A RetroSearch Logo

Home - News ( United States | United Kingdom | Italy | Germany ) - Football scores

Search Query:

Showing content from https://cloud.google.com/sql/docs/postgres/configure-org-policy below:

Add predefined organization policies | Cloud SQL for PostgreSQL

Add predefined organization policies

Stay organized with collections Save and categorize content based on your preferences.

This page describes how to add organization policies on Cloud SQL instances, to put restrictions on Cloud SQL at the project, folder, or organization level. For an overview, see Cloud SQL organization policies.

Before you begin
  1. Sign in to your Google Cloud account. If you're new to Google Cloud, create an account to evaluate how our products perform in real-world scenarios. New customers also get $300 in free credits to run, test, and deploy workloads.
  2. In the Google Cloud console, on the project selector page, select or create a Google Cloud project.

    Note: If you don't plan to keep the resources that you create in this procedure, create a project instead of selecting an existing project. After you finish these steps, you can delete the project, removing all resources associated with the project.

    Go to project selector

  3. Make sure that billing is enabled for your Google Cloud project.

  4. Install the gcloud CLI.

  5. If you're using an external identity provider (IdP), you must first sign in to the gcloud CLI with your federated identity.

  6. To initialize the gcloud CLI, run the following command:

    gcloud init
  7. In the Google Cloud console, on the project selector page, select or create a Google Cloud project.

    Note: If you don't plan to keep the resources that you create in this procedure, create a project instead of selecting an existing project. After you finish these steps, you can delete the project, removing all resources associated with the project.

    Go to project selector

  8. Make sure that billing is enabled for your Google Cloud project.

  9. Install the gcloud CLI.

  10. If you're using an external identity provider (IdP), you must first sign in to the gcloud CLI with your federated identity.

  11. To initialize the gcloud CLI, run the following command:

    gcloud init
  12. Add the Organization Policy Administrator role (roles/orgpolicy.policyAdmin) to your user or service account from the IAM & Admin page.

    Go to the IAM accounts page

  13. See Restrictions before performing this procedure.
Add the connection organization policy

For an overview see Connection organization policies.

To add a connection organization policy:

  1. Go to the Organization policies page.

    Go to the Organization policies page

  2. Click projects dropdown menu in the top tab, and then select the project, folder, or organization that requires the organization policy. The Organization policies page displays a list of organization policy constraints that are available.

  3. Filter for the constraint name or display_name.

  4. Select the policy Name from the list.

  5. Click Edit.

  6. Click Customize.

  7. Click Add rule.

  8. Under Enforcement, click On.

  9. Click Save.

Add the CMEK organization policy

For an overview, see Customer-managed encryption keys organization policies.

To add a CMEK organization policy:

  1. Go to the Organization policies page.

    Go to the Organization policies page

  2. Click projects dropdown menu in the top tab, and then select the project, folder, or organization that requires the organization policy. The Organization policies page displays a list of organization policy constraints that are available.

  3. Filter for the constraint name or display_name.

  4. Select the policy Name from the list.

  5. Click Edit.

  6. Click Customize.

  7. Click Add rule.

  8. Under Policy values, click Custom.

  9. For constraints/gcp.restrictNonCmekServices: a. Under Policy types, select Deny. b. Under Custom values, enter sqladmin.googleapis.com.

    For constraints/gcp.restrictCmekCryptoKeyProjects: a. Under Policy types, select Allow. b. Under Custom values, enter the resource using the following format: under:organizations/ORGANIZATION_ID, under:folders/FOLDER_ID, or projects/PROJECT_ID.

  10. Click Done.

  11. Click Save.

What's next

Except as otherwise noted, the content of this page is licensed under the Creative Commons Attribution 4.0 License, and code samples are licensed under the Apache 2.0 License. For details, see the Google Developers Site Policies. Java is a registered trademark of Oracle and/or its affiliates.

Last updated 2025-07-02 UTC.

[[["Easy to understand","easyToUnderstand","thumb-up"],["Solved my problem","solvedMyProblem","thumb-up"],["Other","otherUp","thumb-up"]],[["Hard to understand","hardToUnderstand","thumb-down"],["Incorrect information or sample code","incorrectInformationOrSampleCode","thumb-down"],["Missing the information/samples I need","missingTheInformationSamplesINeed","thumb-down"],["Other","otherDown","thumb-down"]],["Last updated 2025-07-02 UTC."],[],[]]


RetroSearch is an open source project built by @garambo | Open a GitHub Issue

Search and Browse the WWW like it's 1997 | Search results from DuckDuckGo

HTML: 3.2 | Encoding: UTF-8 | Version: 0.7.4