Professional Cloud Architect flashcards
137 free flashcards. Tap a card to flip it.
Cloud Composer (Apache Airflow)
Flip cardA fully managed workflow orchestration service built on Apache Airflow, used to programmatically author, schedule, and monitor complex data pipelines.
- Uses Directed Acyclic Graphs (DAGs) for workflow definition.
- Supports Python for defining tasks and dependencies.
- Provides robust scheduling, monitoring, and error handling.
- Integrates with various Google Cloud and third-party services.
Memory trick: Composer conducts your complex jobs with Python and perfect timing.
Google Cloud Operations Suite
Flip cardA suite of services (formerly Stackdriver) for monitoring, logging, tracing, and debugging applications on Google Cloud.
- Cloud Monitoring: Collects metrics, creates dashboards, sets alerts.
- Cloud Logging: Collects and stores logs.
- Cloud Trace: Provides distributed tracing for latency analysis.
- Cloud Profiler: Identifies CPU/memory bottlenecks in code.
Memory trick: Monitor, Log, Trace, your app's health to embrace!
Google Cloud Database Migration Strategies
Flip cardGoogle Cloud offers various database services and migration paths, each with different levels of compatibility, effort, and cloud-nativeness, depending on the source database and application requirements.
- Lift-and-shift: Minimal changes, often using Bare Metal Solution or Compute Engine.
- Re-platform: Migrate to a managed service (e.g., Cloud SQL), some schema/code changes.
- Re-architect: Migrate to a cloud-native database (e.g., Spanner, Firestore), significant changes.
Memory trick: Oracle's old, cloud's new, Bare Metal makes it simple too!
Google Cloud Shared File Storage
Flip cardGoogle Cloud offers managed file storage solutions that provide shared access to files across multiple Compute Engine instances, suitable for workloads requiring POSIX compliance or NFS/SMB protocols.
- Filestore supports NFS for high-performance file sharing.
- Different Filestore tiers offer varying performance and availability.
- Cloud Storage is object storage, not a traditional file system.
Memory trick: Files shared, fast and free, Filestore's the key!
BigQuery Table Optimization
Flip cardTechniques used to improve query performance and reduce costs in BigQuery by structuring data efficiently.
- Partitioning: Divides a table into smaller segments based on a column (e.g., date, integer range).
- Clustering: Sorts data within partitions based on up to four columns.
- Reduces data scanned, leading to lower costs and faster queries.
- Consider common query filters and join keys when choosing partition/cluster columns.
Memory trick: Structure your BigQuery tables smartly to slash costs and speed up scans.
GKE Resource Management
Flip cardKubernetes allows you to define resource requests and limits for containers within pods to manage resource allocation and ensure stable application performance.
- Requests: Guaranteed minimum resources (CPU, memory).
- Limits: Maximum resources a container can consume.
- Proper configuration prevents throttling and resource contention.
- VPA can automate these settings over time.
Memory trick: Requests and Limits, a pod's best friend, consistent performance to the very end!
Data Residency on Google Cloud
Flip cardData residency refers to the physical location where data is stored and processed, often a critical requirement for regulatory compliance and sovereignty.
- Single-region Cloud Storage buckets keep data within one region.
- Compute Engine instances process data within their deployed region.
- Multi-region and dual-region buckets allow data to cross regional borders.
- Network egress from a region can also be a residency concern.
Memory trick: Region's the rule, data's the jewel, keep it contained, that's the cool!
Committed Use Discounts (CUDs)
Flip cardDeep discounts on Google Cloud resources (like Compute Engine VMs) in exchange for committing to a specific level of resource usage for a 1-year or 3-year term.
- Offer significant savings (up to 70%+ for 3-year commitments).
- Apply automatically to eligible usage in the billing account.
- Best for predictable, stable workloads.
- Can be combined with autoscaling for variable workloads.
Memory trick: Commit for baseline, auto-scale for bursts, save big!
