# GCP Satellite Overview
The CMDB-360 GCP Satellite provides visibility into the resources managed within a Google Cloud Platform (GCP) environment. Google Cloud organizes resources into projects, within which Compute Engine virtual machine instances, disks and networks are provisioned. The GCP Satellite discovers the projects available to it and the Compute Engine resources within them, and supports discovery across one or many Google Cloud projects.
Important
The GCP Satellite does not directly access any virtual machine instance running in your Google Cloud environment, instead only accessing the Google Cloud APIs to gather discovery and other details.
No proprietary asset information is stored on the CMDB-360 Base Station database…only simple rosters of discovered Google Cloud resources are recorded. CMDB-360 users (with proper permissions) may obtain additional details about a discovered resource via the CMDB-360 portal that is streamed from the Satellite to the Base Station and viewed on-demand.
The GCP Satellite only requires read-only permissions to Google Cloud to gather all required CMDB details within the environment.
Important
You must allow outbound HTTPS (port 443/tcp) access from the Satellite to the Google Cloud APIs.
# Main Functions
The GCP Satellite performs two core functions:
- Discovers Google Cloud projects and their Compute Engine resources, and regularly sends non-sensitive resource details to the CMDB-360 Base Station for asset management.
- Provides the CMDB-360 Base Station on-demand access to asset information without storing sensitive information outside the Google Cloud environment.
# Managed Resources
The following Google Cloud resources are accessed:
- Projects
- Compute Engine Instances
- Disks (attached to instances)
- Network Interfaces (of instances)
For each discovered project, the Satellite captures:
- Name, display name and unique ID
- Project type and lifecycle state
- Position in the resource hierarchy — its parent and whether it is a top-level project
- Created and last-updated timestamps
For each discovered Compute Engine instance, the Satellite captures:
- Name, unique ID, description and resource URL
- Machine type and CPU platform
- Status and status message
- Zone
- Hostname and source image
- Created, last-started and last-stopped timestamps
- The project to which the instance belongs
- Its attached disks and network interfaces (described below)
For each attached disk, the Satellite captures:
- Device name, size (in GB), type and interface
- Boot, auto-delete and access-mode flags
- Architecture, attachment index and any associated licenses
For each network interface, the Satellite captures:
- Name, the associated network and subnetwork, and any network attachment
- Internal (network) IP and IPv6 address
- NIC type and IP stack type
Important
Please note that you may disable the discovery and access of any of these resource objects from the Satellite scheduler. You may also disable the ability to access additional details about a resource by disabling the Channel communication websocket as described below.
# Deployment / Installation
The GCP Satellite may be installed or deployed in a number of different ways:
# 1) By Installing a Docker Image from Dockerhub
If you have a compute instance with Docker installed, you may install the GCP Satellite using a container image from Dockerhub. Pull the GCP Satellite Docker image and run the image as a container according to the instructions provided.
All updates to the GCP Satellite will be delivered using the internal satellite update mechanism (used by all satellites), but you may also use Docker to pull the latest version (in which case you will have to re-configure it).
To learn more about installing the GCP Satellite (or any Satellite) on a Docker host, see https://www.cmdb360.com/docs/?uri=Docker/Satellites/Install.html
# 2) By Using Universal Installer On Any Linux VM
You may provision any Linux compute instance running Oracle Linux 8+, Oracle Linux 9, Ubuntu 20.04, or Ubuntu 22.04 on ARM or x86_64 architecture and install the GCP Satellite software using the Installer graphical utility or the AutoInstaller non-interactive utility (for scripts). The provisioned compute instance must have at least 1 OCPU and 4GB RAM along with at least 10GB Disk.
Warning
Please note that if you install any additional software (such as security tools), you must designate at least the required minimal resources to the Satellite for optimal performance.
You may obtain a link to the current Installer or AutoInstaller utilities (and documentation) from your CMDB-360 portal under the deployed GCP Satellite details screen.
Note
The Installer/AutoInstaller utilities also perform the configuration described in the following section, so you may skip that step.
# Additional Notes On Deployment
CMDB-360 recommends that the GCP Satellite be deployed within the customer’s Google Cloud project so that credentials and discovered data remain within the customer’s environment. Because it uses the public Google Cloud APIs, you may however install the GCP Satellite in any other location with outbound internet access.
# Configuration
The GCP Satellite has a 2-step configuration process. First, as with any satellite, you must configure the GCP Satellite to communicate with the CMDB-360 Base Station deployed for your company. Second, you must configure the GCP Satellite to access the Google Cloud APIs of your environment.
# 1) Connection To Base Station
All satellites are connected to their respective CMDB-360 Base Station by the URL and Token values defined in the encrypted config.yml configuration file found in the base config directory of the satellite (/opt/satellite/etc by default). This configuration file is managed by the AdminTool utility which is found in the base of the satellite install directory (/opt/satellite by default).
Please see https://www.cmdb360.com/docs/?uri=OCI-satellite/OciSatelliteSetup/OciSatelliteSetup.html for instructions about setting up the GCP Satellite to its respective Base Station.
Note
The Installer/AutoInstaller utilities perform this configuration step as part of the installation process, so you may skip this step.
# 2) Configure Connection To Google Cloud
The GCP Satellite accesses the Google Cloud APIs using a service account that has been granted read-only access to the projects and resources you wish to discover.
Create a service account and grant it a read-only role — for example, the basic Viewer role, or more granular roles such as Compute Viewer and Browser — at the organization, folder or project scope. Generate a service account key for the account.
Enter the details of your Google Cloud service account using the ConfigTool utility:
cd /opt/satellite/bin
./ConfigTool
Provide your service account key (JSON) and, if desired, the organization, folder or project to scope discovery:
Click Save to save the changes. The GCP Satellite will now automatically begin the discovery process and connect to your CMDB Base Station.