Professional Cloud ArchitectManage and provision solution infrastructureEasy

A company is designing a new microservices architecture on Google Kubernetes Engine (GKE). They need to ensure that traffic from the internet is routed to the correct GKE services and that external load balancing is handled efficiently. Which Google Cloud networking component is primarily responsible for exposing GKE services to external traffic and providing global load balancing?

  1. AVPC Network
  2. BCloud Load Balancing (with Ingress)
  3. CCloud NAT
  4. DCloud Router
Show answer & explanation

Correct answer: B. Cloud Load Balancing (with Ingress)

In GKE, Ingress is an API object that manages external access to services in a cluster, typically HTTP/S. When you create an Ingress resource, GKE provisions a Cloud Load Balancer (specifically a Google Cloud HTTP(S) Load Balancer) to handle external traffic and route it to the appropriate services.

Why the other options are wrong

  • A. VPC Network provides the fundamental network infrastructure but doesn't directly expose GKE services to the internet with load balancing.
  • C. Cloud NAT allows instances without external IP addresses to send outbound traffic, not for inbound external load balancing.
  • D. Cloud Router enables BGP peering with on-premises networks for hybrid connectivity, not for external GKE service exposure.

GKE Ingress with Cloud Load Balancing

In GKE, Ingress is a Kubernetes API resource that uses Google Cloud Load Balancing to provide external HTTP/S access to services within the cluster.

  • Exposes GKE services to external internet traffic
  • Leverages Google Cloud's global load balancing infrastructure
  • Handles routing, SSL termination, and host/path-based rules

Memory trick: Ingress is the gatekeeper for GKE, with Load Balancing as its bouncer.

More Manage and provision solution infrastructure questions