Skip to main content

GCP services used

This page lists every Google Cloud service and every tool the GCP edition uses, with a link to the explainer for each. Each explainer says what the service does in general and then exactly how BuiltForProd uses it: which project runs it, which unit or module creates it, and what it is connected to.

The Used in column names the product whose repositories create or configure the service. "All four products" means the GCP Enterprise Baseline and the GCP Web App, Data and ETL, and Secrets Blueprints. Services and features that are switched off by default, such as VPC Service Controls, the organization-wide edge rules of Google Cloud Armor, the Security Command Center notifier on Cloud Run, the self-hosted runners on GKE Autopilot and the bastions behind Identity-Aware Proxy, are listed because the code for them ships and one setting turns them on.

How the areas fit together​

Identity comes first because every other service is reached through an IAM binding on the organization, a folder, a project or a resource. The Shared VPC networks carry the workloads, the security services constrain and watch everything, and the delivery tooling is the only path by which any of it changes. The architecture overview shows the pieces in context, and the GCP product page says what each GCP product delivers.

Resource hierarchy and identity​

The organization, folders and projects, and who and what can act in them.

ServiceWhat the page coversUsed in
Resource ManagerHow the GCP Enterprise Baseline builds the organization, two folders and 14 projects, the secure tags bound to them, and the baseline every project receives.GCP Enterprise Baseline, all three blueprints
Organization Policy ServiceThe 19 organization policy constraints the GCP Enterprise Baseline sets at the organization node, the exceptions, and the custom label constraints.GCP Enterprise Baseline
Identity and Access ManagementHow the GCP Enterprise Baseline binds its 14 groups to IAM roles at organization, folder and project, with custom roles and resource-level grants.All four products
IAM deny policiesHow IAM deny policies keep anyone, Owners included, from deleting or changing the GCP audit trail, and keep auditors away from data.GCP Enterprise Baseline
Cloud IdentityThe 14 Google groups the GCP Enterprise Baseline grants access to, how they are found or created, and how break-glass sign-ins are watched.GCP Enterprise Baseline
Privileged Access ManagerHow the GCP Enterprise Baseline makes Owner and organization admin eligible grants with Privileged Access Manager, with approvals and a 12-hour limit.GCP Enterprise Baseline
Workload Identity FederationHow GitHub Actions workflows authenticate to Google Cloud through Workload Identity Federation and per-repository service accounts, with no keys.All four products
Service accountsWhere the GCP platform uses service accounts, how deployers are impersonated per project, and why no service account key exists.All four products

Security, keys and secrets​

The detective and protective controls, the keys, and where secrets and the contract live.

ServiceWhat the page coversUsed in
Security Command CenterHow the GCP Enterprise Baseline wires Security Command Center: the tier, high-severity notifications, the sandbox mute rule and the optional notifier.GCP Enterprise Baseline
Cloud KMSWhich Cloud KMS key rings and keys the GCP platform creates, how they rotate, and who may use each one.GCP Enterprise Baseline, Secrets Blueprint, Data and ETL Blueprint
SOPSHow the GCP Secrets Blueprint keeps application secrets encrypted in Git with SOPS and per-stage Cloud KMS keys, then syncs them to Secret Manager.Secrets Blueprint, GCP Enterprise Baseline
Secret ManagerWhere the GCP platform keeps secrets in Secret Manager: hand-entered placeholders, the web app's connection values and the synced application secrets.GCP Enterprise Baseline, Web App Blueprint, Secrets Blueprint
Parameter ManagerHow the GCP Enterprise Baseline publishes the landing-zone contract as Parameter Manager parameters, and how the blueprints read and record values there.All four products
Google Cloud ArmorHow Cloud Armor protects the GCP web application: per-stage policies built from the Baseline's rule template, and the optional hierarchical policy.GCP Enterprise Baseline, Web App Blueprint
Cloud NGFW firewall policiesThe hierarchical firewall policy at the organization and the network firewall policy of each VPC that keep prod and nonprod apart and log denied traffic.GCP Enterprise Baseline
VPC Service ControlsHow the GCP Enterprise Baseline can put a VPC Service Controls perimeter around the stage projects, always written as a dry run first.GCP Enterprise Baseline
Artifact AnalysisHow Artifact Analysis scans every image pushed to the GCP platform's Artifact Registry for vulnerabilities, and what it costs.GCP Enterprise Baseline

Audit, logging and monitoring​

Where every audit record, log line, metric and alert ends up, and what the platform costs.

