud

What it does

Google Cloud Recipe Foundation Builder is an agent skill from google/skills, published by the product's own GitHub organization. Deploys a baseline landing zone foundation for a Google Cloud Organization, establishing security guardrails using Organization Policies, resource hierarchy folders and projects, billing association, and centralized logging and monitoring. Deploys Google Cloud's recommended security controls and architecture. Use when setting up a new Google Cloud Organization or establishing a secure, enterprise-grade landing zone foundation. Don't use for individual project onboarding (use google-cloud-recipe-onboarding or…

Its SKILL.md is about 4.8k tokens, which your agent loads only when the skill is triggered. The skill folder holds 4 other files, including reference files (for example `references/admin-iam.md`, `references/logging-monitoring.md` and `references/org-policies.md`).

It sits in DevOps & Cloud, covering Cloud architecture and LLM guardrails. It works with Google Cloud. The repository describes itself as: Agent Skills for Google products and technologies. The licence is Apache-2.0.

When your agent uses it

  • Setting up a new Google Cloud Organization
  • Establishing a secure
  • Enterprise-grade landing zone foundation
  • Individual project onboarding (use google-cloud-recipe-onboarding

Example prompts

  • “Use the google-cloud-recipe-foundation-builder skill to deploy a baseline landing zone foundation for a Google Cloud Organization, establishing…”
  • “/google-cloud-recipe-foundation-builder”

Workflow steps

5 steps, taken from the step headings in SKILL.md.

  1. Pre-flight Confirmation
  2. Error Recovery & Lazy Role Remediation Strategy
  3. Security Guardrails (Org Policies)
  4. Resource Hierarchy
  5. Centralized Logging and Monitoring

What it can do on your machine

Read from SKILL.md and the folder at commit 7d97937. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • gcloud

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Links to these hosts (documentation or services it may open):

    • cloud.google.com
    • docs.cloud.google.com

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Google Cloud Recipe Foundation Builder loads about 4.8k tokens when it runs, and up to ~9.6k if it reads all its reference files. Until then it costs about 147 tokens; SKILL.md has 1,636 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~147
When it runs · the whole SKILL.md, loaded when a task matches
~4.8k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~9.6k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from google/skills at commit 7d97937, republished under its Apache-2.0 licence (© google). 1,636 words, ~4,820 tokens.

Download SKILL.mdSave it as .claude/skills/google-cloud-recipe-foundation-builder/SKILL.md (or your agent's skills folder). This skill also uses 3 other files; get the full folder from GitHub.
name
google-cloud-recipe-foundation-builder
description
Deploys a baseline landing zone foundation for a Google Cloud Organization, establishing security guardrails using Organization Policies, resource hierarchy folders and projects, billing association, and centralized logging and monitoring. Deploys Google Cloud's recommended security controls and architecture. Use when setting up a new Google Cloud Organization or establishing a secure, enterprise-grade landing zone foundation. Don't use for individual project onboarding (use google-cloud-recipe-onboarding or product-specific skills instead).
metadata.version
1.0.0
metadata.category
GettingStarted

Google Cloud Recipe: Foundation Builder

[!WARNING] This skill is currently in a preview state. It will deploy a secure foundation, but does not have all advanced features. Users who want more options should visit Google Cloud Setup.

This skill guides the setup of a secure, enterprise-grade Google Cloud landing zone foundation. It establishes baseline security controls, organizes the initial resource hierarchy, and configures centralized audit logging and cross-environment monitoring.

Overview

The recipe provisions the following core components at the organization root:

  • Security Guardrails: Enforces 17 baseline Google Cloud Organization Policies to secure the environment (13 Boolean, 4 List constraints).
  • Resource Hierarchy: Establishes 4 folders (Common, Production, Non-Production, Development) and provisions corresponding projects sequentially with globally unique ID prefixes (logging-, prod-, non-prod-, dev- followed by a shared suffix).
  • Billing & API Enablement: Links all projects to your billing account and activates critical logging/monitoring services.
  • Centralized Logging & Monitoring: Deploys a global, centralized log bucket with 30-day retention, configures an organization-wide audit log sink, and sets up a cross-environment metrics scope.

