Skip to main content

FAQs

GCP Commitment Management enables nOps to autonomously purchase, manage, and optimize Committed Use Discounts (CUDs) on your behalf. This includes both Resource-based CUDs (project-level) and Spend-based (Flex) CUDs (billing account-level).
  • Resource-based CUDs: Purchased at the project level for specific machine families. Requires CUD sharing to be enabled to apply discounts across projects.
  • Spend-based (Flex) CUDs: Purchased at the billing account level and automatically apply to all eligible usage across all projects.
Yes, for Resource-based CUDs. CUD sharing is disabled by default in GCP and must be enabled before nOps can share purchased commitments across your projects.
  • Automation Agent: A service account used by nOps for autonomous purchasing, quota management, and self-healing operations.
  • nOps Support: A group email provided by nOps for console access, manual overrides, dashboards, and verification.
No. Commitment Inventory is included on every nOps plan when your GCP integration is active. Inform is only required to email or schedule inventory reports. This CM setup is for purchasing and deeper CUD inventory reads—not for opening the Inventory page itself.

Before You Start

You will need these 2 values:
Prerequisites — Before configuring Commitment Management, ensure you have completed:You will need the nOps Service Account email from your existing integration. You can find it in nOps Settings → Cloud Provider Integrations.
Prefer infrastructure as code? After completing Step 1 (Enable CUD Sharing) and Step 2 (Create a Dedicated CUD Project), you can use our open-source Terraform module instead of the console steps in Steps 3–7. See Terraform setup.

What You’re Setting Up

nOps uses two identities to manage commitments on your behalf: Both identities need roles at three scopes: Organization, Billing Account, and Project. This guide walks through each scope exactly once, granting roles for both identities at each step.

Step 1: Enable CUD Sharing

CUD sharing is off by default. This must be enabled for resource-based CUD discounts to apply across projects in your billing account.
Cannot be undone from Console. Once enabled, only Cloud Billing Support can revert it. The reverted setting takes effect at the start of the following month.
Spend-based CUDs automatically apply across all projects without this step. This is only needed for resource-based CUDs.
Required permission: Billing Account Administrator (includes billing.subscriptions.update)
1

Open CUD Analysis

Go to Billing in the GCP Console, select your billing account, and then choose CUD analysis on the left sidebar.
2

Open CUD Scope Settings

Click the 3 dots next to Purchase CUDSCUD scope & settings.
3

Select CUD Scope and Settings

In “Resource-based CUD scope”, ensure it says billing account and save.
4

Confirm and Enable

In the confirmation dialog, type Enable and click Enable billing account scope.
Propagation: Can take up to 24 hours. If unchanged after 24 hours, contact Cloud Billing Support.

Step 2: Create a Dedicated CUD Project

nOps purchases all resource-based commitments from a single dedicated project. With CUD sharing enabled (Step 1), discounts automatically apply across all projects in the billing account.
1

Create the Dedicated Project

Go to IAM & Admin at the org levelGo to “Manage Resources”
2

Enter Project Details

Enter the following details:
  • Project name: nops-cud-purchases (or your preferred name)
  • Organization: Select your organization
  • Location: Select the appropriate folder or organization root
3

Create the Project

Click Create to create the project.
4

Link Project to Billing Account

Ensure you pick your billing account you want cud purchases in. It should align with the billing account you selected for this integration.
Save the Project ID — you’ll need it for Step 3 and Step 6.

Step 3: Enable Required APIs

1

Navigate to APIs & Services

Go to APIs & ServicesLibrary
2

Select Project

Select the nops-cud-purchases project from the top dropdown
3

Enable Required APIs

Click Enable for each of the following APIs:

Step 4: Create the Custom Role (Organization Level)

Below are the permissions you will grant to the nOps Custom Role
1

Navigate to Roles

Go to IAM & AdminRoles
2

Select Organization

Select your Organization from the top dropdown
3

Create Role

Click + Create Role on the top menu bar
4

Set Role Details

Set:
  • Title: nOps Resource Manager
  • Description: Least-privilege role for nOps to manage Compute Commitments, Quotas, and Service Usage
  • ID: nOpsResourceManager
  • Role launch stage: General Availability
5

Add Permissions

Click Add PermissionsImportClick the Enter property name or value text box and paste in the first permission in the list aboveSelect the Checkbox next to the permission and click AddClick the blue X next to the permission name you pasted in the Enter property name or value text box to remove the filterRepeat for each of the permissions in the list above
6

Create the Role

When you have finished adding all permissions, click Create to create the role.

