FAQs
What if I don't see my billing data in BigQuery?
What if I don't see my billing data in BigQuery?
- Ensure that Billing Export is enabled for the correct project.
- Check if the dataset and table names match what was configured in nOps.
- Wait up to 48 hours for the first full dataset to appear.
Can I use customer-managed encryption keys?
Can I use customer-managed encryption keys?
How often is billing data updated on nOps?
How often is billing data updated on nOps?
How long does it take for the Pricing and Detailed Resource tables to be available?
How long does it take for the Pricing and Detailed Resource tables to be available?
Do all exports need to be in the same location?
Do all exports need to be in the same location?
Why do I need to grant permissions at three different levels (Organization, Billing Account, Project)?
Why do I need to grant permissions at three different levels (Organization, Billing Account, Project)?
- Organization-level role (Compute Viewer) allows nOps to list resource-based commitment objects across your organization.
- Billing Account-level role is required to access billing metadata, currency information, and CUD recommendations at billing scope. This cannot be granted at the project level.
- Project-level roles provide access to the BigQuery dataset containing your cost export data.
Overview
- Checking if billing exports are already enabled
- Configuring GCP billing exports (if not already enabled)
1. Domain Restricted Sharing
iam.allowedPolicyMemberDomains constraint), you will encounter an error when trying to grant IAM roles to the nOps service account:
roles/orgpolicy.policyAdmin) IAM role on the organization. Contact your GCP administrator if you don’t have this role.Checking and Configuring Domain Restricted Sharing
During GCP onboarding, the integration wizard shows the Domain Restricted Sharing section in Step 1 so you can confirm whether DRS applies and act on it before granting permissions. To check whether DRS is enabled in your organization:Open the GCP Integration Wizard
Review the Domain Restricted Sharing section
iam.allowedPolicyMemberDomains policy enabled before proceeding.Go to Organization Policies
Select Organization
Find the Domain Restricted Sharing Policy
iam.allowedPolicyMemberDomains).Manage Policy
Add Value
Enter nOps Customer ID
Save
2. Link GCP Billing Data to nOps
Once billing exports are configured in GCP, connect them to nOps using the integration wizard.Open Cloud Provider Integrations
Step 1: Configure Billing Exports and Name Your Integration
iam.allowedPolicyMemberDomains policy enabled, add this Customer ID to your allowed domains now (see Domain Restricted Sharing). If DRS is not enabled in your organization, no action is needed.
Detailed Usage Cost, Pricing, and Committed Use Discounts must all be enabled. See Prerequisites if you have not configured them yet.Enter an Integration Name (e.g., “My Organization GCP Integration 1”) and click Next.Step 2: Enter Billing Account ID and Dataset IDs
XXXXXX-XXXXXX-XXXXXX (e.g., 0115B9-C18400-A979DC)
Format: project.dataset.table or project.dataset
Format: project.dataset.table or project.dataset
Format: project.dataset.table or project.dataset
Format: project.dataset.table or project.dataset. Leave this blank if you have not enabled the FOCUS billing export.Use the How to find links next to each field for guidance on locating these values.Create the Integration
gcp_billing_immutable_<BILLING_ACCOUNT_ID>_<LOCATION> (with dashes in your billing account ID replaced by underscores) and lives in the project you chose when you turned the export on. You can add it later from Settings → Cloud Provider Integrations if you enable the export after connecting.Finding Your Billing Account IDs
Navigate to Billing
Copy Billing Account ID
XXXXXX-XXXXXX-XXXXXX (e.g., 0115B9-C18400-A979DC).Finding Your BigQuery Dataset IDs
Navigate to Billing Export
gcp_billing_immutable_<BILLING_ACCOUNT_ID>_<LOCATION>.Open Dataset in BigQuery
Manage Permissions
Grant BigQuery Data Viewer Role
- In the permissions panel, click Add Principal.
- In the New principals field, enter the nOps service account email.
- In the Select a role dropdown, choose BigQuery Data Viewer (
roles/bigquery.dataViewer). - Click Save.
- Repeat for each distinct export dataset, including the FOCUS dataset (
gcp_billing_immutable_<BILLING_ACCOUNT_ID>_<LOCATION>) if you enabled that export.
3. Grant Service Account Permissions in GCP
Once the nOps service account email is generated, grant it the required permissions in the Google Cloud Console, unless you are using Terraform setup. Permissions must be granted at three different levels: Organization, Billing Account, and Project.A. Organization-Level Roles (Savings Analysis)
For the initial savings analysis setup, three organization-level roles are required. Additional roles for full resource analysis are configured later during Commitment Management setup. Required Roles:Navigate to Organization IAM
Switch to Organization
Grant Access to nOps Service Account
- Compute Viewer (
roles/compute.viewer) - Recommender Viewer (
roles/recommender.viewer) - Browser (
roles/browser) Click Save.
B. Billing Account-Level Role
This role is required for currency and billing metadata validation. It must be granted directly on the Billing Account. Required Role: Billing Account Viewer (roles/billing.viewer)
Navigate to Billing Account Management
Open the Info Panel
Grant Billing Account Viewer Role
roles/billing.viewer).
Click Save.C. Dataset-Level Roles (Cost Export Datasets)
These roles are required for reading BigQuery billing data and must be granted on each dataset that contains your cost export data:- Detailed Usage Cost dataset
- Pricing dataset
- Committed Use Discounts dataset
- FOCUS dataset: only if you entered a FOCUS Dataset ID
roles/bigquery.dataViewer)
Navigate to Billing Export
Open Dataset in BigQuery
Manage Permissions
Grant BigQuery Data Viewer Role
- In the permissions panel, click Add Principal.
- In the New principals field, enter the nOps service account email.
- In the Select a role dropdown, choose BigQuery Data Viewer (
roles/bigquery.dataViewer). - Click Save.
Repeat for Other Datasets (if different)
D. Project-Level Service Usage Role
The Service Usage Consumer role must be granted on the project that hosts your billing exports. Required Role: Service Usage Consumer (roles/serviceusage.serviceUsageConsumer)
Navigate to IAM
Select Project
Grant Service Usage Consumer Role
roles/serviceusage.serviceUsageConsumer).
Click Save.E. Project-Level BigQuery Resource Viewer Role (Optional)
roles/bigquery.resourceViewer)
Navigate to IAM
Select Project
Grant BigQuery Resource Viewer Role
roles/bigquery.resourceViewer).
Click Save.4. Enable Required APIs
Enable the following APIs in the Google Cloud Console to allow nOps to collect cost and usage data for savings analysis, unless you are using Terraform setup, which can enable them for you. APIs only need to be enabled in the project that hosts your billing exports, not across all projects. Required APIs (Savings Analysis):Navigate to APIs & Services
Select Project
Enable Required APIs
- Cloud Billing API (
cloudbilling.googleapis.com) - Recommender API (
recommender.googleapis.com)
Terraform Setup (Alternative to Console)
If you manage GCP with Terraform or OpenTofu, you can provision the organization-, billing-, project-, and BigQuery dataset-level IAM bindings for the nOps service account, and enable the required APIs on your billing export project, using the official nOps module. Use this path instead of the manual console instructions under Finding Your BigQuery Dataset IDs (BigQuery Data Viewer), Section 3, and Section 4. Repository: nops-io/terraform-gcp-nops-integration Complete the same prerequisites and nOps-side steps first:- GCP Integration Prerequisites (including billing exports)
- Domain Restricted Sharing, if it applies to your organization
- Section 2: create the integration in nOps, enter your billing export details, and copy the nOps service account email. The module uses this as an input
examples/basic layout, and how to run terraform apply or tofu apply.