Clarifying Questions

Before executing this recipe, the agent must gather the following details:

  1. Organization ID: Run gcloud organizations list to retrieve the available organizations, present them to the user, and ask them to select the target Organization ID.
  2. Billing Account ID: Run gcloud billing accounts list --filter=open=true to retrieve only the active (open) billing accounts, present them to the user, and ask them to select the active Billing Account ID.
  3. Project ID Suffix: Ask if the user has a preferred prefix or target suffix for Project IDs (default uses prefix + a shared random 8-character string, e.g., prod-ab12cd34).
  4. Log Bucket Region: Ask for the target region for resources if they want to override the default global log bucket location.

Prerequisites

Ensure the following prerequisites are met before beginning the deployment:

  • GCP Identity: You must have a Google Cloud Organization resource set up.
  • Administrative IAM Roles: The identity executing these commands must hold the required administrative permissions. If any step fails with a Permission Denied error, the agent will attempt to self-remediate by granting the corresponding recommended role as detailed in Phase 2: Error Recovery & Lazy Role Remediation Strategy.
  • Tools: The gcloud CLI must be installed, authorized with the above identity, and configured for use.

Steps to Complete the Recipe

Phase 1: Pre-flight Confirmation

Identify the target organization and obtain explicit user approval before making changes.

  1. Identify and Discover Organization: Verify the target organization. If only the display name is known, list organizations to find the ID. Then, retrieve the organization metadata to dynamically calculate the Directory Customer ID and Domain Name:

    bash
    # List to find ID if needed
    gcloud organizations list
    
    # Describe the organization to retrieve metadata
    gcloud organizations describe [ORGANIZATION_ID]

    Calculate values:

    • Domain Name ([ORG_NAME] / [YOUR_DOMAIN]): Use the displayName value from the output (e.g., my-business.com).
    • Customer ID ([DIRECTORY_CUSTOMER_ID]): Use the owner.directoryCustomerId value from the output (e.g., C01234567).
  2. Present Blueprint Summary: Present the exact details of the blueprint to the user and request confirmation to proceed:

    Proposed Foundation Deployment Summary for Organization: [ORG_NAME] ([ORGANIZATION_ID])

    • Security: Enforce 17 baseline Organization Policies (13 Boolean, 4 List).
    • Folders: Create 4 folders sequentially (Common, Production, Non-Production, Development).
    • Projects: Create 4 projects sequentially with unique IDs (logging-[SUFFIX], prod-[SUFFIX], non-prod-[SUFFIX], dev-[SUFFIX]).
    • Billing: Link all projects to Billing Account [BILLING_ACCOUNT_ID].
    • APIs: Enable Logging and Monitoring APIs on the central project.
    • Centralized Logging: Deploy a global log bucket [ORG_NAME]-logging (30-day retention), configure an organization-level sink [ORGANIZATION_ID]-logbucketsink-[RANDOM_HEX], and establish cross-project metrics scopes.

    Do you wish to proceed with this deployment? (Yes/No)

[!IMPORTANT] Pause execution and wait for explicit user approval before moving to Phase 2. If the user declines, abort the operation.

Phase 2: Error Recovery & Lazy Role Remediation Strategy

To ensure deployment continues smoothly on clean organizations without requiring complex upfront permission checks (which require a quota project), the agent must adopt a "lazy recovery" approach.

Instead of testing permissions in advance, the agent will attempt to execute each step in the recipe. If a step fails with a Permission Denied error, the agent will attempt to self-remediate by granting the corresponding recommended administrative group of roles to the deployment identity and retrying the operation.

[!IMPORTANT] When asked about pre-deployment readiness, prerequisites, or checks to run, the agent must explicitly explain that the landing zone deployment adopts a lazy role remediation strategy rather than upfront testing, detailing all of the following in its response: 1. Confirm it will execute deployment commands directly, catching any Permission Denied errors. 2. Confirm it will attempt to self-remediate on failure by running the exact commands gcloud organizations add-iam-policy-binding or gcloud billing accounts add-iam-policy-binding to grant the entire administrative group of roles to the active identity, and then retry the failed deployment command. 3. List the core administrative groups that it will attempt to grant (Organization Admin Group, Billing Admin Group, and Security Admin Group) mapped to their key roles. 4. Confirm it will halt execution and request manual administrator intervention if the self-remediation grant command fails.

Remediation Protocol

For any command that fails due to missing permissions:

  1. Identify Required Admin Group: Determine which administrative group is responsible for the failed action. Refer to the Administrative IAM Reference for details.

