Professional Cloud Architect flashcards
137 free flashcards. Tap a card to flip it.
Real-time Stream Processing Pipeline
Flip cardAn architectural pattern for processing continuous, high-volume data streams as they arrive, enabling immediate analysis, anomaly detection, and operational insights.
- Ingestion: Pub/Sub (scalable messaging)
- Processing: Dataflow (serverless stream/batch processing)
- Storage/Analysis: BigQuery (serverless data warehouse for streaming data)
- Enables immediate insights and reactions
Memory trick: Pub/Sub > Dataflow > BigQuery: Stream to Insight, Instantly.
Cloud SQL
Flip cardA fully managed relational database service on Google Cloud that supports MySQL, PostgreSQL, and SQL Server.
- Managed relational database service
- Supports MySQL, PostgreSQL, SQL Server
- High availability with automatic failover
- Automated backups and patching
Memory trick: Cloud SQL is like a 'SQL butler' that manages your database for you.
Dedicated Interconnect
Flip cardA physical, direct connection between your on-premises data center and Google's network, offering private, high-bandwidth, and low-latency connectivity, bypassing the public internet.
- Physical direct connection
- Highest bandwidth and lowest latency
- Bypasses public internet for increased security and performance
Memory trick: Dedicated Interconnect is your private express lane to Google Cloud.
Filestore Enterprise
Flip cardA fully managed, highly available, and scalable Network File System (NFS) service on Google Cloud, designed for enterprise workloads.
- Shared file storage (NFS)
- Extremely low latency and high IOPS
- Regional availability with zone-level replication
- Suitable for enterprise applications, GKE, SAP
Memory trick: Filestore is where files are stored and shared, like a digital office cabinet.
Cloud Storage Multi-Regional + Cloud CDN
Flip cardA combination of Google Cloud services for highly available, globally accessible, and low-latency delivery of static content.
- Cloud Storage Multi-Regional provides geo-redundancy and high availability.
- Cloud CDN caches content at Google's edge locations worldwide.
- Ideal for static assets, media, and web content with global users.
Memory trick: Store it globally, cache it locally, deliver it swiftly.
Cloud Run
Flip cardA fully managed, serverless platform for deploying and scaling containerized applications. It automatically scales from zero to handle traffic and charges only for the resources consumed during active requests.
- Serverless container execution
- Scales automatically from zero
- Pay-per-use billing (cost-efficient)
- Ideal for stateless microservices and web hooks
Memory trick: Cloud Run: Scale from Zero, Pay for Use, Grow Like Crazy.
BigQuery
Flip cardA fully managed, serverless, and highly scalable enterprise data warehouse that enables super-fast SQL queries using the processing power of Google's infrastructure.
- Petabyte-scale analytics
- Serverless and fully managed
- Columnar storage for optimal query performance
Memory trick: For huge data, BigQuery makes queries fly fast.
Cloud Spanner
Flip cardA globally distributed, strongly consistent, and horizontally scalable relational database service designed for transactional workloads at petabyte scale and high availability.
- Globally distributed with strong consistency
- Horizontally scalable (automatic sharding)
- Relational model with SQL support
Memory trick: Spanner stretches your relational data across the globe with strong consistency.
Private Google Access
Flip cardA feature that allows VMs with only internal IP addresses (no external IP) to reach Google APIs and services, such as Cloud Storage and BigQuery, over Google's internal network.
- Enables private communication to Google services
- Bypasses the public internet
- Reduces egress costs and improves performance
Memory trick: Private Google Access keeps your data within Google's fast lanes.
Google Cloud VPC Multicast Support
Flip cardGoogle Cloud's Virtual Private Cloud (VPC) networks do not natively support UDP multicast traffic.
- VPC networks are unicast-only
- Multicast applications require re-architecture
- Alternatives include centralized discovery services (DNS, Consul)
- Impacts legacy applications relying on multicast
Memory trick: GCP VPC says 'NO' to multicast, only 'one-to-one' allowed.
