Skip to content
Mekas Cloud Services
Cloud

Labeling Google Cloud Platform Resources

Mekas Cloud Services
Developer reviewing code on screen while managing cloud resources

Do you run and manage applications on the Google Cloud Platform (GCP)? Do you need to group and classify your GCP resources to satisfy compliance requirements? Is your finance team asking for visibility on which team is spending where and how? Do you want to track GCP resource utilization by team and engineer? If you answered yes to any of these questions, you’ll be glad to know that GCP provides multiple ways to annotate your resources to make them easier to track: security marks, labels, and network tags.

While each annotation has different functionality and scope, they are not mutually exclusive — you’ll often use a combination of them to meet your requirements.

Security marks

Security marks provide a method for annotating assets within Cloud Security Command Center (Cloud SCC), enabling searching, selection, or filtering using the mark.

Main use cases include:

  • Classifying and organizing assets and findings independent of resource-level labeling, including multi-parented groupings
  • Tracking violation severity and priority
  • Integrating with workflow systems for assignment and resolution of incidents
  • Enabling differentiated policy enforcement on resources, projects, or groups of projects
  • Enhancing security-focused insights into your resources — e.g., clarifying which publicly accessible buckets are within policy and which are not

Marks are key-value pairs supported by a number of resources and are only visible from Cloud SCC. Edit or view access requires the securityCenter.editor IAM role, independently of roles and permissions on the underlying resource.

Labels

Labels are key-value pairs supported by numerous GCP resources. They enable tracking spending in exported billing data and filtering or grouping resources for various applications, such as identifying test environment resources versus production ones.

With labels you can:

  • Identify resources used by individual teams or cost centers
  • Distinguish deployment environments (prod, stage, QA, test)
  • Identify owners and state
  • Use for cost allocation and billing breakdowns
  • Monitor resource groups via Cloud Monitoring, using labels accessible in resource metadata

Keys must be 1–63 characters, contain only lowercase letters, numeric characters, underscores, and dashes, and start with a lowercase letter or international character. The key portion of a label must be unique per resource.

Network tags

Network tags apply to instances and are the means for controlling network traffic to and from a VM instance. On GCP networks, tags identify which VM instances are subject to firewall rules and network routes.

Using tags, you can create additional isolation between subnetworks by selectively allowing only certain instances to communicate. Tags can be added or removed using gcloud commands, Cloud Console, or API calls:

gcloud compute instances add-tags [INSTANCE_NAME] --tags production,web

Note that network tags can be modified by anyone in your org who has the Compute InstanceAdmin role. For stricter control, use service accounts as the basis for firewall rules instead of tags.

On your mark, get set, go

If you manage a big, complex environment, you know how hard it can be to keep track of all your GCP resources. Security marks, labels, and network tags can make that task a little bit easier. Our cloud services team helps organizations govern and secure GCP resources at scale — talk to the Mekas team about tracking and governing resources in your environment.

Take the next step to start your journey with us

Transform your IT challenges into tailored solutions with expert support, 24/7.