Google Cloud is unusual among clouds in one useful way: it already does most of the analysis for you. Google Recommender watches each project's usage and writes recommendations — this VM is idle, that one is oversized, this disk has not been attached in weeks — each with a projected saving. The hard part isn't finding waste. It is reading the recommendations where they actually live, and correcting the figures before they are added up.
This page describes what InfraSync reads from a Google Cloud project, the five corrections it makes to Google's figures, and what it needs from you. It applies the same rules as our AWS and Azure cost analysis: a claim never exceeds the data behind it, and anything that cannot be priced honestly ships at $0 rather than as a guess.
- What it reads: Google Recommender, at the right scope
- Five corrections before Google's figures become a total
- Connecting a project
- Checked before the first report
- What it does not cover yet
- Frequently asked questions
What it reads: Google Recommender, at the right scope
Each recommender lists its recommendations at particular locations — some per zone, some per region, some globally. Ask for one at the wrong location and the API answers successfully with nothing, so a guessed scope hides findings without an error. InfraSync asks each recommender at the locations Google documents for it.
| Recommendation | What the finding asks you to do |
|---|---|
| Idle VM | Stop or delete a VM that has done no meaningful work. |
| VM machine type | Resize a VM to the machine type Google recommends from its usage. |
| Managed instance group machine type | Resize a zonal group's instance template, and the group with it. |
| Idle persistent disk | Snapshot, then delete, an unattached zonal or regional disk. |
| Idle static IP | Release a reserved address that nothing uses. |
| Idle custom image | Delete an image nobody has used. |
| Committed use discount | Buy a project-level commitment, of the type Google recommends. |
| Cloud SQL | Stop an idle instance, or move an overprovisioned one to a smaller tier. |
| Cloud Run | Switch a service to instance-based billing, from last month's traffic. |
| Idle GKE cluster | Delete a cluster that runs nothing, priced at its actual 30-day cost. |
Findings come with the gcloud command that carries them out, pinned to the project they belong to.
Five corrections before Google's figures become a total
Google's projections are a good starting point and a poor total. Added up as they come, they overstate what a project will save. These are the corrections InfraSync makes.
1. Sustained use discounts make Google's VM figures too high
Google prices VM and instance-group recommendations before sustained use discounts — the automatic discount a VM earns by running for most of the month. A VM that already earns the discount saves less than Google's figure when you remove it. InfraSync scales each figure down by the family's maximum discount — 30% for N1, M1, M2, f1 and g1; 20% for N2, N2D and C2; none for the others — which gives a floor: the least the change can save. A resize between families with different discount rates, or a machine type it does not know, cannot be floored honestly. It ships at $0, with Google's own figure quoted in the finding.
2. Google prices in your billing currency
A billing account in India sees its recommendations in rupees. Reports are in US dollars, so each figure is converted at a dated exchange rate. The finding shows the original amount and the rate, and the report states every rate it used, where it came from and when. If no rate is available, the finding stays unpriced. Nothing is guessed.
3. A billing-account commitment is not one project's saving
Some committed use discounts are recommended for the whole billing account, covering every project on it. Counting one inside each project's report would add the same commitment to your total once per connected project. These appear as a note with Google's figure. Only commitments for the project itself are findings.
4. Nothing is counted twice
A GKE node is also a VM, and a VM in a managed instance group is also a member of that group. When Google recommends for the cluster or the group as well as for its VMs, the per-VM findings are folded into the cluster or group finding, with a note saying so.
5. A priced recommendation is never dropped
If Google returns a resource name in a format InfraSync does not recognise, the finding still ships, scoped to the location it was read from. It just comes without a generated command, rather than disappearing from the total.
Every priced report says what its figures are: list-price projections with the sustained-use floor applied. Your own commitments and any negotiated prices are not reflected, so the saving on your invoice can differ.
Connecting a project
A Google Cloud project connects with a key for a user-managed service account. The service account needs read-only roles on the project:
roles/viewer
roles/recommender.viewer
roles/serviceusage.serviceUsageConsumer
Two more are optional. roles/serviceusage.serviceUsageAdmin lets the Enable Recommender API button work. roles/billing.viewer, on the billing account, lets idle GKE clusters be priced. The setup on InfraSync's Connect page gives the gcloud commands for all of this, with your project ID filled in.
The key is encrypted at rest and never shown again. A project takes one slot of your plan's account allowance, exactly as an AWS account does, in any mix.
Newer Google Cloud organizations block service-account key creation by default, through the iam.disableServiceAccountKeyCreation policy. An organization administrator has to allow it for this project. Workload identity federation, which needs no key, is not supported yet.
Checked before the first report
Connecting a project proves InfraSync can see it — not that the analysis can read what it needs. So right after you connect, InfraSync repeats the analysis's own reads, Recommender and Compute Engine, and shows each one as passing, needing a fix, limited, or unknown. A fix comes with the command that makes it. If the Recommender API is switched off in the project, the fix is one button that enables that API and nothing else.
This matters most on the free plan, whose one savings check would otherwise be spent on a project the analysis cannot read.
What it does not cover yet
- Terraform and drift for Google Cloud are coming soon. Today, InfraSync does cost analysis for Google Cloud, and Terraform and drift for AWS.
- Not analysed yet: idle reservations, storage soft-delete, BigQuery and spend-based commitments.
- No schedules yet. Google Cloud analyses run when you start them.
- Recommender needs history. Google only recommends for resources it has observed for a while, so a brand-new project has little to say.
Frequently asked questions
Does it need write access to my project?
No. The roles above are read-only. The one optional exception is roles/serviceusage.serviceUsageAdmin, which lets the Enable Recommender API button switch on that one API, and nothing else.
Why is the total lower than in the Google Cloud console?
Because of the corrections above: the sustained-use floor, billing-account commitments reported as a note, and conversion to US dollars. Google's own figure stays in each finding's text, so you can always see both.
Why do some findings show $0?
Because they cannot be priced honestly — a resize across discount rates, an unknown machine type, or no exchange rate. The finding still says what to do, and quotes Google's estimate.
Can I analyse AWS and Google Cloud together?
Yes. Both connect to the same InfraSync organization and share one allowance; each account and project gets its own reports.
Try it on a project
The fastest way to see what Recommender knows about your project is to connect it to InfraSync. Access is read-only, the access checks tell you before the first report whether anything is missing, and every figure in the report says where it came from.