Cloud Storage Encryption Options
Flip cardCloud Storage offers various encryption options, including Google-managed, customer-managed (CMEK), and customer-supplied (CSEK), each providing different levels of control over encryption keys.
- Default encryption uses Google-managed keys.
- CMEK allows customers to manage keys in Cloud KMS, offering high control and auditing.
- CSEK requires customers to supply keys with each request.
- CMEK is often preferred for regulatory compliance due to enhanced key control.
Memory trick: CMEK: Control My Encryption Keys, for Audit's sake!
Cloud SQL Insights
Flip cardA feature of Cloud SQL that provides intelligent, in-depth performance monitoring and diagnostics for your databases, helping to identify and resolve performance bottlenecks.
- Identifies slow queries and provides query plan visualizations.
- Offers a holistic view of database load and performance.
- Provides recommendations for optimization.
- Integrates with Cloud Monitoring and Cloud Logging.
Memory trick: Insights illuminate your SQL, showing slow queries and optimization clues.
Database Performance Diagnostics
Flip cardTools and techniques used to identify and resolve performance bottlenecks in database systems, often involving query analysis, connection management, and resource monitoring.
- Inefficient queries are a common cause of performance issues.
- Connection pooling helps manage database connections efficiently.
- Monitoring query execution plans and resource utilization is crucial.
- Cloud Trace and Cloud SQL Insights provide deep visibility into database performance on Google Cloud.
Memory trick: Trace the path, Insight the query, Fix the speed!
Google Cloud Organization Policy Service
Flip cardA service that allows organizations to programmatically define and enforce constraints on the configuration of Google Cloud resources across the entire organization, folders, or projects.
- Part of Resource Manager, applies constraints to resource creation/updates.
- Helps enforce security, compliance, and cost management policies.
- Examples: restrict external IP usage, define allowed regions, enforce CMEK.
Memory trick: Organization Policies Orchestrate Order.
Cloud Data Loss Prevention (DLP)
Flip cardCloud DLP is a fully managed service that helps discover, classify, and protect sensitive data across Google Cloud and hybrid environments.
- Identifies over 150 info types (e.g., credit card numbers, PHI).
- Offers de-identification techniques (redaction, tokenization, format-preserving encryption).
- Scans structured and unstructured data.
Memory trick: DLP is your 'data detective' and 'privacy protector' for sensitive info.
Hashing and Digital Signatures
Flip cardHashing creates a unique fingerprint of data for integrity, while digital signatures use asymmetric cryptography to cryptographically bind an identity to data, providing authenticity and non-repudiation.
- Hashing detects any unauthorized data modification.
- Digital signatures prove the sender's identity and that the message hasn't been tampered with.
- Used for audit logs, software distribution, and secure communication.
Memory trick: CIA: Confidentiality, Integrity, Availability. Non-Repudiation too!
Container Analysis API (for Artifact Registry)
Flip cardA Google Cloud service that automatically scans container images stored in Artifact Registry and Container Registry for known vulnerabilities, providing security insights.
- Integrates directly with Artifact Registry and Container Registry.
- Identifies CVEs and other security findings in image layers.
- Provides metadata and insights for policy enforcement (e.g., with Binary Authorization).
Memory trick: Artifacts Analyzed, Authorization Assured.
Organization Policy Service
Flip cardThe Organization Policy Service allows administrators to programmatically control resource configurations across an entire Google Cloud organization.
- Sets constraints on resource behavior and configuration.
- Enforces policies across projects, folders, and the organization.
- Prevents non-compliant resource deployments.
Memory trick: Organization Policy Service is the 'rulebook' for your entire Google Cloud organization.
Customer-Supplied Encryption Keys (CSEK)
Flip cardCSEK is a Google Cloud feature that allows users to provide their own encryption keys to encrypt data at rest in services like Cloud Storage. The keys are managed entirely by the customer.
- Customer generates and manages the encryption key.
- Key is provided to Google Cloud during data operations (upload/download).
