Skip to main content

Google Cloud Troubleshooting

This guide lists common symptoms, likely causes, and actions you can take before escalating to Cloudaware Support.

Service Account Status Is Yellow or Red

Symptoms

  • The service account in Cloudaware shows yellow or red status.
  • Error messages indicate missing access to organizations or that the service account cannot be found.

Checks

  • In the Google Cloud console:
    • Confirm that the service account still exists and has not been disabled or deleted.
    • Verify that the required viewer and optional roles are still attached at the project/folder/organization level.
  • Confirm that the JSON key used in Cloudaware matches an active key for the service account.

If you rotate keys, upload the new key in Cloudaware and remove unused keys on the GCP side.

Projects Discovered but Not Collected

Symptoms

  • Projects appear in the Projects tab but do not show resources in CMDB.
  • The Service Account Assignment column shows none or warning indicators.

Resolution

  • In Cloudaware Google Cloud Platform → the Projects tab:
    • Assign the service account to the relevant organization, folder, or project.
    • Ensure the service account has sufficient IAM permissions on those scopes.

New projects under assigned parents will inherit collection after the next discovery cycle.

Missing Specific Services (GKE, Billing, SCC, Backups, Tagging)

Symptoms

  • Core compute and storage resources appear, but certain services are empty or partially populated.

Checks

  • Review Least-Privilege Policies and confirm that:
    • Organization/folder viewer roles are granted for hierarchy where needed.
    • roles/billing.viewer is assigned to the service account for relevant billing accounts.
    • Custom roles for backups and tagging are configured and attached.
    • Required APIs (Kubernetes Engine, Cloud Billing, SCC, etc.) are enabled in the relevant projects.

Changes to IAM roles or API enablement can take time to propagate; allow at least 15–30 minutes and re‑check.

API or Quota Issues

Symptoms

  • Errors mention disabled APIs or quota exceeded.
  • Discovery appears slower than expected in large environments.

Resolution

  • Ensure all required APIs are enabled for the projects where the service account operates.
  • Monitor GCP API quotas for the relevant services; increase quotas if persistent limits are reached.
  • Coordinate with Cloudaware Support if you see consistent quota‑related errors across services or projects.

Still Stuck?

If issues persist after these checks, collect the following details:

  • Screenshots of service account IAM roles and API enablement.
  • Example project IDs and resource IDs that are missing.
  • Error text or screenshots from Cloudaware Admin.

Contact Cloudaware Support at support@cloudaware.com and include these details to help shorten time to resolution.