What MarshalCloud does with it
- Your Google Cloud bill, from the BigQuery billing export table you point us at.
- Read-only inventory: virtual machines, disks, buckets, databases, GKE clusters and node pools, functions, Cloud Run services and networking.
- Google's own cost recommendations, and Security Command Center findings where you grant that role.
What it never does
- No credential of yours is stored. You grant a read role to MarshalCloud's own service account; the connection keeps only your project and billing table identifiers.
- Read-only scope. Nothing in Google Cloud is created, changed or deleted.
- Google Cloud does not have the same depth as AWS yet. Where a check has not run, MarshalCloud says unknown rather than showing a pass.
Read-only is the default everywhere. A fix is drafted, priced and explained, and then waits for a person to approve it. The whole access path is on Security and access.
Which plan includes it
Growth and above (Growth is $149 a month, Scaled is quoted). See every plan limit.
How to connect it
- Start a Google Cloud connection in MarshalCloud. It shows the service account address to grant access to.
- Grant that service account read access in your project. The page gives you the exact command to paste.
- Paste your BigQuery billing export table path. MarshalCloud verifies by reading the current month once and tells you how many rows it saw.
Questions
- Does MarshalCloud store a Google Cloud key?
- No. You grant a read role to MarshalCloud's own service account, so there is no key of yours to store, rotate or lose. The connection keeps only your project and billing table identifiers.
- What does MarshalCloud read in Google Cloud?
- Your bill from the BigQuery billing export, read-only inventory across virtual machines, disks, buckets, databases, GKE clusters, functions, Cloud Run and networking, Google's own cost recommendations, and Security Command Center findings where you grant that role.
- Which plan includes Google Cloud?
- Growth and above. MarshalCloud is built deepest for AWS; Google Cloud does not have AWS feature parity yet, and a check that has not run reads as unknown rather than a pass.