VPC Service Controls + Context-Aware Access
Flip cardA powerful combination of Google Cloud security controls to create secure perimeters around sensitive data (VPC Service Controls) and enforce granular access based on user context (Context-Aware Access).
- VPC Service Controls prevent data exfiltration and isolate services.
- Context-Aware Access (BeyondCorp) provides identity- and context-based authorization.
- Ideal for highly regulated industries and sensitive data workloads.
Memory trick: Perimeters keep data in, Context keeps bad actors out.
Cloud Storage Archive
Flip cardA Google Cloud Storage class optimized for long-term data archiving with very infrequent access (less than once a year) at the lowest storage cost.
- Lowest storage costs among all classes
- Designed for data accessed less than once a year
- Higher data retrieval costs and latency compared to other classes
- Ideal for compliance archives, long-term backups
Memory trick: Archive is for archives, rarely seen, lowest fee.
Persistent Disk Extreme (SSD)
Flip cardA Google Cloud block storage option offering the highest IOPS and throughput performance, lowest latency, and guaranteed performance for mission-critical applications and databases.
- Highest performance tier of Persistent Disk.
- Guaranteed IOPS and throughput, provisioned independently of disk size.
- Ideal for transactional databases, data warehouses, and high-performance computing (HPC).
- More expensive than other Persistent Disk types.
Memory trick: Extreme disks drive database speed.
Google Kubernetes Engine (GKE)
Flip cardA managed service for deploying, managing, and scaling containerized applications using Kubernetes, offering automated operations and advanced orchestration features.
- Managed Kubernetes clusters
- Automated deployment, scaling, healing
- Service discovery and load balancing
- Supports multi-region/multi-cluster deployments
Memory trick: GKE: Master of the Container Ships, Sailing Globally.
Streaming Data Pipeline
Flip cardA series of interconnected services designed to ingest, process, and analyze data in real-time as it is generated, typically involving messaging, processing, and storage components.
- Ingestion: Pub/Sub for high-throughput messaging.
- Processing: Dataflow for unified streaming/batch transformations.
- Storage: BigQuery for scalable analytical data warehousing.
Memory trick: Pub/Sub gets the stream, Dataflow processes the flow, BigQuery holds the big data.
GKE Autopilot
Flip cardA fully managed mode of Google Kubernetes Engine (GKE) where Google manages the cluster's underlying infrastructure, including nodes, scaling, and upgrades.
- Minimizes operational overhead for Kubernetes clusters.
- Automatically provisions and scales nodes based on workload.
- Supports various workloads, including those requiring GPUs.
Memory trick: For containers with GPUs, Autopilot takes the wheel, so you can focus on the code.
Compute Engine with Customization
Flip cardGoogle Cloud's Infrastructure-as-a-Service (IaaS) offering, allowing users to create and run virtual machines with extensive customization options for machine types, GPUs, storage, and operating systems.
- Provides the highest level of control over underlying infrastructure.
- Supports various GPU types and custom kernel modules for specialized workloads.
- Offers committed use discounts for significant cost savings on stable workloads.
- Requires manual management of VMs and operating systems.
Memory trick: Compute Engine delivers precise control for custom research.
GKE Standard Node Pools
Flip cardIn GKE Standard mode, node pools allow users to define groups of nodes with specific machine types, disk sizes, and other configurations, providing granular control over the underlying compute resources.
- User-managed nodes in GKE Standard
- Customizable machine types, GPUs, disks
- Essential for precise resource allocation
- Supports specific hardware requirements
Memory trick: GKE Standard: Fine-Tune Your Nodes, Control Your Destiny.
Memorystore for Redis Cluster
Flip cardA fully managed Google Cloud service providing a highly available, scalable, and low-latency in-memory data store compatible with Redis Cluster, ideal for caching, session management, and real-time analytics.
