Skip to main content

Environment

Environment

A deployment lifecycle boundary (e.g. Development, Staging, Production).

Provisions a GCP folder under the parent OrganizationalUnit and acts as an IAM boundary and variable-propagation anchor for its child Projects: it carries baseline permissions, hibernation schedules, and domain segments that are inherited down the org tree. Its direct children are Secret and Project manifests.

PropertyTypeDescription
apiVersionstringAPI schema version. Pins the manifest to a specific schema contract for backward-compatibility. Must be the constant lowops.manifests.v1.
kindstringResource kind discriminator. Identifies this document as an Environment so the engine routes it to the correct defaulter, validator, computer, and executor. Must be the constant Environment.
metadatamapClassification labels and graph linkage. Free-form key/value pairs used to classify the manifest. Certain reserved keys (e.g. name, organizational-unit, organization) are read by the engine to resolve this manifest's identity and its parent OrganizationalUnit in the dependency graph.
specEnvironmentDefinitionUser-provided environment configuration. Defines the environment's display name, baseline access permissions, hibernation schedule, and domain segment. These traits are inherited by child Projects and drive the provisioned GCP folder and its IAM bindings. See the EnvironmentDefinition message for the individual fields.

EnvironmentDefinition

High-level definition of an Environment (e.g., staging, prod) within an organizational boundary.

Maps to a GCP Folder under its parent OU folder. Establishes the boundary where environment-specific IAM, hibernation, and networking defaults are defined.

PropertyTypeDescription
displayNamestringDisplay name of the GCP folder. Human-friendly name for the Environment's GCP Folder. When unspecified, the manifest's metadata.name is used. Proto validation constrains it to 3-30 characters of letters, digits, spaces, underscores, and dashes.
descriptionstringHuman-readable description. Free text describing the GCP asset represented by this Environment.
hibernationHibernationConfigDefault hibernation schedule for the environment. Default schedule for this Environment, overriding the parent OrganizationalUnit schedule and inherited by all child Project manifests. The computed schedule governs the active hours of underlying resources within this environment's projects to manage cost.
permissionsAccessPermissionsDefault access permissions for the environment. Default permissions for all resources within this Environment, inherited by child Project manifests and combined with permissions from the parent OrganizationalUnit. Translated into google_folder_iam_binding resources granting the specified roles to principals on this environment's GCP Folder.
networkEnvironmentNetworkDefault network settings for the environment. See EnvironmentNetwork. NOT YET IMPLEMENTED (the underlying flow-log settings have no consumer).

AccessPermissions

Core definition for assigning administrative and viewer privileges across the platform.

Used by the engine to compute the final IAM policies (google_folder_iam_binding, etc.), aggregating individual user and group definitions to role assignments.

PropertyTypeDescription
administratorsDetailedAccessPermissionsAdministrators. Users and groups granted administrative privileges on the asset. Exact rights are resource-dependent but typically confer full control. See DetailedAccessPermissions.
contributorsDetailedAccessPermissionsContributors. Users and groups granted contributor privileges on the asset. Exact rights are resource-dependent but typically confer read and write access. See DetailedAccessPermissions.
viewersDetailedAccessPermissionsViewers. Users and groups granted viewer privileges on the asset. Exact rights are resource-dependent but typically confer read-only access. See DetailedAccessPermissions.

HibernationConfig

Consolidates hibernation scheduling logic.

Used by the orchestrator to aggregate windows and exclusions across OU, Environment, and Project inheritance chains into a final deployment state.

PropertyTypeDescription
hibernateboolWhen set to 'true', forces the resource into hibernation immediately, overriding any active 'windows' or 'exclusions'. Defaults to 'false'.
windowslist of WindowsEntryA map of recurring time windows during which the resource will be hibernated. The key of the map provides a unique name for each window.
exclusionslist of ExclusionsEntryA map of specific, non-recurring time windows during which hibernation will be suspended, even if a 'window' is active. Use this for planned maintenance or high-traffic periods. The key of the map provides a unique name for each exclusion.

EnvironmentNetwork

Default network settings at the Environment level.

NOT YET IMPLEMENTED. Declared in the schema but currently ignored by the engine (its NetworkLogs payload has no consumer). Intended future behavior: provide default VPC flow-log configuration, inherited by down-level Projects, overriding parent OU settings.

PropertyTypeDescription
logsNetworkLogsDefault VPC flow log settings for the environment. NOT YET IMPLEMENTED. Declared in the schema but currently ignored by the engine (no consumer reads it). Intended future behavior: apply these settings to the log_config of every google_compute_subnetwork created under this environment's projects.

WindowsEntry

PropertyTypeDescription
keystring
valueHibernationWindow

NetworkLogs

VPC Flow Logs export settings.

NOT YET IMPLEMENTED. Declared in the schema but currently ignored by the engine (no consumer reads it). Intended future behavior: populate the log_config block of google_compute_subnetwork, controlling flow-log aggregation interval and sampling rate for network telemetry.

PropertyTypeDescription
intervalstringFlow-log aggregation interval. NOT YET IMPLEMENTED. Declared in the schema but currently ignored by the engine (no consumer reads it). Intended future behavior: set the aggregation_interval of the subnetwork log config, controlling the window over which VPC flow logs are aggregated before export. Proto validation restricts it to the allowed INTERVAL_* enum values.
samplingdoubleFlow-log sampling rate. NOT YET IMPLEMENTED. Declared in the schema but currently ignored by the engine (no consumer reads it). Intended future behavior: set the flow_sampling of the subnetwork log config, the fraction of connections captured. Proto validation constrains it to between 0.0 (no logs) and 1.0 (all logs).

DetailedAccessPermissions

Aggregation of specific user and group access definitions.

Refers to lists of OrganizationUser and OrganizationUserGroup manifests that will be parsed to retrieve actual Google Workspace identity emails for IAM binding construction.

PropertyTypeDescription
memberslist of stringA list of 'OrganizationUser' manifest names to be included in this permission set.
groupslist of stringA list of 'OrganizationUserGroup' manifest names to be included in this permission set.

ExclusionsEntry

PropertyTypeDescription
keystring
valueHibernationExclusion

HibernationWindow

Defines a recurring period when an asset should be scaled down.

Scheduled cron strings used by the control plane's orchestration tools to dynamically stop virtual machines or scale Cloud Run instances to zero.

PropertyTypeDescription
startstringA cron expression defining when the hibernation window begins.
endstringA cron expression defining when the hibernation window ends.

HibernationExclusion

Defines a specific suspension of the hibernation schedule.

Prevents down-scaling operations during the specified timeframe, ensuring workloads remain active for special events or maintenance.

PropertyTypeDescription
startstringThe start date and time for the exclusion window in RFC3339 format. RFC3339
endstringThe end date and time for the exclusion window in RFC3339 format. RFC3339