- Google Cloud never stores the key persistently.
- Provides the highest level of customer control over encryption keys.
Memory trick: Secure Your Data: Keys for Every Need!
Container Analysis API
Flip cardA Google Cloud service that provides vulnerability scanning, software bill of materials (SBOM) generation, and policy enforcement for container images and other artifacts.
- Automatically scans images in Artifact Registry.
- Identifies known vulnerabilities (CVEs).
- Integrates with CI/CD pipelines for automated security checks.
Memory trick: Analyze the Container, Scan for Flaws, Before Deployment, Obey the Laws.
Cloud Identity and IAM for Zero Trust
Flip cardCloud Identity provides the 'who' for authentication and user management, while IAM provides the 'what' and 'where' for granular authorization, together forming the foundation for a zero-trust security model in Google Cloud.
- Zero Trust: Never trust, always verify.
- Cloud Identity manages users, groups, and multi-factor authentication.
- IAM controls granular permissions to Google Cloud resources.
Memory trick: Identity + IAM = Invincible Access Management.
Google Cloud Resource Hierarchy for Isolation
Flip cardThe Google Cloud resource hierarchy (Organization > Folders > Projects > Resources) provides natural boundaries for logical isolation and access control, with Projects offering the strongest isolation for multi-tenant architectures.
- Projects serve as fundamental billing and resource grouping units.
- IAM policies are inherited down the hierarchy, but project boundaries are strong.
- Separating tenants by project offers robust logical isolation and access control.
Memory trick: Projects Protect Tenants, Each with its Own Place.
Cloud Armor
Flip cardA Google Cloud service that provides DDoS protection and Web Application Firewall (WAF) capabilities for applications deployed on Google Cloud.
- Protects against L3/L4 volumetric attacks and L7 application attacks.
- Integrates with HTTP(S) Load Balancing.
- Offers preconfigured WAF rules and custom rules for traffic filtering.
Memory trick: Armor for Apps, Shields from Storms.
Cloud Key Management Service (Cloud KMS)
Flip cardA cloud-hosted key management service that lets you manage cryptographic keys for your cloud services in the same way you manage keys on-premises.
- Manages symmetric and asymmetric encryption keys.
- Integrates with many Google Cloud services for CMEK.
- Provides audit logging for key usage.
Memory trick: Keys in the Cloud, Secure and Sound, Audited All Around.
Binary Authorization
Flip cardBinary Authorization is a deploy-time security control that enforces policies on images deployed to Google Kubernetes Engine (GKE) or Cloud Run.
- Prevents deployment of unauthorized or non-compliant images.
- Integrates with Container Analysis for vulnerability insights.
- Requires attestations (approvals) for images before deployment.
Memory trick: Binary Authorization is the security checkpoint for your container images before they can sail.
Zero Trust Security Model
Flip cardA security model where no user, device, or application is implicitly trusted, regardless of their location. Every access request is verified based on identity, context, and policy.
- Never trust, always verify.
- Access is granted based on the principle of least privilege.
- Contextual access control (identity, device, location, time).
Memory trick: IAP and Access Context Manager are the 'Who are you and where are you?' for Zero Trust.
Google Cloud Internal Network Encryption
Flip cardGoogle Cloud's default practice of encrypting all network traffic between its services within its infrastructure.
- Traffic is encrypted at the network layer by default.
- No explicit configuration is required by users/developers.
- Ensures a 'secure by default' posture for data in transit.
Memory trick: GCP Network: Built-in Shield, All Traffic Sealed.
Cloud HSM
Flip cardCloud HSM is a fully managed hardware security module (HSM) service that allows you to host encryption keys and perform cryptographic operations in FIPS 140-2 Level 3 validated HSMs.
- Provides FIPS 140-2 Level 3 validated hardware.
- Keys are generated and stored exclusively within the HSM.
- Integrated with Cloud KMS for management and access control.
