Skip to main content

Service inventory

The Web App Blueprint deploys seventeen Google Cloud services and features and five Kubernetes components into each stage project, and relies on shared services that the GCP Enterprise Baseline runs in its core projects. Everything in the first two tables is created by the blueprint's own code; the third lists what it uses from the Baseline.

How the pieces group​

Google Cloud services​

ServiceUnitWhat it does in the blueprintStage defaults
Google Kubernetes Engine (GKE)gkeOne regional Standard cluster per stage, acme-usw1-<stage>-gke, on the Regular release channel, with private nodes, a DNS-based control-plane endpoint, Dataplane V2, Workload Identity Federation for GKE, Shielded nodes and security postureTwo zones in dev, three in staging and prod; deletion protection in prod
GKE node poolsgkeA system pool of e2-standard-2 nodes tainted for platform components, and node auto-provisioning that creates and removes pools for the applicationAuto-provisioning ceiling 32, 64 and 128 vCPU
GKE Gatewaygke (controller), chart, argocdThe Gateway API controller: the chart's public Gateway (gke-l7-global-external-managed) and ArgoCD's internal one (gke-l7-rilb)Same in every stage
Cloud Load Balancingfrontend-service, chart, argocdA global external Application Load Balancer for the front end, one the Gateway controller builds for the API, and a regional internal one for ArgoCD; two SSL policies with the MODERN profile and TLS 1.2 minimumSame in every stage
Cloud Armorapi-gateway, frontend-serviceTwo security policies per stage, acme-usw1-<stage>-api-armor and -frontend-armor, built from the Baseline's rule templateRate and WAF rules in preview in dev; preview off in staging and prod
Certificate Managerapi-gateway, frontend-serviceDNS authorizations, Google-managed certificates and certificate maps for blueprint-api and blueprint-appSame in every stage
Cloud CDNfrontend-serviceCaches the front end on the load balancer's backend service in CACHE_ALL_STATIC modeSame in every stage
Cloud Runfrontend-serviceThe service acme-usw1-<stage>-frontend: nginx serving the built React app, internal and load balancer ingress only, no run.app URL0 to 10 instances of 1 vCPU and 256 MiB
FirestorefirestoreThe database acme-usw1-<stage>-mongo, Enterprise edition with MongoDB compatibility; the application signs in through IAM (MONGODB-OIDC)Point-in-time recovery in staging and prod; daily backups kept 35 days and delete protection in prod
Memorystore for ValkeyvalkeyThe instance acme-usw1-<stage>-valkey, Valkey 8.0 in cluster-disabled mode, TLS and IAM authenticationSHARED_CORE_NANO without a replica in dev; STANDARD_SMALL with a replica in another zone elsewhere
Private Service ConnectvalkeyTwo consumer endpoints in the stage's data subnet that reach the Valkey instanceSame in every stage
Secret Managerfirestore, valkeyThe connection values mongo--* and redis--* that External Secrets maps into the podsSame in every stage
Parameter Managerevery unit that reads the contract; api-gateway, frontend-serviceReads the Baseline's landing-zone values; publishes the API edge names (api--*) and the front end names and deployed tag (frontend--*)Same in every stage
Cloud DNSapi-gateway, frontend-service, external-dns, external-dns-internalDNS authorization records and the front end's record in the stage zone; zone-level bindings that let external-dns write the API and ArgoCD recordsSame in every stage
Identity and Access Management (IAM)gke, app-namespace, external-secrets, external-dns, valkey, frontend-serviceThe node and front end service accounts, the Workload Identity principal bindings, and the code pipeline's scoped rights on the front endSame in every stage
Cloud Logginggke, frontend-service, chartSystem, workload, API server, controller manager and scheduler logs of the cluster; request logs of both load balancersSame in every stage
Cloud MonitoringgkeSystem and control plane metrics, and Google Cloud Managed Service for Prometheus (enable_managed_prometheus, on)Same in every stage

The application identity also holds roles/cloudtrace.agent, which lets it write traces to Cloud Trace. Sizing per stage has every stage value.

Kubernetes components​

ComponentUnitRole
ArgoCDargocdSyncs the application's Helm chart from the GitOps repository; two replicas per component in staging and prod
External Secrets Operatorexternal-secretsCopies the connection values and the application secrets from the stage project's Secret Manager into Kubernetes Secrets through the ClusterSecretStore gcp-sm
ExternalDNSexternal-dns, external-dns-internalTwo releases: external-dns writes the API record into the stage zone, ext-dns-int writes ArgoCD's record into internal.company.com
cert-managercert-managerAn internal certificate authority for *.<stage>.internal.company.com hosts such as ArgoCD; public certificates come from Certificate Manager
GKE Dataplane V2gkeThe cluster's eBPF data plane, which enforces the chart's default-deny network policy

Everything the infrastructure repository installs into the cluster tolerates the system pool's taint; the application chart does not, so its pods run on auto-provisioned nodes.

Used from the Baseline​

ServiceWhere it livesUse
Parameter Manager contractEach stage projectThe landing-zone values every module reads at plan time, published by the Baseline's pm-publish unit
Shared VPCacme-core-networkThe stage's nodes subnet with its pods and services ranges, the data subnet for the Valkey endpoints, the domain's shared proxy-only subnet for the internal load balancer, the GKE control-plane range and Cloud NAT for egress
Cloud DNS zonesacme-core-dns, acme-core-networkThe stage zone <stage>.company.com and the private zone internal.company.com
Artifact Registryacme-core-artifactsThe repositories acme-gcp-blueprint-webapp (API) and acme-gcp-blueprint-webapp-frontend (front end), with immutable tags and Artifact Analysis scanning on push
Workload Identity Federationacme-core-autoThe CI service accounts sa-acme-webapp-infra-ci and sa-acme-webapp-code-ci, with no keys
Secret Manageracme-core-autoThe acme-runner GitHub App credentials that ArgoCD clones the GitOps repository with
State bucketacme-core-rootacme-usw1-root-tfstate, under the apps/app-blueprint/ prefix
Cloud Armor rule templateEach stage projectwaf--policy-template, the rules both stage policies are built from; an optional organization-level policy at the plat folder is evaluated first

The exact versions of the tools, providers and charts are on the versions page. How the values cross from the Baseline is on landing zone contract.