- Sub-millisecond latency for reads and writes.
- Horizontal scaling with Redis Cluster protocol compatibility.
- High availability with automatic failover.
- Fully managed service, reducing operational overhead.
Memory trick: Memorystore Redis clusters speed up global gaming sessions.
VPC Service Controls
Flip cardA Google Cloud feature that creates security perimeters around sensitive data to mitigate data exfiltration risks.
- Creates security perimeters for Google Cloud services
- Restricts data movement between perimeters and outside
- Prevents unauthorized access from outside the perimeter
- Crucial for compliance (e.g., HIPAA, PCI DSS)
Memory trick: VPC Service Controls protect sensitive data like a fortress wall, and CMEK guards the keys.
Customer-Managed Encryption Keys (CMEK)
Flip cardAn encryption option in Google Cloud where customers provide and manage their own encryption keys, which are then used by Google Cloud services to encrypt data at rest.
- Provides greater control over encryption keys and key rotation.
- Keys are managed in Cloud Key Management Service (KMS).
- Used by many Google Cloud services for data at rest encryption.
Memory trick: Encrypt with your key, audit every step, for sensitive data's safe keep.
RTO & RPO
Flip cardRecovery Time Objective (RTO) is the maximum acceptable downtime after a disaster. Recovery Point Objective (RPO) is the maximum acceptable data loss after a disaster. These define DR strategy requirements.
- RTO: How quickly you must recover.
- RPO: How much data you can afford to lose.
- Lower RTO/RPO typically means higher cost and complexity.
Memory trick: RTO is 'time to get up', RPO is 'data lost, oh no!'
Global External HTTP(S) Load Balancer
Flip cardA global, proxy-based Layer 7 load balancer for HTTP(S) traffic that distributes requests to backends in different regions, routing users to the closest healthy instance.
- Global reach, single IP address
- Layer 7 (HTTP/S) traffic
- Routes to closest healthy backend
- Provides SSL/TLS termination
Memory trick: Global Web Routes: Closest Server, Happiest User.
Hybrid Network Firewall Inspection
Flip cardAn architectural pattern on Google Cloud that uses Gateway Load Balancer to transparently redirect and distribute hybrid network traffic (on-prem to cloud) to a pool of virtual firewall appliances for centralized security inspection.
- Uses Gateway Load Balancer for transparent redirection
- Distributes inspection load across multiple firewall VMs
- Centralized inspection for hybrid connectivity
- Prevents bottlenecks, ensures scalability and high availability
Memory trick: Gateway LB + Firewalls: Bridge to Cloud, Scan Everything, No Bottlenecks.
Cloud Storage Classes
Flip cardGoogle Cloud Storage offers various storage classes (Standard, Nearline, Coldline, Archive) to optimize cost and performance based on data access frequency and retrieval time requirements.
- Standard: Frequent access, lowest retrieval cost.
- Nearline: Approx. once a month access, 30-day minimum, seconds-level retrieval.
- Coldline: Less than once a month access, 90-day minimum, minutes-level retrieval.
- Archive: Less than once a year access, 365-day minimum, hours-level retrieval.
Memory trick: Hot videos go Standard, cool videos go Coldline, forgotten videos go Archive.
Preemptible VMs
Flip cardLow-cost Compute Engine instances that can be preempted (terminated) by Google Cloud if resources are needed elsewhere, ideal for fault-tolerant batch jobs.
- Significant cost savings (up to 80% off standard VMs)
- Instances can be terminated with 30-second notice
- Maximum run time of 24 hours
- Suitable for batch processing, fault-tolerant workloads
Memory trick: Preemptible VMs get preempted, but save money for jobs that don't mind a restart.
Real-time Personalization Architecture
Flip cardAn architecture designed to deliver immediate, customized user experiences by processing user behavior data in real time, leveraging services for ingestion, stream processing, low-latency feature serving, and model inference.