Memory trick: FIPS 140-2 Level 3 means a strong, verified hardware box for your keys, and that's Cloud HSM.
Google Cloud Armor
Flip cardGoogle Cloud Armor is a DDoS protection and Web Application Firewall (WAF) service that helps protect applications and websites from various types of attacks.
- Provides Layer 3/4 and Layer 7 DDoS protection.
- Offers WAF rules to mitigate common web vulnerabilities.
- Allows IP-based and geo-based access control policies.
- Integrates with Google Cloud Load Balancing.
Memory trick: Armor guards the gates from digital threats.
Cloud Storage Data Residency
Flip cardEnsuring that data stored in Cloud Storage physically resides within a specific geographic region or country to meet regulatory and compliance requirements.
- Achieved by selecting appropriate bucket locations (region or multi-region).
- Regional buckets guarantee data stays within a single region.
- Multi-region buckets distribute data across a broader geography for resilience.
Memory trick: Residency: Regions Rule, Multi-regions Roam.
Cloud HSM (Hardware Security Module)
Flip cardA Google Cloud service that provides a fully managed cloud-hosted hardware security module (HSM) for generating and storing cryptographic keys.
- Offers FIPS 140-2 Level 3 validated HSMs.
- Provides enhanced security for sensitive cryptographic operations.
- Integrates with Cloud KMS for key management operations.
Memory trick: HSM for FIPS, Regulatory Trips, Secure Key Ships.
VPC Network Isolation Strategies
Flip cardMethods to logically separate and control network traffic between resources in Google Cloud, ranging from shared to highly isolated.
- Separate VPCs offer maximum isolation.
- Shared VPC centralizes networking but requires careful management.
- Peering allows controlled communication between isolated VPCs.
Memory trick: Separate VPCs, Walls are High, Blast Radius Low, Secure the Sky.
Google Cloud IAM Custom Roles
Flip cardCustom roles in Google Cloud IAM allow administrators to define a specific set of permissions tailored to an organization's needs, enabling granular access control.
- Enforce the principle of least privilege.
- Combine specific permissions from Google-defined roles.
- Can be applied at the project, folder, or organization level.
Memory trick: IAM Roles: Basic, Predefined, Custom, Service. Choose Wisely.
Ultimate Data Control Stack
Flip cardA combination of Google Cloud services (Confidential Computing, EKM, Key Access Justifications) providing the highest level of customer control over encryption keys and assurance against unauthorized access to unencrypted data.
- Confidential Computing encrypts data in-use (memory).
- External Key Manager (EKM) puts key management fully under customer control.
- Key Access Justifications provides audit and approval for Google personnel key access.
Memory trick: Confidential EKM, Justify My Key, Ultimate Control, Google Can't See.
Zero Trust Security
Flip cardA security model based on the principle of 'never trust, always verify,' requiring strict identity verification for every access request, regardless of whether it originates inside or outside the network perimeter.
- Verifies every user and device for every access request.
- Uses context-aware policies (identity, device health, location, etc.).
- Identity-Aware Proxy (IAP) is a key Google Cloud implementation component.
Memory trick: Verify Every Access, Trust No One's Pass, Context is King, Secure the Glass.
Cloud Key Management Service (KMS)
Flip cardA Google Cloud service for managing cryptographic keys in a cloud-hosted environment, enabling strong encryption for data at rest and in transit.
- Supports symmetric and asymmetric encryption keys.
- Integrates with many Google Cloud services for CMEK.
- Provides key rotation, access control, and audit logging.
Memory trick: Keys Keep My Secrets Secure, Every time.
Google Cloud Project
Flip cardA Google Cloud Project is the fundamental container for all Google Cloud resources, providing a boundary for billing, quotas, resource management, and IAM policies.
- Primary isolation boundary for resources.
- Independent billing and quota management.
- Unit for applying IAM policies.
Memory trick: Organization holds folders, folders hold projects, projects hold resources.