ServiceWhat the page coversUsed in
Cloud LoggingHow the GCP platform collects audit logs from every project through aggregated sinks into a central log bucket and an archive, and how long logs are kept.All four products
Cloud MonitoringHow acme-core-security is the metrics scope over every GCP project, the CIS and platform alert policies, the notification channel and Cloud Trace.GCP Enterprise Baseline, Web App Blueprint
Pub/SubHow the GCP platform uses Pub/Sub: the alerts topic that carries Security Command Center findings, and the event delivery behind the ETL trigger.GCP Enterprise Baseline, Data and ETL Blueprint
Cloud BillingHow the GCP Enterprise Baseline attaches projects to the billing account and sets optional per-project budget alerts.GCP Enterprise Baseline

Networking and DNS​

The Shared VPC networks, egress, private access to Google services and name resolution.

ServiceWhat the page coversUsed in
VPC networksThe hub, prod and nonprod VPC networks of the GCP Enterprise Baseline, their per-stage subnets and secondary ranges, and where every range comes from.GCP Enterprise Baseline, all three blueprints
Shared VPCHow acme-core-network hosts the GCP platform's networks as the only Shared VPC host and each stage project uses only its own subnets.GCP Enterprise Baseline, all three blueprints
VPC Network PeeringHow the hub VPC peers with each isolation-domain VPC on the GCP platform, and why prod and nonprod cannot route to each other.GCP Enterprise Baseline
Cloud NATHow each GCP VPC network reaches the internet through its own Cloud Router and Cloud NAT, and what the switches cost.GCP Enterprise Baseline
Private Service AccessHow the GCP platform reaches Google APIs and managed services privately: Private Google Access, Private Service Access and Private Service Connect.GCP Enterprise Baseline, Web App Blueprint
Cloud DNSThe public and private zones of the GCP platform, DNSSEC, query logging, and how stage identities write only their own records.GCP Enterprise Baseline, Web App Blueprint
Identity-Aware ProxyHow engineers reach private GCP resources through IAP TCP forwarding and OS Login, per group and stage, with optional bastions.GCP Enterprise Baseline
Compute EngineWhere virtual machines appear on the GCP platform, GKE nodes and optional bastions, and the project-wide settings the Baseline enforces on all of them.GCP Enterprise Baseline, Web App Blueprint

Edge and load balancing​

Where public traffic enters the web application.

ServiceWhat the page coversUsed in
Cloud Load BalancingThe global external Application Load Balancers in front of the GCP web application: one built by the GKE Gateway for the API, one for the SPA.Web App Blueprint
Cloud CDNHow Cloud CDN caches the GCP web application's single-page front end at the edge, and how a deployment invalidates it.Web App Blueprint
Certificate ManagerHow the GCP web application gets Google-managed certificates through DNS authorizations in the stage zone and certificate maps on its load balancers.Web App Blueprint
GKE GatewayHow the GCP Web App Blueprint exposes its API and ArgoCD through the Kubernetes Gateway API on GKE, with Cloud Armor, TLS and health checks.Web App Blueprint

Storage and data​

The buckets, the data lake and the databases.

