Google Cloud integration
Private betaGoogle Cloud cost management, keyless from BigQuery
The Google Cloud integration is in private beta — enabled per organization on request. Ask us to turn it on, and GCP spend joins the same ledger, dashboards, and allocation as your other clouds.
The connection is keyless: you grant a CloudQuell service account two read-only BigQuery roles and access works through Workload Identity Federation. No key, secret, or password ever changes hands — there is nothing to store, rotate, or leak.
What CloudQuell ingests
Your BigQuery Detailed usage cost export — the same invoice-grade record Google bills you from.
- Detailed usage cost export
- Read directly from BigQuery, down to project and SKU. This is Google's invoice-grade billing export, not an estimate.
- Projects & labels
- Each project lands as its own sub-account; resource and project labels merge into tags (resource labels win on conflicts) for allocation and tag coverage.
- Committed Use Discounts
- CUD-covered usage lands with its commitment identity, so GCP counts toward commitment coverage and Effective Coverage %.
- FOCUS: on the roadmap
- CloudQuell reads the Detailed export today; Google's FOCUS export is still preview, and FOCUS support here is on the roadmap.
What the data looks like normalized
A BigQuery export row lands on the same schema as an AWS line item — project as sub-account, labels as tags.
| Normalized field | GCP source | Example |
|---|---|---|
| Date | BigQuery export day | 2026-08-04 |
| Provider | constant | GCP |
| Service | service + SKU | Compute Engine |
| Scope | project | prod-analytics |
| Cost (USD) | detailed export | $438.90 |
| Usage | usage amount | 512 hrs |
| Attribution | resource / project labels | team=data |
How it connects
Keyless. You grant a service account two read-only BigQuery roles — there is no key to store, rotate, or leak.
- Credential
- None to hand over. Access works through Google's Workload Identity Federation: you grant CloudQuell's service-account email BigQuery Job User on the export project and BigQuery Data Viewer on the export dataset. Revoking those grants revokes CloudQuell.
- Access scope
- Read-only, scoped to the billing export dataset — no access to any other dataset or resource. Nothing is written back; the connect step runs a BigQuery dry-run that scans no data.
- Setup
- Three steps: enable the Detailed usage cost export, grant the two IAM roles, then enter the billing-account, project, and dataset and verify. Costs typically appear within minutes.
- Time to first data
- Google backfills only the current and previous month on a new export, and a fresh export takes 24–48 hours to populate; history grows forward. Daily sync re-pulls the current and previous invoice months.
What it unlocks (in beta)
During the beta, GCP spend flows into the same views as the rest of your bill, with two roadmap gaps noted.
One ledger
GCP spend by project, service, SKU, and label in the same dashboard, reports, and cost centers as AWS, Snowflake, and your AI spend.
Allocation
Projects as sub-accounts and labels as tags feed the same allocation rules and cost-center hierarchy as everything else.
How allocation works →Budgets & anomalies
Budget thresholds, trend and anomaly rules cover GCP spend, routed to the channel your team already watches.
Commitments
CUD coverage counts toward Effective Coverage %. CUD expiry alerts and savings recommendations aren't covered yet.
Effective Coverage % →
Common questions
- Is the Google Cloud integration available now?
- It is in limited availability (private beta), enabled per organization on request. When it is on, reporting, budgets, allocation, alert rules, anomaly detection, and committed-use-discount coverage all include GCP spend; savings recommendations remain AWS-only and CUD expiry alerts are not covered yet. Email us to enable it for your org.
- How does CloudQuell connect to GCP?
- Keyless, through Workload Identity Federation. You grant CloudQuell's service account two read-only BigQuery roles — Job User on the export project and Data Viewer on the export dataset — and nothing else. There is no key or secret to store or rotate; removing the two IAM grants revokes access.
- What GCP data does it read?
- The Detailed usage cost export in BigQuery — Google's invoice-grade billing record, down to project and SKU. Projects appear as sub-accounts and resource and project labels arrive as tags. Google's FOCUS export is still preview, so CloudQuell reads the Detailed export today; FOCUS support is on the roadmap.
- How far back does GCP history go?
- Google backfills only the current and previous month when an export is first enabled, and a new export takes 24–48 hours to populate — so history grows forward from there. If you have already been exporting billing to BigQuery, you get that full history.
GCP is in private beta, enabled per organization on request. Free under $10K/month of tracked spend once it is on.