Customer-Supplied Encryption Keys (CSEK) for Cloud Storage
Flip cardCSEK allows users to provide their own AES-256 encryption key for Cloud Storage objects, which must be supplied with each API request, giving direct control over the encryption key.
- Customer manages the key entirely, not Google or Cloud KMS.
- Key is provided with each read/write operation for an object.
- Offers maximum control for specific compliance needs.
Memory trick: Keys: Google, Customer-Managed, or Customer-Supplied.
Resource Location Restriction (Organization Policy)
Flip cardAn Organization Policy constraint that restricts the geographic locations (regions, multi-regions) where Google Cloud resources can be created.
- Enforces data residency requirements at an organizational level.
- Prevents creation of resources outside allowed locations.
- Applies to various resource types (Compute Engine, Storage, BigQuery, etc.).
Memory trick: Organization Policy is the 'border patrol' for where your cloud resources can live.
External HTTP(S) Load Balancer
Flip cardA global, highly scalable load balancer that distributes HTTP/HTTPS traffic to backends based on URL maps and health checks, providing a single IP address.
- Global load balancing for HTTP/HTTPS traffic.
- Provides a single global IP address.
- Intelligent routing based on URL paths, hosts, and health.
- Supports GKE, Compute Engine, and Cloud Run backends.
Memory trick: External HTTP(S) is for the world wide web, Network is for raw connections, Internal is for within.
Cloud Filestore
Flip cardGoogle Cloud's fully managed, high-performance file storage service for applications that require a file system interface and a shared filesystem.
- Supports NFS protocol
- Can be mounted by multiple Compute Engine instances
- Ideal for shared files, CI/CD, content management
Memory trick: Filestore shares files like a network drive.
Spot VMs (formerly Preemptible VMs) with C2 instances
Flip cardSpot VMs are highly cost-effective Compute Engine instances suitable for fault-tolerant workloads that can handle interruptions. C2 instances are optimized for high CPU performance, making them ideal for computationally intensive tasks.
- Spot VMs offer significant cost savings (up to 91% off on-demand prices)
- Instances can be preempted with a 30-second notice
- C2 instances are optimized for compute-intensive workloads
- Ideal for batch jobs, scientific computing, and stateless applications
Memory trick: Spot the C2 for cheap, speedy batch processing.
Cloud Bigtable
Flip cardA fully managed, petabyte-scale NoSQL wide-column database service on Google Cloud, optimized for extremely high read/write throughput and low-latency access.
- Ideal for large operational and analytical workloads (IoT, gaming, ad tech).
- Supports high throughput for time-series, financial, and marketing data.
- Designed for low-latency access with a flexible wide-column data model.
Memory trick: Bigtable for big traffic, big speed, big scale.
Cloud Storage Standard Regional
Flip cardThe Cloud Storage Standard class is for frequently accessed data requiring high performance, combined with a Regional location type for high availability within a specific geographic region.
- Highest performance and lowest latency.
- Suitable for frequently accessed data (e.g., streaming, interactive websites).
- Regional location offers high durability and availability within a single region.
- Cost-effective for regional deployments compared to Multi-Regional.
Memory trick: Standard Regional is the standard choice for speedy streaming in one region.
CMEK with Cloud KMS, IAM, and Cloud Audit Logs
Flip cardCustomer-Managed Encryption Keys (CMEK) allow customers to use their own encryption keys managed within Cloud Key Management Service (KMS) for data at rest in Google Cloud services like Cloud Storage. IAM controls access to these keys, and Cloud Audit Logs provide an immutable record of all key usage for compliance and auditing.
- Cloud KMS manages customer-provided encryption keys (CMEK)
- IAM controls who can use, manage, or view key resources
- Cloud Audit Logs record all administrative and data access events related to keys
- Ensures strong control and audibility over encryption keys
Memory trick: KMS keys, IAM guards, Audit Logs record all.
