Service inventory
The Web App Blueprint deploys seventeen Google Cloud services and features and five Kubernetes components into each stage project, and relies on shared services that the GCP Enterprise Baseline runs in its core projects. Everything in the first two tables is created by the blueprint's own code; the third lists what it uses from the Baseline.
How the pieces group
Google Cloud services
| Service | Unit | What it does in the blueprint | Stage defaults |
|---|---|---|---|
| Google Kubernetes Engine (GKE) | gke | One regional Standard cluster per stage, acme-usw1-<stage>-gke, on the Regular release channel, with private nodes, a DNS-based control-plane endpoint, Dataplane V2, Workload Identity Federation for GKE, Shielded nodes and security posture | Two zones in dev, three in staging and prod; deletion protection in prod |
| GKE node pools | gke | A system pool of e2-standard-2 nodes tainted for platform components, and node auto-provisioning that creates and removes pools for the application | Auto-provisioning ceiling 32, 64 and 128 vCPU |
| GKE Gateway | gke (controller), chart, argocd | The Gateway API controller: the chart's public Gateway (gke-l7-global-external-managed) and ArgoCD's internal one (gke-l7-rilb) | Same in every stage |
| Cloud Load Balancing | frontend-service, chart, argocd | A global external Application Load Balancer for the front end, one the Gateway controller builds for the API, and a regional internal one for ArgoCD; two SSL policies with the MODERN profile and TLS 1.2 minimum | Same in every stage |
| Cloud Armor | api-gateway, frontend-service | Two security policies per stage, acme-usw1-<stage>-api-armor and -frontend-armor, built from the Baseline's rule template | Rate and WAF rules in preview in dev; preview off in staging and prod |
| Certificate Manager | api-gateway, frontend-service | DNS authorizations, Google-managed certificates and certificate maps for blueprint-api and blueprint-app | Same in every stage |
| Cloud CDN | frontend-service | Caches the front end on the load balancer's backend service in CACHE_ALL_STATIC mode | Same in every stage |
| Cloud Run | frontend-service | The service acme-usw1-<stage>-frontend: nginx serving the built React app, internal and load balancer ingress only, no run.app URL | 0 to 10 instances of 1 vCPU and 256 MiB |
| Firestore | firestore | The database acme-usw1-<stage>-mongo, Enterprise edition with MongoDB compatibility; the application signs in through IAM (MONGODB-OIDC) | Point-in-time recovery in staging and prod; daily backups kept 35 days and delete protection in prod |
| Memorystore for Valkey | valkey | The instance acme-usw1-<stage>-valkey, Valkey 8.0 in cluster-disabled mode, TLS and IAM authentication | SHARED_CORE_NANO without a replica in dev; STANDARD_SMALL with a replica in another zone elsewhere |
| Private Service Connect | valkey | Two consumer endpoints in the stage's data subnet that reach the Valkey instance | Same in every stage |
| Secret Manager | firestore, valkey | The connection values mongo--* and redis--* that External Secrets maps into the pods | Same in every stage |
| Parameter Manager | every unit that reads the contract; api-gateway, frontend-service | Reads the Baseline's landing-zone values; publishes the API edge names (api--*) and the front end names and deployed tag (frontend--*) | Same in every stage |
| Cloud DNS | api-gateway, frontend-service, external-dns, external-dns-internal | DNS authorization records and the front end's record in the stage zone; zone-level bindings that let external-dns write the API and ArgoCD records | Same in every stage |
| Identity and Access Management (IAM) | gke, app-namespace, external-secrets, external-dns, valkey, frontend-service | The node and front end service accounts, the Workload Identity principal bindings, and the code pipeline's scoped rights on the front end | Same in every stage |
| Cloud Logging | gke, frontend-service, chart | System, workload, API server, controller manager and scheduler logs of the cluster; request logs of both load balancers | Same in every stage |
| Cloud Monitoring | gke | System and control plane metrics, and Google Cloud Managed Service for Prometheus (enable_managed_prometheus, on) | Same in every stage |
The application identity also holds roles/cloudtrace.agent, which lets it write traces to Cloud Trace. Sizing per stage has every stage value.
Kubernetes components
| Component | Unit | Role |
|---|---|---|
| ArgoCD | argocd | Syncs the application's Helm chart from the GitOps repository; two replicas per component in staging and prod |
| External Secrets Operator | external-secrets | Copies the connection values and the application secrets from the stage project's Secret Manager into Kubernetes Secrets through the ClusterSecretStore gcp-sm |
| ExternalDNS | external-dns, external-dns-internal | Two releases: external-dns writes the API record into the stage zone, ext-dns-int writes ArgoCD's record into internal.company.com |
| cert-manager | cert-manager | An internal certificate authority for *.<stage>.internal.company.com hosts such as ArgoCD; public certificates come from Certificate Manager |
| GKE Dataplane V2 | gke | The cluster's eBPF data plane, which enforces the chart's default-deny network policy |
Everything the infrastructure repository installs into the cluster tolerates the system pool's taint; the application chart does not, so its pods run on auto-provisioned nodes.
Used from the Baseline
| Service | Where it lives | Use |
|---|---|---|
| Parameter Manager contract | Each stage project | The landing-zone values every module reads at plan time, published by the Baseline's pm-publish unit |
| Shared VPC | acme-core-network | The stage's nodes subnet with its pods and services ranges, the data subnet for the Valkey endpoints, the domain's shared proxy-only subnet for the internal load balancer, the GKE control-plane range and Cloud NAT for egress |
| Cloud DNS zones | acme-core-dns, acme-core-network | The stage zone <stage>.company.com and the private zone internal.company.com |
| Artifact Registry | acme-core-artifacts | The repositories acme-gcp-blueprint-webapp (API) and acme-gcp-blueprint-webapp-frontend (front end), with immutable tags and Artifact Analysis scanning on push |
| Workload Identity Federation | acme-core-auto | The CI service accounts sa-acme-webapp-infra-ci and sa-acme-webapp-code-ci, with no keys |
| Secret Manager | acme-core-auto | The acme-runner GitHub App credentials that ArgoCD clones the GitOps repository with |
| State bucket | acme-core-root | acme-usw1-root-tfstate, under the apps/app-blueprint/ prefix |
| Cloud Armor rule template | Each stage project | waf--policy-template, the rules both stage policies are built from; an optional organization-level policy at the plat folder is evaluated first |
The exact versions of the tools, providers and charts are on the versions page. How the values cross from the Baseline is on landing zone contract.