// the find
terraform-google-modules/terraform-example-foundation
Shows how the CFT modules can be composed to build a secure cloud foundation
Google's reference implementation for standing up a secure GCP organization from scratch, following the Enterprise Foundations Blueprint and built on CFT Terraform modules. It's for platform teams at large orgs who need multi-environment separation of duties (dev/nonprod/prod) managed entirely as code, not for anyone wanting a quick turnkey GCP setup.
The staged layout (0-bootstrap through 5-app-infra) enforces a correct apply order and bakes separation of duties into IAM from the start — distinct service accounts per stage, split state/CI-CD projects in bootstrap. Policy validation is wired in for real via terraform-tools and the policy-library Scorecard bundle, not just left as a suggestion in a doc. The new production_only_deploy flag is a sane concession — you can stand up just prod for evaluation or cost reasons without forking the whole 3-environment topology yourself.
In-place upgrades are explicitly unsupported — the maintainers tell you upfront that once you fork and customize this, you're alone for any future breaking change in the blueprint. Onboarding cost is real: a dozen-plus separately-applied Terraform projects, each with its own README, before you've deployed anything. CI/CD is Cloud Build by default; GitHub/GitLab/Terraform Cloud support exists only as .tf.example files you manually rename in, which is a rough edge for anyone not already on Google's own tooling. This is explicitly not meant to be referenced as a remote module, so you inherit all the Terraform and maintenance burden yourself rather than pulling updates.