Spot VMs with MIGs
Flip cardSpot VMs provide significant cost savings for fault-tolerant workloads, and Managed Instance Groups (MIGs) can manage their creation, deletion, and recreation, ensuring availability for batch jobs.
- Spot VMs are up to 91% cheaper than standard VMs.
- Can be preempted by Compute Engine with 30 seconds notice.
- MIGs can automatically recreate preempted instances.
- Ideal for batch processing, analytics, and fault-tolerant tasks.
Memory trick: Spot VMs with MIGs cut costs for batch jobs, like finding a good deal on a team.
IoT Data Pipeline on GCP
Flip cardA common architecture for processing real-time IoT data involves Pub/Sub for ingestion, Dataflow for stream processing, and Bigtable for time-series storage.
- Pub/Sub: Real-time, scalable messaging for ingestion
- Dataflow: Serverless, unified stream/batch processing
- Bigtable: Petabyte-scale, low-latency NoSQL for time-series
Memory trick: Pub/Sub brings it in, Dataflow processes, Bigtable stores it for IoT.
Cloud Storage Archive Class
Flip cardCloud Storage Archive class is the lowest-cost storage class designed for long-term digital archiving, backup, and disaster recovery. It is optimized for data that is accessed less than once a year, with retrieval latency typically in minutes.
- Lowest storage cost
- Highest retrieval cost (per GB)
- Minimum storage duration of 365 days
- Retrieval latency in minutes
Memory trick: Archive if you access it almost never, but keep it forever.
Cloud Bigtable for Gaming
Flip cardCloud Bigtable is a highly scalable, fully managed NoSQL wide-column database service designed for large analytical and operational workloads. It excels at low-latency access and high throughput for massive datasets, making it suitable for real-time gaming data, IoT, and ad tech applications.
- Petabyte-scale, low-latency NoSQL wide-column database
- Optimized for high read/write throughput (millions ops/sec)
- Ideal for operational data, time-series, and large-scale key-value stores
- Used for gaming, IoT, ad tech, financial analytics
Memory trick: Bigtable handles big game data with lightning speed.
Cloud CDN with External HTTP(S) Load Balancing
Flip cardCloud CDN is Google Cloud's content delivery network for delivering web and video content with low latency. It integrates seamlessly with External HTTP(S) Load Balancing to provide global load distribution, SSL termination, and protection against DDoS attacks.
- Global content caching at edge locations
- Reduces latency and origin server load
- External HTTP(S) Load Balancing provides DDoS protection
- Supports SSL/TLS termination
Memory trick: CDN and External LB make web apps fly and stay safe.
IoT Data Pipeline (GCP)
Flip cardA common architecture on Google Cloud for ingesting, processing, and analyzing real-time data from IoT devices.
- Often starts with Pub/Sub for ingestion.
- Uses Dataflow for real-time stream processing.
- Integrates with BigQuery for analytics and Cloud Storage for raw data.
Memory trick: Pub/Sub gets data, Dataflow processes the flow.
Cloud Filestore High Scale
Flip cardA fully managed, high-performance file storage service on Google Cloud, optimized for demanding workloads requiring shared file systems.
- Offers NFSv3 and NFSv4.1 protocol support.
- Provides high throughput and low latency.
- Suitable for GKE stateful applications requiring shared file systems.
Memory trick: GKE needs shared files, fast and ready.
Cloud KMS CMEK Roles
Flip cardSpecific IAM roles for Cloud Key Management Service (KMS) that control access to cryptographic keys for encryption and decryption operations.
- CMEK allows customers to manage their own encryption keys.
- Requires specific permissions for service accounts to use keys.
- Different roles exist for viewing, administering, and using keys.
Memory trick: Encrypt/Decrypt with the Crypto Key Encrypter Decrypter.
Managed Instance Groups (MIGs) with Autoscaling
Flip cardMIGs manage a group of identical VM instances, and with autoscaling enabled, they automatically adjust the number of instances to meet demand.
