> For the complete documentation index, see [llms.txt](https://help.aikido.dev/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://help.aikido.dev/docs/docs-ja/kuraudosukyan/connect-your-cloud/gcp/connect-google-cloud-organization.md).

# Google Cloud Organization を接続する

同じ Google Cloud 組織に属する複数の GCP プロジェクトがある場合、そのうち1つを接続し、組織レベルで権限を付与すると、Aikido が残りを自動的に接続します。将来作成するプロジェクトも含まれます。

### Google Cloud 組織を接続する理由は？ <a href="#why-connect-aws-organization" id="why-connect-aws-organization"></a>

組織レベルでオンボーディングすることで、次の利点があります:

* **セットアップの高速化**：手動で接続する必要があるのは 1 つのプロジェクトだけです。
* **プロジェクトの自動検出**：プロジェクトは自動的に Aikido に追加されます。将来作成するものも含まれます。
* **コンテナの自動スキャン設定**：Aikido は、すべてのプロジェクトの Artifact Registry からコンテナを自動的にスキャンします。

### 前提条件 <a href="#prerequisites" id="prerequisites"></a>

* Pro、Advanced、または Enterprise プランをご利用です。
* Google Cloud 組織へのアクセス権があり、組織レベルで権限を付与できます。
* GCP プロジェクトの1つを「管理」プロジェクトとして指定します。このプロジェクトでサービス アカウント／Workload Identity Federation プールを作成し、Aikido にオンボードします。

### はじめに <a href="#getting-started" id="getting-started"></a>

Google Cloud 組織を接続するには、'Full GCP Organizatio&#x6E;**'** オプションを [GCP オンボーディング ウィザード](https://app.aikido.dev/clouds/add/gcp).

<figure><img src="/files/981d08245a708ede7adac2464ac56050746b1c10" alt=""><figcaption></figcaption></figure>

「管理」プロジェクトの ID と番号を入力したら、次の情報を提供する必要があります：

* **Organization ID**：'783352941112' のような形式です。
* **含めるフォルダ ID（任意）**：このオプションを使うと、組織の一部だけをオンボードできます。たとえば、あるフォルダとそのすべての子孫です。
* **除外するフォルダ ID（任意）**：このオプションを使うと、フォルダ全体を自動オンボーディングから除外できます。これは次の項目と組み合わせても機能します： **含めるフォルダ** オプションを有効にします。
* **除外するプロジェクト ID**：任意で、特定の GCP プロジェクトを Aikido への追加対象から除外できます。
* また、次を有効にすると、プロジェクト全体でコンテナ スキャンを自動的に設定することもできます： **Artifact Registry スキャン**.

この情報は、次の場所から取得できます: [Google Cloud Resource Manager のページ](https://console.cloud.google.com/cloud-resource-manager) （プロジェクト セレクタから組織を選択します）。

{% hint style="info" %}
オンボーディング中に認証情報の検証に失敗した場合でも、IAM 権限が Google Cloud 組織内にまだ反映中である可能性があります。数分待ってから再試行してください。反映時間は組織の規模によって異なります。
{% endhint %}

#### Terraform モジュール <a href="#cloud-purpose-determination" id="cloud-purpose-determination"></a>

Infrastructure as Code を使いたい場合は、Aikido の Terraform モジュールを使用して、組織レベルのオンボーディングに必要な Google Cloud IAM と Workload Identity Federation の設定を行えます。このモジュールは、単一プロジェクト構成と組織全体構成の両方、任意の Artifact Registry スキャン、任意の VM スキャン権限をサポートしています。

<https://github.com/AikidoSec/gcp-onboarding-terraform-module>

組織レベルのオンボーディングには modules/org モジュールを使用し、その後生成された `credential_config_json` をクラウド接続フロー中に Aikido にアップロードします。

Aikido アカウントが EU インスタンス（app.aikido.dev）にない場合は、次を設定してください： `aikido_region` を `us`, `me`、または `au` それに応じて。

{% hint style="info" %}
**重要**

Terraform モジュールは必要な Google Cloud IAM 設定のみを行います。クラウドアカウントを接続するには、生成されたものをアップロードして Aikido でオンボーディングフローを最後まで完了する必要があります `credential_config_json` そして、残りのアプリ内手順を完了してください。
{% endhint %}

#### クラウド用途の判定 <a href="#cloud-purpose-determination" id="cloud-purpose-determination"></a>

GCP プロジェクトの用途／環境は、プロジェクト名に基づいて自動的に判定されます。Aikido は「production」「staging」「uat」などの用語を探し、それに応じてクラウドの用途を設定します。一致するものが見つからない場合、用途は「mixed」になります。各クラウド接続の用途は、「Configure」ボタンを使って手動で更新できます。

### FAQ <a href="#faqs" id="faqs"></a>

* **安全ですか？**

はい。GCP 組織の接続は、個別の GCP プロジェクトを接続するのと同じ仕組みに基づいています。 [Workload Identity Federation](https://help.aikido.dev/cloud-scanning/connect-your-cloud/gcp/google-cloud-workload-identity-federation-setup) もサポートされており、推奨されています。

* **組織に GCP プロジェクトを追加したら、Aikido に表示されますか？**

はい。Aikido は「管理」プロジェクトをスキャンするたびに GCP 組織もスキャンし、新しい GCP プロジェクトを自動的に接続します。特に GCP 組織に何千ものプロジェクトがある場合、Aikido にプロジェクトが表示されるまで少し遅れることがあります（私たちは次を尊重します [Google Cloud API の制限](https://cloud.google.com/resource-manager/docs/limits)).

* **組織に新しい GCP プロジェクトを追加したのに、Aikido に表示されませんでした。**

Aikido が GCP の「管理」プロジェクトをスキャン済みで（手動でスキャンすることもできます）、新しいプロジェクトが 15 分経っても表示されない場合、プランのクラウド数上限に達している可能性があります。上限の引き上げについてお問い合わせください。

* **GCP プロジェクトを停止したり、別の組織に移動したりするとどうなりますか？**

Aikido は、そのプロジェクトがもはやアクティブでない、または組織に属していないことを検出し、対応するクラウドを「到達不能」としてマークします。これが次に表示されます [Clouds ページ](https://app.aikido.dev/clouds).


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://help.aikido.dev/docs/docs-ja/kuraudosukyan/connect-your-cloud/gcp/connect-google-cloud-organization.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
