> For the complete documentation index, see [llms.txt](https://help.aikido.dev/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://help.aikido.dev/docs/docs-ja/kuraudosukyan/connect-your-cloud/gcp/connect-google-cloud-organization.md).

# Google Cloud Organization を接続

同じ Google Cloud 組織に属する複数の GCP プロジェクトがある場合、そのうち 1 つを接続して組織レベルで権限を付与すれば、Aikido が残りのプロジェクトを自動的に接続します。将来作成するプロジェクトも含まれます。

### Google Cloud 組織を接続する理由 <a href="#why-connect-aws-organization" id="why-connect-aws-organization"></a>

組織レベルでオンボーディングすると、次の利点があります：

* **セットアップの高速化**: 手動で接続する必要があるのは 1 つのプロジェクトだけです。
* **プロジェクトの自動検出**: プロジェクトは Aikido に自動的に追加されます。将来作成するものも含まれます。
* **コンテナスキャンの自動セットアップ**: Aikido は、すべてのプロジェクトの Artifact Registry からコンテナを自動的にスキャンします。

### 前提条件 <a href="#prerequisites" id="prerequisites"></a>

* Pro、Advanced、または Enterprise プランをご利用中です。
* Google Cloud 組織へのアクセス権があり、組織レベルで権限を付与できること。
* GCP プロジェクトの 1 つを「管理」プロジェクトとして指定します。このプロジェクトでサービスアカウント / Workload Identity Federation プールを作成し、Aikido にオンボードします。

### はじめに <a href="#getting-started" id="getting-started"></a>

Google Cloud 組織を接続するには、「Full GCP Organizatio&#x6E;**'** オプションを [GCP オンボーディングウィザード](https://app.aikido.dev/clouds/add/gcp).

<figure><img src="/files/981d08245a708ede7adac2464ac56050746b1c10" alt=""><figcaption></figcaption></figure>

「管理」プロジェクトの ID と番号を入力した後、次の情報を提供する必要があります。

* **組織 ID**: 例: '783352941112' のようになります。
* **含めるフォルダ ID（任意）**: このオプションにより、組織の一部のみをオンボードできます。例: 1 つのフォルダとその配下すべて。
* **除外するフォルダ ID（任意）**: このオプションにより、フォルダ全体を自動オンボーディングから除外できます。これは次の項目とも連動します。 **含めるフォルダ** オプションを選択してください。
* **除外するプロジェクト ID**: 任意で、特定の GCP プロジェクトを Aikido に追加しないよう除外できます。
* 次を有効にすることで、プロジェクト全体のコンテナスキャンも自動設定できます。 **Artifact Registry スキャン**.

この情報は、次の場所から取得できます： [Google Cloud Resource Manager のページ](https://console.cloud.google.com/cloud-resource-manager) （プロジェクトセレクターから組織を選択してください）。

{% hint style="info" %}
オンボーディング中に認証の検証に失敗した場合でも、IAM 権限がまだ Google Cloud 組織内に伝播中である可能性があります。数分待ってから再試行してください。伝播にかかる時間は、組織の規模によって異なる場合があります。
{% endhint %}

#### Terraform モジュール <a href="#cloud-purpose-determination" id="cloud-purpose-determination"></a>

Infrastructure as Code を好む場合は、Aikido の Terraform モジュールを使用して、組織レベルのオンボーディングに必要な Google Cloud IAM と Workload Identity Federation の設定を行えます。このモジュールは、単一プロジェクト構成と組織全体構成の両方、任意の Artifact Registry スキャン、任意の VM スキャン権限をサポートしています。

<https://github.com/AikidoSec/gcp-onboarding-terraform-module>

組織レベルのオンボーディングには modules/org モジュールを使用し、生成された `credential_config_json` をクラウド接続フロー中に Aikido へアップロードします。

Aikido アカウントが EU インスタンス（app.aikido.dev）上にない場合は、 `aikido_region` を次に設定します: `us`, `me`、または `au` をそれぞれ設定してください。

{% hint style="info" %}
**重要**

Terraform モジュールは、必要な Google Cloud IAM 設定のみを行います。生成された `credential_config_json` をアップロードし、残りのアプリ内手順を完了して、Aikido でクラウドアカウントを接続するオンボーディングフローを引き続き完了する必要があります。
{% endhint %}

#### クラウド用途の判定 <a href="#cloud-purpose-determination" id="cloud-purpose-determination"></a>

GCP プロジェクトの目的 / 環境は、プロジェクト名に基づいて自動的に判定されます。Aikido は「production」「staging」「uat」などの用語を探し、それに応じてクラウドの目的を設定します。該当するものが見つからない場合、目的は「mixed」になります。「Configure」ボタンを使って、各クラウド接続の目的を手動で更新できます。

### よくある質問 <a href="#faqs" id="faqs"></a>

* **安全ですか？**

はい。GCP 組織の接続は、個別の GCP プロジェクトを接続する際に使用するのと同じ仕組みに依存しています。 [Workload Identity Federation](https://help.aikido.dev/cloud-scanning/connect-your-cloud/gcp/google-cloud-workload-identity-federation-setup) もサポートされており、推奨されています。

* **GCP プロジェクトを組織に追加したら、Aikido に表示されますか？**

はい。Aikido は「管理」プロジェクトをスキャンするたびに GCP 組織をスキャンし、新しい GCP プロジェクトを自動的に接続します。特に GCP 組織に数千のプロジェクトがある場合、Aikido にプロジェクトが表示されるまで多少遅延することがあります（私たちは [Google Cloud API の制限を尊重しています](https://cloud.google.com/resource-manager/docs/limits)).

* **GCP の新しいプロジェクトを組織に追加したのですが、Aikido に表示されませんでした。**

Aikido が GCP の「管理」プロジェクトをスキャンし（手動でスキャンできます）、新しいプロジェクトが 15 分後にも表示されない場合、プランのクラウド上限に達している可能性があります。上限を増やすにはお問い合わせください。

* **GCP プロジェクトを停止したり、別の組織に移動したりするとどうなりますか？**

Aikido は、そのプロジェクトがもはやアクティブでないか、組織の一部ではないことを検出し、対応するクラウドを「到達不能」とマークします。これは次の場所で確認できます。 [クラウド一覧ページ](https://app.aikido.dev/clouds).


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://help.aikido.dev/docs/docs-ja/kuraudosukyan/connect-your-cloud/gcp/connect-google-cloud-organization.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
