Before you begin
- Create custom rules using Rego and upload rules to a Cloud Storage bucket.
- Enable the following APIs in your Google Cloud project where you create and run the evaluation:
- Service Usage API
- Cloud Monitoring API
Required roles
For more information about the required IAM roles, see required permissions to create and run an evaluation.
Evaluate workloads using custom rules
To create a workload evaluation using custom rules, follow these steps:
In the Google Cloud console, go to the Workload Manager page.
Go to Workload Manager.
Select a Google Cloud project.
If prompted, to enable the required API for Workload Manager, click Enable.
Click New evaluation.
On the Evaluation details page, do the following:
- For Evaluation name, enter a name for the workload evaluation.
- For Description, enter a description for the workload evaluation.
- For Workload type, select General.
- Select the Cloud Storage bucket containing the custom rules.
- Optional: To export evaluation results to BigQuery dataset, select Save evaluation results to BigQuery dataset and specify the name of the dataset.
- Optional: To create a separate table for each evaluation, click Create a new results table for this evaluation.
Click Continue.
On the Evaluation scope page, select the resources that you want to include in the evaluation.
Click Continue.
On the Evaluation rules page, select the custom rules you want to validate the selected resources against.
On the Scheduling page, select the schedule for your evaluation to run.
Click Continue.
On the Notifications page, select the notification channel and select the events for which you want to receive notifications.
Click Continue.
Review the evaluation settings and click Create.
Run the evaluation
To run a workload evaluation, follow these steps:
In the Google Cloud console, go to the Workload Manager page.
Go to Workload Manager.
Click the Evaluation name.
On the Evaluation information page, click Run. A workload evaluation takes a few minutes to complete. There might be evaluations that aren't completely real-time due to the time it takes for an evaluation to complete.
What's next
- Learn more about workload evaluations