Assigned
Status Update
Comments
ak...@google.com <ak...@google.com>
ak...@google.com <ak...@google.com>
an...@google.com <an...@google.com>
[Deleted User] <[Deleted User]> #2
Thanks for the report. I will route this to the appropriate internal team and update this when I hear back from them.
Description
Summary: This is a feature request to have a more comprehensive result when checking for effective organisation policies. Result for effective constraints should include child resources which as exempted down the hierarchy.
Problem you have encountered: Currently, when checking for enforced constraints at the organisation level. Results does not show projects/folders that override that constraint. This gives the impression that all child resources in the hierarchy are following the rule whiles in reality could be exempted.
[TOIL] Customers have to manually traverse all projects/folders to find out which ones are exempted which is error prone and has significant toil.
What you expected to happen: When the command [1] is used. The result should detail exempted child resources.
Steps to reproduce:
Other information (workarounds you have tried, documentation consulted, etc): [1] gcloud org-policies describe LIST_CONSTRAINT --effective --organization=ORGANIZATION_ID