DevOps on Google Cloud, part 5: Pipelines and observability — Cloud Build and the operations suite
Part 5from the DevOps on Google Cloud series · 6 parts in all
Part 5: the two loops. GCP's native delivery is Cloud Build + Cloud Deploy; its observability suite (Logging, Monitoring, Trace, Error Reporting) is the most "it just works" of the three clouds because GKE and Cloud Run emit structured telemetry without an agent.
The delivery loop: Cloud Build
MapleCart's build: test, containerize, push to Artifact Registry, deploy to Cloud Run —
all defined in cloudbuild.yaml living beside the code:
# cloudbuild.yaml - triggered on push to main
steps:
- name: 'python:3.12'
entrypoint: bash
args: [-c, 'pip install -r requirements.txt && pytest'] # test first
- name: 'gcr.io/cloud-builders/docker'
args: ['build', '-t',
'us-central1-docker.pkg.dev/maplecart/web/web:$SHORT_SHA', '.']
- name: 'gcr.io/cloud-builders/docker'
args: ['push',
'us-central1-docker.pkg.dev/maplecart/web/web:$SHORT_SHA']
- name: 'gcr.io/google.com/cloudsdktool/cloud-sdk'
entrypoint: gcloud
args: ['run', 'deploy', 'maplecart-web',
'--image', 'us-central1-docker.pkg.dev/maplecart/web/web:$SHORT_SHA',
'--region', 'us-central1']
images:
- 'us-central1-docker.pkg.dev/maplecart/web/web:$SHORT_SHA'
options: { logging: CLOUD_LOGGING_ONLY }
# Wire the trigger (or connect the repo in the console):
gcloud builds triggers create github --name maplecart-main \
--repo-name maplecart --repo-owner maplecart-org \
--branch-pattern='^main$' --build-config=cloudbuild.yaml
Cloud Run's revision-based deploys give canary analysis for free: each deploy is a new revision; split traffic 5% to the new revision, watch the error-rate metric, then promote — or roll back with one command, since revisions are immutable:
gcloud run services update-traffic maplecart-web --to-revisions=web-00042=10,web-00041=90
gcloud run services update-traffic maplecart-web --to-latest # promote
gcloud run services update-traffic maplecart-web --to-revisions=web-00041=100 # instant rollback
The feedback loop: the operations suite
Cloud Run and GKE emit request logs, structured JSON, and latency metrics natively — no agent to install. The alerts that matter, on symptoms:
# p95 latency and 5xx rate on the Cloud Run service
gcloud alpha monitoring policies create --policy-from-file=alert-p95.yaml
# alert-p95.yaml (abridged):
# conditions:
# - conditionThreshold:
# filter: metric.type="run.googleapis.com/request_latencies"
# resource.type="cloud_run_revision"
# comparison: COMPARISON_GT > threshold: 800 # ms, p95
# duration: 300s
# notificationChannels: [projects/maplecart/notificationChannels/12345]
Error Reporting deserves its own sentence: it clusters exceptions across services by stack shape, counts occurrences, and emails you when a new error appears — catching the "we deployed and something new started failing" case that metrics alarms alone miss.
Next: the finale — MapleCart's whole stack, one terraform apply, on the cloud
with the smallest catalog and the sharpest defaults.