Cloud integration
Google Cloud
Connect Google Cloud via Billing Export to BigQuery by granting IAM roles to OptCloud's published service account. No key file ever needs to leave your project.
Billing Export (BigQuery) + IAM grant to OptCloud's service account (no keys)
Read-only
After the first successful billing export load (often same day)
How OptCloud connects with GCP
Google Cloud's recommended path for detailed cost data is Billing Export into BigQuery. OptCloud operates a single, published service account identity; instead of creating a new service account and handing us a JSON key, you enable standard or detailed export and grant our service account the read-only IAM roles it needs directly on your dataset and project. We normalize GCP line items alongside AWS and Azure so FinOps teams see one ledger.
Required permissions (read-only)
- BigQuery Data Viewer, granted to OptCloud's service account, on the dataset that receives billing export
- BigQuery Job User, granted to OptCloud's service account, on the project used to run queries
- Billing Account Viewer (optional) for account-level metadata
- Compute Viewer / Kubernetes Engine Viewer (optional) for rightsizing inventory
OptCloud does not need Billing Account Administrator and never asks you to create a service account key on our behalf. Access is entirely via IAM roles granted to our published service account identity.
Standard vs. Detailed export — what you see, and when
Standard usage cost export gives project- and SKU-level totals and is enough for high-level FinOps reporting. Detailed usage cost export adds resource-level labels and is required for rightsizing and idle-resource recommendations. Export rows are not instantaneous — the first rows typically land in BigQuery within a few hours of enabling export, and OptCloud's next scheduled sync picks them up automatically. Until then, you'll see limited or no data for that billing account.
Connecting multiple projects (Billing Accounts and Organizations)
A single Cloud Billing export covers every project linked to that Billing Account, so connecting one export gives OptCloud visibility into all projects under it — no per-project setup needed. If your company uses a GCP Organization with multiple Billing Accounts (e.g. per business unit), repeat the export + IAM grant steps for each Billing Account you want visible in OptCloud, and assign each connection to the right team or workspace.
Create a connection
- 1
Enable Cloud Billing Export
In Google Cloud Console, open Billing → Billing export. Enable Standard and/or Detailed usage cost export into a BigQuery dataset you control.
- 2
Grant OptCloud's service account access
In IAM & Admin, add the OptCloud service account shown on the Cloud Accounts → Add account → GCP screen (e.g. optcloud-hub-connector@optcloud-hub-XXXXXX.iam.gserviceaccount.com). Grant it BigQuery Data Viewer on the export dataset and BigQuery Job User on the project used to run queries — no key or secret ever leaves your project.
- 3
Enter project and dataset details
In OptCloud, provide the billing account ID, export project, dataset name, and table prefix. OptCloud validates it can run a test query using its own credentials.
- 4
Wait for export rows
Billing export is not instantaneous — allow a few hours for the first rows. Once rows appear in BigQuery, OptCloud's next sync populates Cost Explorer and recommendations.
- 5
Confirm CUD and BigQuery cost views
Validate Committed Use Discount coverage views and BigQuery query/slot cost intelligence once data is flowing.
Backfilling historical billing data
Cloud Billing export only writes rows going forward from when it's enabled — Google does not backfill export tables retroactively. For historical totals prior to enabling export, OptCloud can use the Cloud Billing budgets/reports API where available, but full resource- and label-level detail is only guaranteed from the export start date onward. Enable export as early as possible to maximize the historical window you'll be able to analyze in detail later.
Data collected
- Billing export line items (service, SKU, project, labels, credits)
- Optional GCE/GKE inventory for rightsizing
- CUD inventory for commitment planning
What you get in OptCloud
- Project- and label-level cost allocation
- BigQuery cost intelligence (bytes scanned / slot oriented views)
- CUD sizing recommendations from sustained usage
- Cross-cloud normalization with AWS and Azure
Filterable dimensions
Once connected, you can filter and group cost data in Cost Explorer and Reports by:
- Project — project name and ID
- Category — compute, storage, network, database, other (OptCloud's normalized category)
- Service / SKU — e.g. Compute Engine, Cloud Storage, BigQuery
- Location — region or multi-region
- Resource — specific resource ID where the export includes it
- Label / Not labeled — any GCP resource label key and value
- Cost type — usage, tax, adjustment, CUD/commitment amortization
Updating or rotating your connection
Because access is granted via IAM roles on OptCloud's fixed service account rather than a key you issued, there's no customer-side secret to rotate. If OptCloud needs an additional role (for example, to add inventory-based recommendations later), we'll tell you exactly which IAM role to grant and to which resource — existing cost sync keeps working while you do. To revoke access entirely, remove OptCloud's service account from IAM on the dataset, project, or Billing Account.
Troubleshooting
BigQuery permission denied
Ensure OptCloud's service account was granted both BigQuery Data Viewer on the export dataset and BigQuery Job User on the query project. Data Viewer alone is not enough without Job User.
Detailed vs standard export
Detailed export enables richer resource-level analysis. Prefer detailed when available; standard still supports high-level FinOps reporting.
Related integrations
Ready to connect GCP?
Open the dashboard to add the account, or book a walkthrough with our team.