GCP services used
This page lists every Google Cloud service and every tool the GCP edition uses, with a link to the explainer for each. Each explainer says what the service does in general and then exactly how BuiltForProd uses it: which project runs it, which unit or module creates it, and what it is connected to.
The Used in column names the product whose repositories create or configure the service. "All four products" means the GCP Enterprise Baseline and the GCP Web App, Data and ETL, and Secrets Blueprints. Services and features that are switched off by default, such as VPC Service Controls, the organization-wide edge rules of Google Cloud Armor, the Security Command Center notifier on Cloud Run, the self-hosted runners on GKE Autopilot and the bastions behind Identity-Aware Proxy, are listed because the code for them ships and one setting turns them on.
How the areas fit together
Identity comes first because every other service is reached through an IAM binding on the organization, a folder, a project or a resource. The Shared VPC networks carry the workloads, the security services constrain and watch everything, and the delivery tooling is the only path by which any of it changes. The architecture overview shows the pieces in context, and the GCP product page says what each GCP product delivers.
Resource hierarchy and identity
The organization, folders and projects, and who and what can act in them.
| Service | What the page covers | Used in |
|---|---|---|
| Resource Manager | How the GCP Enterprise Baseline builds the organization, two folders and 14 projects, the secure tags bound to them, and the baseline every project receives. | GCP Enterprise Baseline, all three blueprints |
| Organization Policy Service | The 19 organization policy constraints the GCP Enterprise Baseline sets at the organization node, the exceptions, and the custom label constraints. | GCP Enterprise Baseline |
| Identity and Access Management | How the GCP Enterprise Baseline binds its 14 groups to IAM roles at organization, folder and project, with custom roles and resource-level grants. | All four products |
| IAM deny policies | How IAM deny policies keep anyone, Owners included, from deleting or changing the GCP audit trail, and keep auditors away from data. | GCP Enterprise Baseline |
| Cloud Identity | The 14 Google groups the GCP Enterprise Baseline grants access to, how they are found or created, and how break-glass sign-ins are watched. | GCP Enterprise Baseline |
| Privileged Access Manager | How the GCP Enterprise Baseline makes Owner and organization admin eligible grants with Privileged Access Manager, with approvals and a 12-hour limit. | GCP Enterprise Baseline |
| Workload Identity Federation | How GitHub Actions workflows authenticate to Google Cloud through Workload Identity Federation and per-repository service accounts, with no keys. | All four products |
| Service accounts | Where the GCP platform uses service accounts, how deployers are impersonated per project, and why no service account key exists. | All four products |
Security, keys and secrets
The detective and protective controls, the keys, and where secrets and the contract live.
| Service | What the page covers | Used in |
|---|---|---|
| Security Command Center | How the GCP Enterprise Baseline wires Security Command Center: the tier, high-severity notifications, the sandbox mute rule and the optional notifier. | GCP Enterprise Baseline |
| Cloud KMS | Which Cloud KMS key rings and keys the GCP platform creates, how they rotate, and who may use each one. | GCP Enterprise Baseline, Secrets Blueprint, Data and ETL Blueprint |
| SOPS | How the GCP Secrets Blueprint keeps application secrets encrypted in Git with SOPS and per-stage Cloud KMS keys, then syncs them to Secret Manager. | Secrets Blueprint, GCP Enterprise Baseline |
| Secret Manager | Where the GCP platform keeps secrets in Secret Manager: hand-entered placeholders, the web app's connection values and the synced application secrets. | GCP Enterprise Baseline, Web App Blueprint, Secrets Blueprint |
| Parameter Manager | How the GCP Enterprise Baseline publishes the landing-zone contract as Parameter Manager parameters, and how the blueprints read and record values there. | All four products |
| Google Cloud Armor | How Cloud Armor protects the GCP web application: per-stage policies built from the Baseline's rule template, and the optional hierarchical policy. | GCP Enterprise Baseline, Web App Blueprint |
| Cloud NGFW firewall policies | The hierarchical firewall policy at the organization and the network firewall policy of each VPC that keep prod and nonprod apart and log denied traffic. | GCP Enterprise Baseline |
| VPC Service Controls | How the GCP Enterprise Baseline can put a VPC Service Controls perimeter around the stage projects, always written as a dry run first. | GCP Enterprise Baseline |
| Artifact Analysis | How Artifact Analysis scans every image pushed to the GCP platform's Artifact Registry for vulnerabilities, and what it costs. | GCP Enterprise Baseline |
Audit, logging and monitoring
Where every audit record, log line, metric and alert ends up, and what the platform costs.