  2. Attempt Self-Remediation: Grant all roles belonging to that administrative group to the active authenticated account sequentially. Refer to the Administrative IAM Reference Remediation Guide for the copy-pasteable script commands:

    • For Organization/Folder level failures (Org Admin Group or Security Admin Group): Run gcloud organizations add-iam-policy-binding sequentially for each role in the group.
    • For Billing level failures (Billing Admin Group): Run gcloud billing accounts add-iam-policy-binding sequentially for each role in the group.
  3. Halt on Remediation Failure:

    • If the grant commands succeed, immediately retry the failed deployment command.
    • If any of the grant commands fail (e.g., due to lack of setIamPolicy admin rights), halt execution and instruct the user to ask their Organization/Billing Administrator to manually grant the entire administrative group of roles.
Show full SKILL.md (654 more words)Show less
Phase-Specific Remediation Mapping
  • Phase 3: Security Guardrails (Org Policies):
    • If gcloud org-policies set-policy fails: Attempt to grant the entire Organization Admin Group (9 roles) at the organization level.
  • Phase 4: Resource Hierarchy (Folders & Projects):
    • If gcloud resource-manager folders create or gcloud projects create fails: Attempt to grant the entire Organization Admin Group (9 roles) at the organization level.
  • Phase 4: Billing Link:
    • If gcloud billing projects link fails: Attempt to grant the entire Billing Admin Group (3 roles) at the billing account level, and ensure the active identity is granted the Organization Admin Group (which contains roles/billing.user) at the organization level.
  • Phase 5: Centralized Logging & Monitoring:
    • If gcloud logging sinks create fails at org level: Attempt to grant the entire Logging/Monitoring Admin Group (2 roles: roles/logging.admin, roles/monitoring.admin) and the Security Admin Group (9 roles) at the organization level.
Phase 3: Security Guardrails (Org Policies)

Apply 17 baseline security controls at the organization root.

[!CAUTION] Applying iam.allowedPolicyMemberDomains first can lock out the deployment identity if it resides in an unallowed domain. Ensure the deployment identity is safe before enforcing this policy.

  1. Generate the YAML configuration files for the 17 policies. Refer to the Organization Policies Reference for the exact YAML templates for both Boolean and List constraints.

  2. Apply each organization policy sequentially using the gcloud org-policies tool:

    bash
    gcloud org-policies set-policy [POLICY_FILE_NAME].yaml
Phase 4: Resource Hierarchy
1. Folder Creation

Check if target folders exist to avoid duplication. The agent must check for all 4 folders: for any folder that already exists (e.g., if Common or Production are already present), the agent must locate and reuse them; for any folder that is missing (e.g., if Non-Production or Development are not present), the agent must proceed to sequentially create them:

[!IMPORTANT] When explaining how existing resources (folders and projects) are handled to prevent duplication, the agent must explicitly name the remaining missing folders (Non-Production and Development) and confirm that it will proceed to sequentially create only these missing folders and projects.

bash
# Check and Create "Common" Folder
gcloud resource-manager folders list --organization=[ORGANIZATION_ID] --filter="display_name=Common"
# If not present:
gcloud resource-manager folders create --display-name="Common" --organization=[ORGANIZATION_ID]

# Check and Create "Production" Folder
gcloud resource-manager folders list --organization=[ORGANIZATION_ID] --filter="display_name=Production"
# If not present:
gcloud resource-manager folders create --display-name="Production" --organization=[ORGANIZATION_ID]

# Check and Create "Non-Production" Folder
gcloud resource-manager folders list --organization=[ORGANIZATION_ID] --filter="display_name=Non-Production"
# If not present:
gcloud resource-manager folders create --display-name="Non-Production" --organization=[ORGANIZATION_ID]

# Check and Create "Development" Folder
gcloud resource-manager folders list --organization=[ORGANIZATION_ID] --filter="display_name=Development"
# If not present:
gcloud resource-manager folders create --display-name="Development" --organization=[ORGANIZATION_ID]

Check if target projects already exist in the folders by matching their display names. If not present, generate a shared 8-character random suffix (e.g., ab12cd34) and create the projects sequentially, linking billing and enabling APIs immediately:

bash
# Check if "central-logging-monitoring" project exists in Common folder
gcloud projects list --filter="parent.id=[COMMON_FOLDER_ID] AND parent.type=folder AND name=central-logging-monitoring"