- Ingestion: Pub/Sub (high-throughput messaging)
- Stream Processing: Dataflow (real-time data transformations)
- Feature Serving: Bigtable (low-latency access to features/profiles)
- Model Inference: AI Platform (real-time prediction service)
Memory trick: Pub/Sub + Dataflow + Bigtable + AI: Instant Personal Touch.
Artifact Registry
Flip cardA fully managed universal package manager on Google Cloud that supports various artifact formats, including Docker images, and integrates with security scanning and access control.
- Universal package manager (Docker, Maven, npm, etc.)
- Vulnerability scanning integration
- Fine-grained access control and audit logs
Memory trick: Artifact Registry is where all your trusted build artifacts live.
Cloud Batch
Flip cardA fully managed service for running batch jobs on Google Cloud, handling infrastructure provisioning, job scheduling, and scaling for high-performance computing workloads.
- Serverless batch processing
- Automates resource management
- Ideal for HPC, data processing, transcoding
- Cost-effective for intermittent, large-scale tasks
Memory trick: Batch processes: Set it, Forget it, Get the job done.
Cloud SQL + Database Migration Service (DMS)
Flip cardCloud SQL is a fully managed relational database service. Database Migration Service (DMS) facilitates continuous, minimal-downtime migrations of relational databases from on-premises or other clouds to Cloud SQL.
- Cloud SQL supports MySQL, PostgreSQL, and SQL Server.
- DMS supports online migrations with continuous data replication (CDC).
- Minimizes downtime during database cutover.
- Reduces operational burden through fully managed services.
Memory trick: DMS moves your relational data smoothly to Cloud SQL.
GKE Autopilot with Spot Pods
Flip cardA fully managed Google Kubernetes Engine mode that automatically scales and manages clusters, combined with Spot Pods for running fault-tolerant, interruptible workloads at a significantly reduced cost.
- Autopilot handles node provisioning, scaling, and upgrades.
- Spot Pods offer up to 90% cost savings compared to on-demand.
- Ideal for batch jobs, video transcoding, and other interruptible tasks.
- Requires applications to be resilient to preemption.
Memory trick: Autopilot spots savings for interruptible media jobs.
Global HTTP(S) Load Balancer
Flip cardA global, external load balancer that distributes HTTP(S) traffic to backend services across multiple regions, providing low latency and high availability.
- Global reach, routes to nearest healthy backend
- Supports session affinity
- Provides DDoS protection and SSL offload
- Can be used with Compute Engine, GKE, Cloud Run, App Engine
Memory trick: Global Load Balancer keeps global users connected, even if regions fall.
Network Virtual Appliance (NVA) Integration
Flip cardIntegrating third-party network security appliances, such as firewalls or intrusion detection systems, into a Google Cloud VPC to provide advanced traffic inspection and policy enforcement.
- Enables specialized security features not native to GCP firewalls.
- Often used in highly regulated environments for deep packet inspection.
- Requires careful routing and network design to direct traffic through the NVA.
Memory trick: Secure networks funnel traffic through a central checkpoint.
Google Cloud Batch
Flip cardA fully managed service for running large-scale batch jobs on Google Cloud, optimizing resource allocation and job execution.
- Ideal for HPC, data processing, and scientific simulations.
- Supports various machine types, including custom and GPUs.
- Integrates with other Google Cloud services like Cloud Storage and Pub/Sub.
Memory trick: Batch processes big jobs, breaking them into bite-sized bits.
Cloud Dataflow
Flip cardA fully managed, serverless service on Google Cloud for executing Apache Beam pipelines, enabling scalable and cost-effective processing of large datasets in both batch and streaming modes.
- Serverless and fully managed, minimizing operational overhead.
- Supports Apache Beam, allowing unified batch and streaming processing.
- Automatically scales resources based on workload demands.
- Cost-effective for petabyte-scale data processing.