| Service | What the page covers | Used in |
|---|---|---|
| Cloud Logging | How the GCP platform collects audit logs from every project through aggregated sinks into a central log bucket and an archive, and how long logs are kept. | All four products |
| Cloud Monitoring | How acme-core-security is the metrics scope over every GCP project, the CIS and platform alert policies, the notification channel and Cloud Trace. | GCP Enterprise Baseline, Web App Blueprint |
| Pub/Sub | How the GCP platform uses Pub/Sub: the alerts topic that carries Security Command Center findings, and the event delivery behind the ETL trigger. | GCP Enterprise Baseline, Data and ETL Blueprint |
| Cloud Billing | How the GCP Enterprise Baseline attaches projects to the billing account and sets optional per-project budget alerts. | GCP Enterprise Baseline |
Networking and DNS
The Shared VPC networks, egress, private access to Google services and name resolution.
| Service | What the page covers | Used in |
|---|---|---|
| VPC networks | The hub, prod and nonprod VPC networks of the GCP Enterprise Baseline, their per-stage subnets and secondary ranges, and where every range comes from. | GCP Enterprise Baseline, all three blueprints |
| Shared VPC | How acme-core-network hosts the GCP platform's networks as the only Shared VPC host and each stage project uses only its own subnets. | GCP Enterprise Baseline, all three blueprints |
| VPC Network Peering | How the hub VPC peers with each isolation-domain VPC on the GCP platform, and why prod and nonprod cannot route to each other. | GCP Enterprise Baseline |
| Cloud NAT | How each GCP VPC network reaches the internet through its own Cloud Router and Cloud NAT, and what the switches cost. | GCP Enterprise Baseline |
| Private Service Access | How the GCP platform reaches Google APIs and managed services privately: Private Google Access, Private Service Access and Private Service Connect. | GCP Enterprise Baseline, Web App Blueprint |
| Cloud DNS | The public and private zones of the GCP platform, DNSSEC, query logging, and how stage identities write only their own records. | GCP Enterprise Baseline, Web App Blueprint |
| Identity-Aware Proxy | How engineers reach private GCP resources through IAP TCP forwarding and OS Login, per group and stage, with optional bastions. | GCP Enterprise Baseline |
| Compute Engine | Where virtual machines appear on the GCP platform, GKE nodes and optional bastions, and the project-wide settings the Baseline enforces on all of them. | GCP Enterprise Baseline, Web App Blueprint |
Edge and load balancing
Where public traffic enters the web application.
| Service | What the page covers | Used in |
|---|---|---|
| Cloud Load Balancing | The global external Application Load Balancers in front of the GCP web application: one built by the GKE Gateway for the API, one for the SPA. | Web App Blueprint |
| Cloud CDN | How Cloud CDN caches the GCP web application's single-page front end at the edge, and how a deployment invalidates it. | Web App Blueprint |
| Certificate Manager | How the GCP web application gets Google-managed certificates through DNS authorizations in the stage zone and certificate maps on its load balancers. | Web App Blueprint |
| GKE Gateway | How the GCP Web App Blueprint exposes its API and ArgoCD through the Kubernetes Gateway API on GKE, with Cloud Armor, TLS and health checks. | Web App Blueprint |
Storage and data
The buckets, the data lake and the databases.