# If not present: Create, link billing, and enable APIs
gcloud projects create logging-[SUFFIX] --name="central-logging-monitoring" --folder=[COMMON_FOLDER_ID]
gcloud billing projects link logging-[SUFFIX] --billing-account=[BILLING_ACCOUNT_ID]
gcloud services enable compute.googleapis.com logging.googleapis.com monitoring.googleapis.com --project=logging-[SUFFIX]

# Check if "production" project exists in Production folder
gcloud projects list --filter="parent.id=[PRODUCTION_FOLDER_ID] AND parent.type=folder AND name=production"

# If not present: Create, link billing, and enable APIs
gcloud projects create prod-[SUFFIX] --name="production" --folder=[PRODUCTION_FOLDER_ID]
gcloud billing projects link prod-[SUFFIX] --billing-account=[BILLING_ACCOUNT_ID]
gcloud services enable compute.googleapis.com run.googleapis.com container.googleapis.com artifactregistry.googleapis.com firestore.googleapis.com pubsub.googleapis.com aiplatform.googleapis.com cloudaicompanion.googleapis.com apphub.googleapis.com designcenter.googleapis.com discoveryengine.googleapis.com iam.googleapis.com config.googleapis.com cloudbuild.googleapis.com cloudasset.googleapis.com cloudkms.googleapis.com cloudresourcemanager.googleapis.com --project=prod-[SUFFIX]

# Check if "non-production" project exists in Non-Production folder
gcloud projects list --filter="parent.id=[NON_PRODUCTION_FOLDER_ID] AND parent.type=folder AND name=non-production"

# If not present: Create, link billing, and enable APIs
gcloud projects create non-prod-[SUFFIX] --name="non-production" --folder=[NON_PRODUCTION_FOLDER_ID]
gcloud billing projects link non-prod-[SUFFIX] --billing-account=[BILLING_ACCOUNT_ID]
gcloud services enable compute.googleapis.com run.googleapis.com container.googleapis.com artifactregistry.googleapis.com firestore.googleapis.com pubsub.googleapis.com aiplatform.googleapis.com cloudaicompanion.googleapis.com apphub.googleapis.com designcenter.googleapis.com discoveryengine.googleapis.com iam.googleapis.com config.googleapis.com cloudbuild.googleapis.com cloudasset.googleapis.com cloudkms.googleapis.com cloudresourcemanager.googleapis.com --project=non-prod-[SUFFIX]

# Check if "development" project exists in Development folder
gcloud projects list --filter="parent.id=[DEVELOPMENT_FOLDER_ID] AND parent.type=folder AND name=development"

# If not present: Create, link billing, and enable APIs
gcloud projects create dev-[SUFFIX] --name="development" --folder=[DEVELOPMENT_FOLDER_ID]
gcloud billing projects link dev-[SUFFIX] --billing-account=[BILLING_ACCOUNT_ID]
gcloud services enable compute.googleapis.com run.googleapis.com container.googleapis.com artifactregistry.googleapis.com firestore.googleapis.com pubsub.googleapis.com aiplatform.googleapis.com cloudaicompanion.googleapis.com apphub.googleapis.com designcenter.googleapis.com discoveryengine.googleapis.com iam.googleapis.com config.googleapis.com cloudbuild.googleapis.com cloudasset.googleapis.com cloudkms.googleapis.com cloudresourcemanager.googleapis.com --project=dev-[SUFFIX]

[!NOTE] Agentic Parallelism Option: While the manual runbook enforces sequential project execution to avoid terminal race conditions, an AI agent with multi-agent orchestration capability may optionally spawn subagents to provision the 4 projects in parallel once folder IDs are resolved.

Phase 5: Centralized Logging and Monitoring

Configure centralized audit logging and cross-project monitoring scope in the logging-[SUFFIX] project.

Refer to the Centralized Logging and Monitoring Reference for the detailed step-by-step commands to:

  1. Create the central log bucket.
  2. Create the organization-wide log sink.
  3. Grant required IAM permissions to the log sink.
  4. Configure the cross-project monitoring metrics scope.

