Kubernetes
Kubernetes schedules containers onto nodes and keeps them running as declared. Inside each stage's GKE cluster, the GCP Web App Blueprint runs a small set of platform add-ons on a reserved node pool and the application on auto-provisioned capacity, with every pod hardened and isolated by default.
What it does
A namespace groups workloads; Pod Security Standards enforced per namespace reject pods that ask for privileges. A Deployment keeps a number of pod replicas running, a HorizontalPodAutoscaler (HPA) changes that number with load, and a PodDisruptionBudget (PDB) keeps a minimum running during node drains. Topology spread constraints distribute replicas over zones and nodes. A NetworkPolicy allows only the listed traffic once a default-deny is in place. Taints and tolerations keep pods off nodes they do not belong on.
How BuiltForProd uses it
| Namespace | What runs | Installed by |
|---|---|---|
argocd | ArgoCD | argocd unit |
cert-manager | cert-manager and the internal CA | cert-manager unit |
external-secrets | External Secrets Operator | external-secrets unit |
kube-system | The two external-dns releases | external-dns units |
blueprint-app | The API: Deployment, Service, Gateway, HTTPRoute, HPA, PDB, NetworkPolicy, ExternalSecrets | ArgoCD, from the chart |
Where pods run. The system node pool is tainted CriticalAddonsOnly=true:NoSchedule, and every add-on tolerates it. The application chart sets no toleration, node selector or affinity on purpose: its pods cannot land on the system pool, so node auto-provisioning creates untainted pools that fit them and removes the nodes when the pods go.
Namespace and identity. The app-namespace unit creates blueprint-app with the Pod Security Standard restricted enforced and warned, and the service account blueprint-app-sa. Workload Identity Federation for GKE binds that Kubernetes service account directly as an IAM principal, with no Google service account in between, to roles/datastore.user and roles/cloudtrace.agent; the Valkey unit adds its connection role on the instance.
Pod hardening. The pods run as user and group 10001, non-root, with the RuntimeDefault seccomp profile, no privilege escalation, every capability dropped and a read-only root filesystem with an emptyDir on /tmp only.
Scaling and availability, per stage values file:
| Stage | Replicas | HPA | PDB minAvailable |
|---|---|---|---|
| dev | 1 | off | off |
| staging | 2 | 2 to 5, 70% CPU | 1 |
| prod | 3 | 3 to 10, 60% CPU | 2 |
Replicas spread over zones and hosts with maxSkew: 1 and ScheduleAnyway, so a small cluster stays schedulable and the autoscaler adds the node the spread needs.
Network isolation. The chart's NetworkPolicy, enforced by Dataplane V2, denies all ingress and egress by default, then allows TCP 8080 in from Google's load balancer and health-check ranges, and out: DNS to kube-dns, the GKE metadata server, TCP 443 to the Firestore endpoints and the private Google API ranges, and TCP 6379 to the stage's data subnet for Valkey. Other internet egress is off unless allowInternetEgress is set.
Terms you will see
| Term | Meaning |
|---|---|
restricted | The strictest Pod Security Standard, enforced on the app namespace. |
CriticalAddonsOnly | The taint that reserves the system pool for platform add-ons. |
| HPA | Scales replicas between a minimum and a maximum on CPU use. |
| PDB | Keeps a minimum of pods up while nodes are drained or upgraded. |
| Default-deny | A NetworkPolicy baseline that blocks traffic not explicitly allowed. |
Where to read more
- GCP Web App Blueprint overview for the application.
- Helm for the chart that declares these objects.
- Defense in depth for how pod and network controls layer.