| Service | What the page covers | Used in |
|---|---|---|
| Cloud Storage | Every Cloud Storage bucket the GCP platform creates, what it holds, and the controls applied to all of them. | GCP Enterprise Baseline, Web App Blueprint, Data and ETL Blueprint |
| BigQuery | How the GCP Data and ETL Blueprint lands processed data in BigQuery with column-level policy tags, and how the Baseline links its log bucket to a dataset. | Data and ETL Blueprint, GCP Enterprise Baseline |
| Dataplex Universal Catalog | How Dataplex organizes the GCP data lake into zones, discovers the files and publishes them as BigQuery tables. | Data and ETL Blueprint |
| Dataproc Serverless | How the GCP Data and ETL Blueprint runs one Spark batch per landed file on Dataproc Serverless, as a dedicated identity in the stage data subnet. | Data and ETL Blueprint |
| Eventarc | How Eventarc delivers a Cloud Storage object-finalized event from the raw bucket to the GCP ETL trigger service. | Data and ETL Blueprint |
| Firestore with MongoDB compatibility | How the GCP Web App Blueprint stores its data in Firestore with MongoDB compatibility, without passwords, with backups and recovery per stage. | Web App Blueprint |
| Memorystore for Valkey | How the GCP Web App Blueprint runs Memorystore for Valkey with TLS and IAM authentication, reached through Private Service Connect endpoints. | Web App Blueprint |
Compute and containers
What runs the workloads and how their images are built and stored.
| Service | What the page covers | Used in |
|---|---|---|
| Artifact Registry | How Artifact Registry holds every GCP platform image with immutable tags, cleanup policies that keep releases, and scoped readers and writers. | GCP Enterprise Baseline, Web App Blueprint, Data and ETL Blueprint |
| Cloud Run | The three Cloud Run services of the GCP platform: the web front end behind Cloud CDN, the ETL trigger and the optional findings notifier. | Web App Blueprint, Data and ETL Blueprint, GCP Enterprise Baseline |
| Google Kubernetes Engine | How the GCP Web App Blueprint runs one private regional GKE cluster per stage, and the optional Autopilot cluster that hosts the Baseline's runners. | Web App Blueprint, GCP Enterprise Baseline |
| Kubernetes | What runs inside the GCP Web App Blueprint GKE cluster and how the application pods are hardened, scaled and isolated. | Web App Blueprint |
| Helm | What Helm is, how the GCP Web App Blueprint chart is structured, and which add-ons and runner components are installed as Helm releases. | Web App Blueprint, GCP Enterprise Baseline |
| ArgoCD | How ArgoCD in each GKE cluster syncs the GCP Web App Blueprint chart from the GitOps repository, automatically in dev and staging and by hand in prod. | Web App Blueprint |
| cert-manager | How cert-manager runs the internal certificate authority of the GCP Web App Blueprint for its internal hostnames. | Web App Blueprint |
| external-dns | How two external-dns releases write the GCP web application's public and internal records from its routes, each with access to one zone only. | Web App Blueprint |
| External Secrets Operator | How the External Secrets Operator turns Secret Manager secrets into Kubernetes Secrets for the GCP Web App Blueprint. | Web App Blueprint, Secrets Blueprint |
| Docker | How the GCP platform images are built, hardened in their Dockerfiles, scanned and pushed once to Artifact Registry. | Web App Blueprint, Data and ETL Blueprint, GCP Enterprise Baseline |
Delivery and tooling
The only path by which any of the above changes.
| Service | What the page covers | Used in |
|---|---|---|
| OpenTofu | What OpenTofu is, which version the GCP repositories pin, and how providers, modules and state are organized around it. | GCP Enterprise Baseline, Web App Blueprint, Data and ETL Blueprint |
| Terragrunt | What Terragrunt adds on top of OpenTofu and how the Stacks layout of units, templates and stage files works in the GCP repositories. | GCP Enterprise Baseline, Web App Blueprint, Data and ETL Blueprint |
| GitHub Actions | How every GCP repository plans, applies, builds, scans and promotes through GitHub Actions, on GitHub-hosted runners or the optional self-hosted runners. | All four products |
| Checkov, Trivy and tflint | Which static scanners run on the GCP infrastructure code and images, where they run, and how findings are suppressed with a reason. | GCP Enterprise Baseline, Web App Blueprint, Data and ETL Blueprint |
| pre-commit | Which pre-commit hooks run in each GCP repository, from formatters and scanners to the guard scripts that keep the layout, address plan and contract consistent. | All four products |
Terms used on these pages
The glossary defines the GCP terms these explainers use, from folder and Shared VPC to Workload Identity Federation. The AWS services used and Azure services used pages are the same index for the other editions.