GCP
GCP Mental Model
Practice mapping app jobs to GCP projects, APIs, resources, callers, billing, and shared responsibility.
Projects, Billing, and Regions
Practice placing a GCP workload through projects, folders, billing accounts, APIs, quotas, regions, and zones.
Resources, Names, and Labels
Practice using project IDs, names, labels, tags, and resource paths to identify exact GCP resources before changing them.
GCP Core Services Map
Practice mapping GCP service families to app jobs for traffic, compute, state, access, signals, deployment, cost, and recovery.
What Is GCP IAM
Practice reading GCP IAM as principal, role, resource, scope, condition, and evidence before applying fixes.
Service Accounts
Practice runtime identity, deploy identity, ADC, impersonation, keys, and Workload Identity Federation for GCP workloads.
Secret Manager
Practice secret names, versions, IAM access, runtime flow, rotation, evidence, encryption, and KMS judgment.
What Is a GCP VPC
Practice separating global VPC networks, regional subnets, route decisions, and service-specific attachment points.
Firewall Rules
Practice GCP firewall direction, priority, targets, sources, implied rules, and IAM boundaries.
Public Entry Points
Practice tracing DNS, HTTPS, load balancer frontends, serverless backends, and health evidence for public GCP services.
Cloud Run Networking
Practice separating Cloud Run ingress, IAM, egress, Direct VPC egress, private ranges, all-traffic paths, and startup failure evidence.
Private Access
Practice choosing private access patterns for managed services while keeping DNS, network path, and IAM evidence separate.
What Is Compute
Practice matching GCP runtimes to workload shape, start signal, scaling behavior, and operating responsibility.
Cloud Run
Practice Cloud Run container contracts, services, revisions, traffic, scaling, runtime identity, configuration, and rollout evidence.
Compute Engine
Practice VM-shaped responsibility: images, disks, zones, startup, process management, service accounts, networking, logs, and patching.
Cloud Run Functions
Practice event-shaped compute with events, triggers, handlers, invocations, retries, timeouts, identity, logs, and service boundaries.
GKE
Practice recognizing when Kubernetes is the requirement, then reviewing clusters, Autopilot versus Standard, workload objects, identity, and node responsibility.
What Is Storage
Practice matching GCP data shapes to objects, relational records, documents, analytics tables, attached storage, and recovery copies.
Cloud Storage
Practice Cloud Storage buckets, objects, names, metadata, access, signed URLs, lifecycle, and versioning decisions.
Cloud SQL
Practice relational data shape, Cloud SQL instances, transactions, connections, private access, migrations, backups, and high availability.
Firestore
Practice Firestore document modeling through documents, collections, paths, access patterns, indexes, transactions, and security boundaries.
BigQuery
Practice BigQuery analytics shape through datasets, tables, loading, queries, partitioning, clustering, cost habits, and data quality.
Persistent Disk and Filestore
Practice attached-storage choices for GCP workloads that need block devices, snapshots, placement, or shared filesystem paths.
Backups and Retention
Practice recovery points, service-specific restore options, retention, safe deletion, and restore drills for GCP data.