This document provides a consolidated overview of organization-level how-to guides and best practices for configuring, orchestrating, and monitoring VM Manager across your Cloud de Confiance by S3NS organization or folders. You can use these guides to automate fleet-wide operating system management, enforce compliance, and centralize reporting across projects. Each entry in the following table links to detailed documentation for specific tasks:
Select a category:
| Category | Best practices | Summary |
|---|---|---|
| Setup and enablement | Enable VM Manager across a folder or organization | Enable the OS Config API across all existing and future projects in an organization or folder by using hierarchical service activation and organization policy constraints. |
| Setup and enablement | Set up VM Manager across an organization by using Terraform | Automate organization-wide VM Manager enablement, custom IAM role creation, instance metadata configuration, and OS policy assignments by using Terraform. |
| Policy orchestration | About policy orchestrator | Understand how organization-level and folder-level policy orchestrators automate progressive rollouts of OS policy assignments across projects and zones. |
| Policy orchestration | Prerequisites for using policy orchestrator | Configure the service agents, IAM permissions, and VPC Service Controls ingress rules that are required for organization-level and folder-level policy orchestration. |
| Policy orchestration | Manage OS policy assignments using policy orchestrator | Create organization-level or folder-level policy orchestrators to progressively roll out, update, or delete OS policy assignments across multiple projects and zones. |
| Policy orchestration | View, edit, and delete policy orchestrators | Inspect rollout status across your organization or folders, modify orchestration scopes, or delete existing policy orchestrators. |
| Compliance and custom data | View OS policy compliance summary for an organization or folder | Review aggregated OS policy compliance states across all projects in your organization or folder in the Cloud de Confiance console, and filter results by using the query builder. |
|
Compliance and custom data Monitoring and governance |
View custom data from OS policies for your organization | Export VM Manager and Cloud Asset Inventory data to BigQuery to query custom script outputs (strings or JSON) and enforcement error messages across all VMs in your organization. |
| Patch and vulnerability management | View vulnerability reports for your organization | Export OS inventory and vulnerability data to BigQuery by using Cloud Asset Inventory to identify and query Common Vulnerabilities and Exposures (CVEs) across your organization. |
| Patch and vulnerability management | View patch summary for VMs in an organization or folder | Monitor organization-wide or folder-wide patch compliance, available OS updates, and reboot requirements across all projects in the Cloud de Confiance console. |
| Monitoring and governance | View VM Manager status for your organization | Export Cloud Asset Inventory resource and OS inventory snapshots to BigQuery to verify VM Manager enablement, check OS Config agent versions, and audit operating system distributions across your organization. |
| Monitoring and governance | VM Manager audit logs | Monitor Admin Activity and Data Access audit logs for VM Manager operations, including organization-level and folder-level policy orchestrator actions. |
|
Monitoring and governance Policy orchestration |
Quotas and limits | Track and manage folder-level and organization-level quotas for policy orchestrators across large VM fleets. |