Step 5: Organization IAM (Grant Roles to Both Identities)

While you’re still at the Organization level in IAM:
1

Navigate to IAM

Go to IAM & AdminIAM
2

Confirm Organization

Confirm your Organization is selected in the top dropdown

Grant access to the Automation Agent (Service Account)

1

Grant access to the Automation Agent (Service Account)

Click + Grant Access
2

Enter nOps Service Account email

Enter the nOps Service Account email in New principals
3

Add roles

Add roles:
  • Cloud Asset Viewer (roles/cloudasset.viewer)
  • Browser (roles/browser)
  • Recommender Viewer (roles/recommender.viewer)
  • Cloud SQL Viewer (roles/cloudsql.viewer)
  • Cloud Run Viewer (roles/run.viewer)
  • Compute Recommender Viewer (roles/recommender.computeViewer)
  • (Paid support plan only) Cloud Support Tech Support Editor (roles/cloudsupport.techSupportEditor)
4

Save

Click Save

Grant access to nOps Support

1

Grant access to nOps Support

Click + Grant Access
2

Enter nOps Support email

Enter the nOps Support email in New principals
3

Add roles

Add roles:
  • Browser (roles/browser)
  • Compute Viewer (roles/compute.viewer)
  • (Paid support plan only) Cloud Support Tech Support Editor (roles/cloudsupport.techSupportEditor)
4

Save

Click Save
No paid support plan? Skip the techSupportEditor role for both identities. You can still contact Cloud Billing Support for CUD-related issues at no cost.To check your plan: SupportOverview → look for “Your current Customer Care service.”

Step 6: Project IAM (Grant Roles to Both Identities)

1

Navigate to IAM

Go to IAM & AdminIAM
2

Select Project

Select the nops-cud-purchases project from the top dropdown

Grant access to the Automation Agent (Service Account)

1

Grant access to the Automation Agent (Service Account)

Click + Grant Access
2

Enter nOps Service Account email

Enter the nOps Service Account email in New principals
3

Add roles

Add roles:
  • Compute Viewer (roles/compute.viewer)
  • nOps Resource Manager (the custom role from Step 3)
4

Save

Click Save

Grant access to nOps Support

1

Grant access to nOps Support

Click + Grant Access
2

Enter nOps Support email

Enter the nOps Support email in New principals
3

Add roles

Add roles:
  • Compute Viewer (roles/compute.viewer)
4

Save

Click Save

Step 7: Billing Account IAM (Grant Roles to Both Identities)

1

Navigate to Billing Account Management

Go to Billing → select your billing account → Account Management
2

Show info panel

Click Show info panel in the top-right corner

Grant access to the Automation Agent (Service Account)

1

Grant access to the Automation Agent (Service Account)

Click + Add Principal
2

Enter nOps Service Account email

Enter the nOps Service Account email in New principals
3

Add roles

Add roles:
  • Billing Account Viewer (roles/billing.viewer)
  • Consumer Procurement Order Admin (roles/consumerprocurement.orderAdmin)
  • Recommender Billing Account CUD Admin (roles/recommender.billingAccountCudAdmin)
4

Save

Click Save

Grant access to nOps Support

1

Grant access to nOps Support

Click + Add Principal
2

Enter nOps Support email

Enter the nOps Support email in New principals
3

Add roles

Add roles:
  • Billing Account Viewer (roles/billing.viewer)
  • Recommender Billing Account CUD Viewer (roles/recommender.billingAccountCudViewer)
4

Save

Click Save

Terraform Setup (Alternative to Console)

If you manage GCP with Terraform or OpenTofu, you can provision everything in Steps 3–7—the required APIs, the nOps Resource Manager custom role, and the organization-, project-, and billing account-level IAM bindings for both identities—using the official nOps module. Use this path instead of the manual console instructions in Step 3 through Step 7. Repository: nops-io/terraform-gcp-nops-commitment-management Complete these steps first — they cannot be done with the module:
  1. Step 1: Enable CUD Sharing — a billing account setting that must be changed in the Console
  2. Step 2: Create a Dedicated CUD Project — the module configures an existing CUD purchase project; note the Project ID for the module input
Then configure the module inputs with your organization ID, billing account ID, CUD purchase project ID, and the nOps Service Account email and nOps Support email from nOps. Follow the README in the repository for the full list of variables, the examples/basic layout, and how to run terraform apply or tofu apply.
The repository README is the source of truth for Terraform inputs and optional settings (such as the Cloud Support Tech Support Editor role for paid support plans). If anything conflicts with this guide, follow the module documentation for Terraform-specific behavior.

Prerequisites

Configure billing exports and prepare your GCP environment.

Integration Setup

Link GCP billing data and grant service account permissions.

Permissions and Resources - Savings Analysis

Overview of all permissions and resources needed for Savings Analysis.

Permissions and Resources - Commitment Management

Overview of all permissions and resources needed for Commitment Management.