Memory trick: Dataflow streams through big data, serverless and fast.
Dataflow
Flip cardA fully managed, serverless service for executing Apache Beam pipelines for large-scale data processing (batch and streaming).
- Serverless and fully managed
- Supports Apache Beam for complex data transformations
- Automatic scaling and resource optimization
- Ideal for ETL, batch processing, stream analytics
Memory trick: Dataflow makes data flow smoothly through your pipeline, like a river.
Memorystore for Redis
Flip cardA fully managed in-memory data store service compatible with open-source Redis, providing extremely low-latency (sub-millisecond) data access for caching and real-time use cases.
- Fully managed Redis compatible service
- Sub-millisecond latency for reads/writes
- Ideal for caching, session management, real-time analytics
Memory trick: Memorystore Redis remembers sessions super fast.
RTO and RPO
Flip cardRecovery Time Objective (RTO) is the maximum acceptable delay before an application is available after a disaster. Recovery Point Objective (RPO) is the maximum acceptable amount of data loss after a disaster.
- RTO: How quickly you recover (time)
- RPO: How much data you can lose (data volume/time)
- Lower RTO/RPO implies more complex and costly solutions
- Critical for disaster recovery planning
Memory trick: RTO is 'Time Out', RPO is 'Point Of no return' for data.
Cloud Storage Multi-Regional
Flip cardA Google Cloud object storage class designed for high availability and global accessibility, storing data redundantly across multiple geographic regions for maximum resilience and low latency access from anywhere.
- Ideal for frequently accessed content with global distribution.
- Unlimited storage capacity, scales to petabytes and beyond.
- Offers high availability and durability (99.999999999% annual durability).
- Serverless, pay-as-you-go model with no operational overhead for infrastructure.
Memory trick: Cloud Storage Multi-Regional holds all global user content.
Google Cloud ETL Services
Flip cardGoogle Cloud offers various services for Extract, Transform, Load (ETL) operations, catering to different levels of technical expertise and complexity.
- Cloud Data Fusion: Visual, no-code/low-code ETL.
- Dataflow: Code-based (Apache Beam), serverless, stream/batch processing.
- Dataproc: Managed Spark/Hadoop for big data processing.
- Cloud Composer: Workflow orchestration.
Memory trick: Data Fusion's the key, ETL made easy, no code, just glee!
Disaster Recovery (DR) Strategies
Flip cardDisaster Recovery (DR) strategies define how an organization recovers its IT infrastructure and data after a disaster, balancing Recovery Time Objective (RTO) and Recovery Point Objective (RPO) with cost and complexity.
- RTO is the maximum acceptable delay before services are restored.
- RPO is the maximum acceptable amount of data loss.
- Common strategies include Backup and Restore, Pilot Light, Warm Standby, and Hot Standby.
Memory trick: Backup, Pilot, Warm, Hot: DR's Path.
Autoscaling with MIGs
Flip cardGoogle Cloud's Managed Instance Groups (MIGs) automatically adjust the number of VM instances in a group based on defined policies, often combined with Cloud Load Balancing to distribute traffic efficiently.
- Dynamically scales compute resources up or down.
- Ensures application availability and performance during variable loads.
- Optimizes costs by only paying for resources when needed.
Memory trick: Auto-scaling is like a flexible team, always having just enough people to handle the rush.
Preemptible VMs (PVMs)
Flip cardCompute Engine instances that you can create and run at a much lower price than regular instances, but Google Cloud might terminate (preempt) these instances if it needs the resources elsewhere.
- Up to 80% cheaper than standard VMs.
- Instances last a maximum of 24 hours.
- Ideal for fault-tolerant batch jobs, stateless applications, and dev/test environments.
- Require robust retry logic or checkpointing for reliability.
Memory trick: Cheap, interruptible, retry-able: PVMs for the win!