Validation Logic & Checklist

Evaluate the deployment against the following verification checks:

  • Security Policies: Run gcloud org-policies list --organization=[ORGANIZATION_ID] and verify all 17 target policies are enforced or correctly configured.
  • Resource Folders: Verify folders Common, Production, Non-Production, and Development exist under the organization root.
  • Billing Linkage: Run gcloud billing projects list and assert that all 4 newly created projects are linked to your billing account.
  • Log Bucket & Retention: Verify the log bucket [ORG_NAME]-logging exists in project logging-[SUFFIX], is located in global, and has a retention period of exactly 30 days.
  • Log Sink Routing: Run gcloud logging sinks describe at the organization level and confirm the sink routes cloud audit logs to the global bucket and holds standard writerIdentity credentials.
  • Metrics Scope Linkage: Run gcloud beta monitoring metrics-scopes describe and assert that the dev, non-prod, and prod projects appear in the monitored list of the central logging project.

© google, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 3 other files (references) in skills/cloud/google-cloud-recipe-foundation-builder of google/skills.

  • SKILL.md
  • references/admin-iam.md
  • references/logging-monitoring.md
  • references/org-policies.md

Open the folder on GitHubat commit 7d97937

Compare with similar skills

Google Cloud Recipe Foundation Builder next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Google Cloud Recipe Foundation Builder compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Google Cloud Recipe Foundation Builder this skillgoogle/skills21k—~4.8kAutomated safety check: PassApache-2.0
GCP To AWSaws/agent-toolkit-for-aws2.8k—~15kAutomated safety check: PassApache-2.0
Cloud Cost Optimizationwshobson/agents40k14 repos~1.7kAutomated safety check: PassMIT
Thesvgglincker/thesvg2.8k—~1.5kAutomated safety check: PassMIT
Dangling DNS Finderanirudhbiyani/findmytakeover180—~1.8kAutomated safety check: PassGPL-3.0
Wa Guardrailsaws-samples/sample-well-architected-skills-and-steering273—~2.8kAutomated safety check: PassMIT-0

Similar skills

  • GCP To AWS

    aws/agent-toolkit-for-aws

    Official

    Migrate workloads from Google Cloud Platform to AWS — plus AI and agentic workloads from any provider.

    2.8k GitHub stars~15k tokensUpdated yesterday
    DevOps & CloudAuto-check passed
  • Cuts cloud spend across AWS, Azure, GCP and OCI with cost tagging, rightsizing, commitment and spot pricing models, and architecture changes.

    40k GitHub starsUsed in 14 repos~1.7k tokens
    DevOps & CloudAuto-check passed
  • Thesvg

    glincker/thesvg

    Fetch brand SVG logos and cloud architecture icons (AWS, Azure, GCP) from theSVG.

    2.8k GitHub stars~1.5k tokensUpdated yesterday
    DevOps & CloudAuto-check passed
  • Dangling DNS Finder

    anirudhbiyani/findmytakeover

    Detect dangling DNS records and subdomain-takeover risks across a multi-cloud environment by running the bundled findmytakeover tool.

    180 GitHub stars~1.8k tokensUpdated 1 mo ago
    DevOps & CloudAuto-check passed
  • Wa Guardrails

    aws-samples/sample-well-architected-skills-and-steering

    Official

    Generate preventive Well-Architected guardrails — AWS Config rules, Service Control Policies, permission boundaries, CloudWatch alarms, and IaC policy checks (CDK Aspects, cfn-guard, OPA/Sentinel) —…

    273 GitHub stars~2.8k tokensUpdated 2 days ago
    AI & LLM EngineeringAuto-check passed
  • Build reusable, tested Terraform modules for AWS, Azure, GCP and OCI, with a standard file layout, an AWS VPC example, versioning rules and Terratest checks.

    40k GitHub starsUsed in 11 repos~1.3k tokens
    DevOps & CloudAuto-check passed

More from google/skills

All 147 skills in this repo
  • Official

    Query Cloud Trace spans, filter by latency thresholds or error status, correlate distributed traces with Cloud Logging, and diagnose latency bottlenecks across Google Cloud services.

    21k GitHub stars~1.7k tokensUpdated yesterday
    Auto-check passed
  • Official

    Manages Google Cloud Privileged Access Manager entitlements and grants: create and edit entitlements, request temporary access, and approve or deny pending grants.