- Automated instance creation/deletion
- Ensures high availability and fault tolerance
- Supports rolling updates and autohealing
Memory trick: MIGs auto-scale, keeping your apps alive and thriving.
Cloud Composer
Flip cardA fully managed workflow orchestration service built on Apache Airflow, enabling users to author, schedule, and monitor pipelines.
- Manages complex workflows with dependencies.
- Supports long-running batch jobs and ETL pipelines.
- Integrates with other Google Cloud services.
Memory trick: Composer conducts the complex cloud orchestra.
Shared VPC
Flip cardA networking feature that allows multiple projects (service projects) to connect to a common Virtual Private Cloud (VPC) network in a host project.
- Centralizes network administration and control.
- Enables communication between service projects using internal IP addresses.
- Consolidates network resources like VPNs, Interconnects, and firewalls.
- Improves security and simplifies network topology.
Memory trick: Share your VPC to simplify your network's journey.
GKE Ingress with Cloud Load Balancing
Flip cardIn GKE, Ingress is a Kubernetes API resource that uses Google Cloud Load Balancing to provide external HTTP/S access to services within the cluster.
- Exposes GKE services to external internet traffic
- Leverages Google Cloud's global load balancing infrastructure
- Handles routing, SSL termination, and host/path-based rules
Memory trick: Ingress is the gatekeeper for GKE, with Load Balancing as its bouncer.
IAM and Cloud Audit Logs for Storage Security
Flip cardIAM defines who can do what with Cloud Storage resources, while Cloud Audit Logs record administrative activities and data access events for auditing and compliance.
- IAM provides role-based access control (RBAC)
- Cloud Audit Logs capture 'who did what, where, and when'
- Essential for compliance and security monitoring
Memory trick: IAM grants the keys, Audit Logs watch the door.
Cloud Run for Event-Driven Processing
Flip cardCloud Run is a fully managed serverless platform that allows you to deploy stateless containerized applications. It automatically scales based on demand, from zero to many instances, and can be triggered by various events, making it ideal for event-driven, variable-duration workloads.
- Fully managed and serverless
- Deploys stateless containers
- Scales automatically from zero
- Event-driven (e.g., Cloud Storage, Pub/Sub)
Memory trick: Run containers when events arrive, scale to zero and back up.
Dedicated Cloud Interconnect
Flip cardDedicated Cloud Interconnect provides direct physical connections between an on-premises network and Google's network. It offers high-bandwidth, low-latency, private connectivity that bypasses the public internet, suitable for enterprise-grade workloads requiring strong SLAs.
- Direct physical connection to Google's network
- High bandwidth (10 Gbps or 100 Gbps links)
- Low latency and consistent network performance
- Bypasses the public internet, enhancing security
Memory trick: Dedicated Interconnect dedicates a direct line to the cloud.
Centralized Egress with Custom Routes
Flip cardA networking pattern where all outbound internet traffic from spoke VPCs is routed through a dedicated hub VPC containing security appliances, typically using custom static routes.
- Enforces security policies on all egress traffic
- Uses custom static routes with next-hops to internal load balancers/IPs
- Allows instances to operate without public IP addresses
Memory trick: Routes guide all traffic through the security gate.
IoT Data Pipeline (Pub/Sub, Dataflow, BigQuery, Bigtable)
Flip cardA common Google Cloud architecture for processing IoT data involves Cloud Pub/Sub for scalable ingestion, Dataflow for real-time stream processing and transformation, BigQuery for long-term analytics and reporting, and Cloud Bigtable for low-latency access to time-series data for real-time dashboards.
- Cloud Pub/Sub: Real-time, scalable message ingestion
- Dataflow: Unified stream and batch processing with custom logic
- BigQuery: Petabyte-scale data warehousing for analytics
- Cloud Bigtable: Low-latency NoSQL for time-series and operational data
Memory trick: Pub/Sub gets it, Dataflow cooks it, BigQuery archives it, Bigtable shows it.