Get hands-on experience with 20+ free Google Cloud products and $300 in free credit for new customers.

GCP Project creation disabled but additional service on and users can create project checked?

Hi,

I am in a strange situation where we already have a dozen of projects created, and our directory is correctly configured to enable the Google Cloud Platform ON and users can create projects checked in a suitable OU.

Everything has been fine for the last 4 years, but now I receive this error when trying to create a new project:

(gcloud.projects.create) FAILED_PRECONDITION: Cloud Resource Manager project creation is disabled. Contact your administrator to enable this setting in the Google Cloud Platform service in the Google Workspace Admin console. See https://support.google.com/a/answer/9197205 for more information

The last project I created was in may or june, did something happened on the Google side (version upgrade, account migration, ...) since then I may have missed?

I don't remind any change that could lead to this situation, or the existence of some other setting / policy that could prevent project creation...

Did some of you get into that situation recently?

Any idea, pointers?

Thank you very much.

Solved Solved
0 2 415
1 ACCEPTED SOLUTION

Hi kensan,

Google workspace support is unresponsive...

However, for the record, here is the explanation of this weird behavior I finally dicovered.

Since the introduction of group and  user ACLs in the directory, in addition of the traditional OU ones, for the apps, when you set some ACL for a given app (Google Cloud Platform here) on a user or group, this new ACL takes precedence over the OU ones.

The priority order seems to be: user --> group --> OU

In my case, I probably at some points tested this new feature and unfortunately forget to reverse it...

Because this is fairly undocumented, and Google does not offer any sensible GUI to consolidate or test the ACLs permissions, it is a total mess to maintain / evolve (and we are a small shop of 15, I can't imagine a reasonably sized company rely on the current console features for their daily work).

For now my advice it to choose only one way to set apps settings, either at the OU or the groups (users) but not mix them.

View solution in original post

2 REPLIES 2
Top Labels in this Space
Top Solution Authors