DevOps on Google Cloud, part 1: The map — services and how they fit together
Part 1from the DevOps on Google Cloud series · 6 parts in all
Third series, same three companies — MapleCart, FleetView, NewsGrid — now on Google Cloud. GCP has the smallest service catalog of the three majors and the deepest networking; that combination makes its map the easiest to hold in your head. Part 1: the pieces and their relationships.
The layered model, in GCP terms
- Identity — Cloud IAM, built on the strongest foundation of the three clouds: everything (including humans) is a member (user, group, service account), and roles bind members to permissions on resources. No separate "user" versus "workload" system. Workload Identity extends service accounts to Kubernetes pods.
- Compute — Compute Engine (VMs), Google Kubernetes Engine (GKE — the birthplace of Kubernetes, still the most managed K8s of the three clouds), Cloud Run (container-to-HTTPS with scale-to-zero), and Cloud Functions.
- Data — Cloud SQL (managed MySQL/Postgres/SQL Server), AlloyDB (Postgres-compatible, high performance), Firestore/Bigtable (NoSQL), Cloud Storage, and Memorystore (Redis).
- Network — VPC (global by default — a genuinely different design), firewall rules, Cloud Load Balancing (one global anycast IP), Cloud DNS.
- Delivery — Cloud Build + Cloud Deploy, Artifact Registry; or GitHub Actions, as in the other series.
- Observability — Cloud Logging + Cloud Monitoring (the former Stackdriver), unified across GCP and even AWS/Azure VMs.
The request path
One global load balancer with one anycast IP fronts MapleCart worldwide: DNS resolves
www.maplecart.example to the Global External HTTP(S) Load Balancer
(with Cloud CDN and Cloud Armor WAF attached as back-end services), which routes to a
Cloud Run service or GKE workload in the region nearest the user; the app
talks to Cloud SQL over a private IP via Private Services
Access, authenticated as its service account; logs and metrics flow
to Cloud Logging/Monitoring, whose alerting policies page you. One sentence,
same skeleton — but note the load balancer is global-by-default, not per-region.
The three companies
- MapleCart: Cloud Run for the storefront (containers without cluster management), Cloud SQL Postgres, Cloud Storage + Cloud CDN for images, Memorystore for sessions.
- FleetView: GKE Autopilot (Google runs the nodes' management; you run workloads) for the microservice fleet, Firestore in Native mode for telemetry (its real-time sync is a genuine differentiator), Pub/Sub between services.
- NewsGrid: Cloud Run (scale to zero, scale to thousands on the viral spike — Cloud Run's concurrency-per-instance model absorbs bursts elegantly) + Cloud Storage for the static site behind the same global LB.
Next: compute — where GCP's "containers first" personality is most visible.