Problem
providers/gcp/services/computeengine/client.go:394 lists recommendations from projects/<p>/locations/<region>/recommenders/google.billing.CostInsight.commitmentRecommender. That recommender ID doesn't exist in Google's recommender catalog (https://cloud.google.com/recommender/docs/recommenders). Resource-based CUD recommendations come from google.compute.commitment.UsageCommitmentRecommender; spend-based ones come from google.cloudbilling.commitment.SpendBasedCommitmentRecommender, which is parented on the billing account, not the project. So every region's ListRecommendations call fails whatever IAM is granted, the error is only warn-logged, and GCP Compute Engine CUD recommendations are silently empty.
Found while reviewing cloud-commitments-platform#377, whose roles/recommender.viewer grant covers the correct recommender (recommender.usageCommitmentRecommendations.list).
Fix
Use google.compute.commitment.UsageCommitmentRecommender for resource-based CUDs. If spend-based recommendations are wanted, query the billing-account-parented recommender separately. Add a test asserting the exact recommender path. Consider making a per-region failure that hits every region surface as an error instead of an empty result (fail loud).
Problem
providers/gcp/services/computeengine/client.go:394lists recommendations fromprojects/<p>/locations/<region>/recommenders/google.billing.CostInsight.commitmentRecommender. That recommender ID doesn't exist in Google's recommender catalog (https://cloud.google.com/recommender/docs/recommenders). Resource-based CUD recommendations come fromgoogle.compute.commitment.UsageCommitmentRecommender; spend-based ones come fromgoogle.cloudbilling.commitment.SpendBasedCommitmentRecommender, which is parented on the billing account, not the project. So every region's ListRecommendations call fails whatever IAM is granted, the error is only warn-logged, and GCP Compute Engine CUD recommendations are silently empty.Found while reviewing cloud-commitments-platform#377, whose
roles/recommender.viewergrant covers the correct recommender (recommender.usageCommitmentRecommendations.list).Fix
Use
google.compute.commitment.UsageCommitmentRecommenderfor resource-based CUDs. If spend-based recommendations are wanted, query the billing-account-parented recommender separately. Add a test asserting the exact recommender path. Consider making a per-region failure that hits every region surface as an error instead of an empty result (fail loud).