Real-time Data Ingestion & Processing
Flip cardFor real-time analytics, you need services capable of ingesting high volumes of events with low latency and processing them continuously as they arrive.
- Pub/Sub is the standard for real-time event ingestion on GCP.
- Dataflow (Apache Beam) is excellent for stream processing.
- These services scale automatically to handle fluctuating loads.
Memory trick: Pub/Sub's the start, Dataflow's the brain, real-time insights, again and again!
Managed Instance Groups (MIGs)
Flip cardManaged Instance Groups (MIGs) allow you to run apps on multiple identical VMs, offering autoscaling, autohealing, and load balancing for high availability and scalability.
- Automates instance creation and deletion based on demand.
- Supports rolling updates for seamless software deployments.
- Provides autohealing by recreating unhealthy instances.
Memory trick: MIGs Manage Instances, Growing and Healing.
Multicast on Google Cloud
Flip cardGoogle Cloud VPC networks do not natively support IP multicast routing. Workarounds involve using overlay networks or refactoring applications to use unicast/pub/sub.
- Native multicast is not supported in Google Cloud VPC.
- Overlay networks (e.g., VXLAN, OpenVPN) can encapsulate multicast traffic over unicast.
- Refactoring to unicast or pub/sub (e.g., Cloud Pub/Sub) is the recommended long-term solution.
- Impacts legacy applications heavily reliant on multicast for service discovery or messaging.
Memory trick: No native multicast, so build a tunnel for the broadcast!
Cloud Pub/Sub
Flip cardCloud Pub/Sub is a fully managed, real-time messaging service that allows you to send and receive messages between independent applications, enabling scalable event-driven architectures and streaming analytics.
- Globally distributed, high-throughput, low-latency messaging.
- Decouples publishers from subscribers.
- Automatically scales to handle unpredictable workloads.
- Supports push and pull delivery mechanisms.
Memory trick: Publish and Subscribe: Events Arrive.
Cloud Monitoring
Flip cardCloud Monitoring is a comprehensive service in Google Cloud Operations Suite for collecting, visualizing, and alerting on metrics and metadata from Google Cloud and external services.
- Collects metrics from VMs, GKE, databases, and more.
- Allows creation of custom dashboards and charts.
- Supports setting up alerts based on metric thresholds.
- Integrates with other Operations Suite tools like Cloud Logging.
Memory trick: Logs, Metrics, Traces: Observe All Spaces.
Globally Distributed Databases
Flip cardDatabases designed to operate across multiple geographic regions, offering high availability, low latency, and various consistency models.
- Cloud Spanner: Global, strongly consistent, relational, high throughput.
- Firestore: Global, eventually consistent (cross-region), NoSQL document DB.
- Cloud SQL: Regional, can use read replicas for scale, but not truly global strong consistency.
Memory trick: Global scale, strong and fast, Spanner's the choice, built to last!
Google Cloud Serverless Options
Flip cardManaged services that abstract away infrastructure management, allowing developers to focus on code and pay only for resources consumed, ideal for variable workloads.
- Cloud Functions: Event-driven, short-lived functions.
- Cloud Run: Container-based, scales to zero, for web services and APIs.
- App Engine: Platform-as-a-Service, managed environment for web apps.
- Minimize operational overhead and optimize costs for variable traffic.
Memory trick: Run your containers serverlessly to scale from zero to hero.
Cloud Data Fusion
Flip cardA fully managed, cloud-native data integration service built on open-source CDAP, providing a visual, code-free environment for building and managing ETL/ELT pipelines with built-in data governance features.
- Visual pipeline development (GUI-based).
- Built-in data lineage tracking.
- Data masking and security features.
- Auditing capabilities for data access and transformations.
Memory trick: Fusion ensures your data flows with full governance and clarity.
Storage Transfer Service (on-premises)
Flip cardA fully managed Google Cloud service that enables large-scale, secure, and reliable data transfers from on-premises sources (or other cloud providers) to Google Cloud Storage.
