Ultimate access to all questions.
Your team needs to ensure that Compute Engine instances in your production project cannot have public IP addresses, except for the frontend application instances which require them. The product engineers have the Editor role and can modify resources. How can your team enforce this requirement?