    21k GitHub stars~3.2k tokensUpdated yesterday
    Auto-check passed
  • Official

    Writes Terraform alerting policies for AI agents that emit OpenTelemetry metrics, covering reliability, cost, safety, security and quality signals on Google Cloud.

    21k GitHub stars~4.2k tokensUpdated yesterday
    Auto-check passed
  • Official

    Deploys open models or custom weights from Model Garden to Agent Platform endpoints, checks deployment status and cleans up endpoints, confirming before any change.

    21k GitHub stars~5k tokensUpdated yesterday
    Auto-check passed
  • Official

    Searches, manages and scaffolds skills in the Gemini Enterprise Agent Platform Skill Registry using bundled Python scripts and Google Cloud credentials.

    21k GitHub stars~584 tokensUpdated yesterday
    Auto-check passed
  • Designs GCP infrastructure as local Terraform, validates and scans it against best practices, then imports it to Application Design Center for deployment and troubleshooting.

    21k GitHub stars~4.4k tokensUpdated yesterday
    Auto-check passed

Works with

Questions about Google Cloud Recipe Foundation Builder

What does Google Cloud Recipe Foundation Builder do?

Deploys a baseline landing zone foundation for a Google Cloud Organization, establishing security guardrails using Organization Policies, resource hierarchy folders and projects, billing…. Google Cloud Recipe Foundation Builder is an agent skill from google/skills, published by the product's own GitHub organization. Deploys a baseline landing zone foundation for a Google Cloud Organization, establishing security guardrails using Organization Policies, resource hierarchy folders and projects, billing association, and centralized logging and monitoring.

When should I use Google Cloud Recipe Foundation Builder?

Google Cloud Recipe Foundation Builder fits situations like: setting up a new Google Cloud Organization; establishing a secure; enterprise-grade landing zone foundation; individual project onboarding (use google-cloud-recipe-onboarding.

How do I install Google Cloud Recipe Foundation Builder in Claude Code?

Run `npx skills add google/skills --skill google-cloud-recipe-foundation-builder -a claude-code`. Or copy the skill folder (skills/cloud/google-cloud-recipe-foundation-builder in google/skills) into .claude/skills/google-cloud-recipe-foundation-builder in your project. Claude Code loads it when a task matches its description.

How do I install Google Cloud Recipe Foundation Builder in Codex?

Run `npx skills add google/skills --skill google-cloud-recipe-foundation-builder -a codex`. Or copy the skill folder (skills/cloud/google-cloud-recipe-foundation-builder in google/skills) into .agents/skills/google-cloud-recipe-foundation-builder in your project. Codex loads it when a task matches its description.

Can I use Google Cloud Recipe Foundation Builder in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add google/skills --skill google-cloud-recipe-foundation-builder -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/google-cloud-recipe-foundation-builder, .gemini/skills/google-cloud-recipe-foundation-builder, .github/skills/google-cloud-recipe-foundation-builder and .opencode/skills/google-cloud-recipe-foundation-builder in your project.

What does Google Cloud Recipe Foundation Builder need to run?

Going by SKILL.md and its folder, Google Cloud Recipe Foundation Builder needs the command-line tools its instructions call (gcloud).

Does Google Cloud Recipe Foundation Builder access the network?

SKILL.md names 2 domains. As links in the text: cloud.google.com and docs.cloud.google.com. This is read from the text; nothing was executed.

Is Google Cloud Recipe Foundation Builder safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Google Cloud Recipe Foundation Builder use?

Google Cloud Recipe Foundation Builder is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Google Cloud Recipe Foundation Builder use?

About 4.8k tokens (SKILL.md is roughly 19k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 4.8k tokens, read only when the agent opens those files.

What are the alternatives to Google Cloud Recipe Foundation Builder?

Skills that share tags, products or a category with Google Cloud Recipe Foundation Builder: GCP To AWS (aws/agent-toolkit-for-aws, 2.8k stars), Cloud Cost Optimization (wshobson/agents, 40k stars), Thesvg (glincker/thesvg, 2.8k stars) and Dangling DNS Finder (anirudhbiyani/findmytakeover, 180 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Google Cloud Recipe Foundation Builder?

google (a GitHub organization, an official publisher) maintains it in google/skills, which has 21,032 GitHub stars. The repository holds 147 skills in this directory. The repository was last updated on October 8, 2026.

Source: google/skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.