ServiceWhat the page coversUsed in
Cloud StorageEvery Cloud Storage bucket the GCP platform creates, what it holds, and the controls applied to all of them.GCP Enterprise Baseline, Web App Blueprint, Data and ETL Blueprint
BigQueryHow the GCP Data and ETL Blueprint lands processed data in BigQuery with column-level policy tags, and how the Baseline links its log bucket to a dataset.Data and ETL Blueprint, GCP Enterprise Baseline
Dataplex Universal CatalogHow Dataplex organizes the GCP data lake into zones, discovers the files and publishes them as BigQuery tables.Data and ETL Blueprint
Dataproc ServerlessHow the GCP Data and ETL Blueprint runs one Spark batch per landed file on Dataproc Serverless, as a dedicated identity in the stage data subnet.Data and ETL Blueprint
EventarcHow Eventarc delivers a Cloud Storage object-finalized event from the raw bucket to the GCP ETL trigger service.Data and ETL Blueprint
Firestore with MongoDB compatibilityHow the GCP Web App Blueprint stores its data in Firestore with MongoDB compatibility, without passwords, with backups and recovery per stage.Web App Blueprint
Memorystore for ValkeyHow the GCP Web App Blueprint runs Memorystore for Valkey with TLS and IAM authentication, reached through Private Service Connect endpoints.Web App Blueprint

Compute and containers​

What runs the workloads and how their images are built and stored.

ServiceWhat the page coversUsed in
Artifact RegistryHow Artifact Registry holds every GCP platform image with immutable tags, cleanup policies that keep releases, and scoped readers and writers.GCP Enterprise Baseline, Web App Blueprint, Data and ETL Blueprint
Cloud RunThe three Cloud Run services of the GCP platform: the web front end behind Cloud CDN, the ETL trigger and the optional findings notifier.Web App Blueprint, Data and ETL Blueprint, GCP Enterprise Baseline
Google Kubernetes EngineHow the GCP Web App Blueprint runs one private regional GKE cluster per stage, and the optional Autopilot cluster that hosts the Baseline's runners.Web App Blueprint, GCP Enterprise Baseline
KubernetesWhat runs inside the GCP Web App Blueprint GKE cluster and how the application pods are hardened, scaled and isolated.Web App Blueprint
HelmWhat Helm is, how the GCP Web App Blueprint chart is structured, and which add-ons and runner components are installed as Helm releases.Web App Blueprint, GCP Enterprise Baseline
ArgoCDHow ArgoCD in each GKE cluster syncs the GCP Web App Blueprint chart from the GitOps repository, automatically in dev and staging and by hand in prod.Web App Blueprint
cert-managerHow cert-manager runs the internal certificate authority of the GCP Web App Blueprint for its internal hostnames.Web App Blueprint
external-dnsHow two external-dns releases write the GCP web application's public and internal records from its routes, each with access to one zone only.Web App Blueprint
External Secrets OperatorHow the External Secrets Operator turns Secret Manager secrets into Kubernetes Secrets for the GCP Web App Blueprint.Web App Blueprint, Secrets Blueprint
DockerHow the GCP platform images are built, hardened in their Dockerfiles, scanned and pushed once to Artifact Registry.Web App Blueprint, Data and ETL Blueprint, GCP Enterprise Baseline

Delivery and tooling​

The only path by which any of the above changes.

ServiceWhat the page coversUsed in
OpenTofuWhat OpenTofu is, which version the GCP repositories pin, and how providers, modules and state are organized around it.GCP Enterprise Baseline, Web App Blueprint, Data and ETL Blueprint
TerragruntWhat Terragrunt adds on top of OpenTofu and how the Stacks layout of units, templates and stage files works in the GCP repositories.GCP Enterprise Baseline, Web App Blueprint, Data and ETL Blueprint
GitHub ActionsHow every GCP repository plans, applies, builds, scans and promotes through GitHub Actions, on GitHub-hosted runners or the optional self-hosted runners.All four products
Checkov, Trivy and tflintWhich static scanners run on the GCP infrastructure code and images, where they run, and how findings are suppressed with a reason.GCP Enterprise Baseline, Web App Blueprint, Data and ETL Blueprint
pre-commitWhich pre-commit hooks run in each GCP repository, from formatters and scanners to the guard scripts that keep the layout, address plan and contract consistent.All four products

Terms used on these pages​

The glossary defines the GCP terms these explainers use, from folder and Shared VPC to Workload Identity Federation. The AWS services used and Azure services used pages are the same index for the other editions.