Trust is earned, not given

A different perspective

2018-12-11 · Projects

DevOps on Google Cloud, part 1: The map — services and how they fit together

Part 1from the DevOps on Google Cloud series · 6 parts in all

Third series, same three companies — MapleCart, FleetView, NewsGrid — now on Google Cloud. GCP has the smallest service catalog of the three majors and the deepest networking; that combination makes its map the easiest to hold in your head. Part 1: the pieces and their relationships.

The layered model, in GCP terms

  1. Identity — Cloud IAM, built on the strongest foundation of the three clouds: everything (including humans) is a member (user, group, service account), and roles bind members to permissions on resources. No separate "user" versus "workload" system. Workload Identity extends service accounts to Kubernetes pods.
  2. Compute — Compute Engine (VMs), Google Kubernetes Engine (GKE — the birthplace of Kubernetes, still the most managed K8s of the three clouds), Cloud Run (container-to-HTTPS with scale-to-zero), and Cloud Functions.
  3. Data — Cloud SQL (managed MySQL/Postgres/SQL Server), AlloyDB (Postgres-compatible, high performance), Firestore/Bigtable (NoSQL), Cloud Storage, and Memorystore (Redis).
  4. Network — VPC (global by default — a genuinely different design), firewall rules, Cloud Load Balancing (one global anycast IP), Cloud DNS.
  5. Delivery — Cloud Build + Cloud Deploy, Artifact Registry; or GitHub Actions, as in the other series.
  6. Observability — Cloud Logging + Cloud Monitoring (the former Stackdriver), unified across GCP and even AWS/Azure VMs.

The request path

One global load balancer with one anycast IP fronts MapleCart worldwide: DNS resolves www.maplecart.example to the Global External HTTP(S) Load Balancer (with Cloud CDN and Cloud Armor WAF attached as back-end services), which routes to a Cloud Run service or GKE workload in the region nearest the user; the app talks to Cloud SQL over a private IP via Private Services Access, authenticated as its service account; logs and metrics flow to Cloud Logging/Monitoring, whose alerting policies page you. One sentence, same skeleton — but note the load balancer is global-by-default, not per-region.

The three companies

Next: compute — where GCP's "containers first" personality is most visible.