Best practices for using VM Manager across an organization

This document provides a consolidated overview of organization-level how-to guides and best practices for configuring, orchestrating, and monitoring VM Manager across your Google Cloud organization or folders. You can use these guides to automate fleet-wide operating system management, enforce compliance, and centralize reporting across projects. Each entry in the following table links to detailed documentation for specific tasks:

Select a category:

Category Best practices Summary
Setup and enablement Enable VM Manager across a folder or organization Enable the OS Config API across all existing and future projects in an organization or folder by using hierarchical service activation and organization policy constraints.
Setup and enablement Set up VM Manager across an organization by using Terraform Automate organization-wide VM Manager enablement, custom IAM role creation, instance metadata configuration, and OS policy assignments by using Terraform.
Policy orchestration About policy orchestrator Understand how organization-level and folder-level policy orchestrators automate progressive rollouts of OS policy assignments across projects and zones.
Policy orchestration Prerequisites for using policy orchestrator Configure the service agents, IAM permissions, and VPC Service Controls ingress rules that are required for organization-level and folder-level policy orchestration.
Policy orchestration Manage OS policy assignments using policy orchestrator Create organization-level or folder-level policy orchestrators to progressively roll out, update, or delete OS policy assignments across multiple projects and zones.
Policy orchestration View, edit, and delete policy orchestrators Inspect rollout status across your organization or folders, modify orchestration scopes, or delete existing policy orchestrators.
Compliance and custom data View OS policy compliance summary for an organization or folder Review aggregated OS policy compliance states across all projects in your organization or folder in the Google Cloud console, and filter results by using the query builder.

Compliance and custom data

Monitoring and governance

View custom data from OS policies for your organization Export VM Manager and Cloud Asset Inventory data to BigQuery to query custom script outputs (strings or JSON) and enforcement error messages across all VMs in your organization.
Patch and vulnerability management View vulnerability reports for your organization Export OS inventory and vulnerability data to BigQuery by using Cloud Asset Inventory to identify and query Common Vulnerabilities and Exposures (CVEs) across your organization.
Patch and vulnerability management View patch summary for VMs in an organization or folder Monitor organization-wide or folder-wide patch compliance, available OS updates, and reboot requirements across all projects in the Google Cloud console.
Monitoring and governance View VM Manager status for your organization Export Cloud Asset Inventory resource and OS inventory snapshots to BigQuery to verify VM Manager enablement, check OS Config agent versions, and audit operating system distributions across your organization.
Monitoring and governance VM Manager audit logs Monitor Admin Activity and Data Access audit logs for VM Manager operations, including organization-level and folder-level policy orchestrator actions.

Monitoring and governance

Policy orchestration

Quotas and limits Track and manage folder-level and organization-level quotas for policy orchestrators across large VM fleets.