- Supports transfers from NFS, HDFS, S3-compatible sources, Azure Blob Storage.
- Optimizes transfer bandwidth and performance.
- Provides data integrity checks and retry mechanisms.
- Managed service, reduces operational overhead.
Memory trick: Storage Transfer Service smoothly moves your mountain of data securely.
Autoscaling Metrics
Flip cardAutoscaling policies define how Managed Instance Groups (MIGs) adjust the number of instances based on demand, using various metrics to trigger scaling actions.
- CPU utilization is a common, but reactive, metric.
- HTTP load balancing serving capacity is a proactive metric for web applications.
- Custom metrics can provide fine-grained control based on application-specific needs.
Memory trick: React fast, scale smart, keep apps tart!
Disaster Recovery (DR) Objectives
Flip cardRTO (Recovery Time Objective) is the maximum acceptable downtime after a disaster. RPO (Recovery Point Objective) is the maximum acceptable data loss after a disaster.
- Lower RTO/RPO often means higher cost and complexity.
- Asynchronous replication is common for regional DR.
- Snapshots, backups, and replication are key DR tools.
Memory trick: RTO, RPO, plan it fast, data's safe, disaster's past!
Database Connection Pooling
Flip cardConnection pooling is a technique used to manage and reuse database connections, reducing overhead and preventing database saturation caused by numerous application connections.
- Poolers like PgBouncer sit between app and DB.
- Reduces the number of open connections to the database.
- Improves performance and scalability for high-traffic applications.
- Essential for microservices architectures.
Memory trick: Connections flow, don't let them stall, PgBouncer saves them all!
Google Cloud Storage Classes
Flip cardDifferent storage classes in GCS offer varying levels of availability, latency, and cost, allowing optimization based on data access patterns.
- Standard: High availability, low latency, general purpose.
- Nearline: Lower cost for data accessed less than once a month.
- Coldline: Even lower cost for data accessed less than once a quarter.
- Archive: Lowest cost for data accessed less than once a year.
Memory trick: Access needs dictate the GCS class, balancing speed and price.
Google Cloud Encryption Options
Flip cardGoogle Cloud offers various encryption key management options, providing different levels of customer control over encryption keys for data at rest and in transit.
- GMEK: Google manages keys, default for most services.
- CMEK: Customer manages keys in Cloud KMS, Google uses them.
- CSEK: Customer supplies keys directly for each operation, Google does not store them.
- Application-layer encryption: Handled by the application itself.
Memory trick: Control of your keys dictates Google's access level.
Service Mesh (Istio)
Flip cardA service mesh is a dedicated infrastructure layer for handling service-to-service communication. It makes communication between microservices flexible, reliable, and fast. Istio is an open-source service mesh that provides traffic management, policy enforcement, and telemetry.
- Manages service-to-service communication
- Provides traffic management, security, and observability
- Operates at the infrastructure layer, independent of application code
- Anthos Service Mesh is Google Cloud's managed Istio offering
Memory trick: Mesh services to observe, manage, and secure their chat.
Google Cloud Data Residency
Flip cardThe geographical location where data is physically stored and processed, crucial for regulatory compliance and sovereignty.
- Regional resources keep data within a single specified region.
- Multi-regional resources distribute data across multiple regions.
- Dual-regional resources distribute data across two specific regions.
- Compliance with regulations like HIPAA, GDPR often requires strict regional residency.
Memory trick: Regional resources are key to keeping your data in its designated home.
Cloud Interconnect
Flip cardGoogle Cloud Interconnect provides high-bandwidth, low-latency connections between an on-premises network and Google Cloud, bypassing the public internet.
- Offers Dedicated Interconnect or Partner Interconnect.
- Crucial for hybrid cloud architectures requiring high throughput and low latency.
- Supports private IP space communication between networks.
Memory trick: Connect directly, place precisely, for speed and secrecy.