Production GKE Platform — From Zero to Production›01 · Google Cloud & GKE services and terms

Lesson 01 of 18 · Part 1 — Foundations

Google Cloud & GKE services and terms

The vocabulary every later lesson assumes: the Google Cloud services a GKE platform is built from, the GKE-specific terms you'll hear in design reviews, and a map from every EKS and AWS term to its GKE equivalent.

Beginner → Practitioner
Key wordsGoogle Cloud servicesGKE termsorganizationfolderprojectShared VPCIAMservice accountCompute EngineCloud Load BalancingPersistent DiskFilestoreArtifact RegistryCloud KMSCloud LoggingCloud MonitoringAutopilotnode poolrelease channelEKS to GKE
Google-managed project (you don't see it) GKE control plane regional: replicas in 3 zones etcd / cluster state managed and backed up by Google Control-plane endpoints DNS-based and/or IP-based Your project and VPC (you own it) Node pools Compute Engine VMs (Standard mode) Autopilot Google runs nodes, you pay per Pod Pods get VPC IPs from alias ranges VPC-native, Dataplane V2 (eBPF) Google APIs for pods Workload Identity Managed components DNS, CSI, logging, LB private
A GKE cluster: Google runs the control plane in its own project; the nodes, Pods and networking live in your project and VPC.

How to use this page

Keep it open while you work through the track. Every later lesson uses these words without explaining them again. If you know AWS and EKS, start with the map at the bottom: most GKE ideas have a direct equivalent, and the few that don't are where the surprises are.

Moving from AWS to Google Cloud is like moving to a new city that has the same kinds of shops with different names. The bakery is still a bakery, but it's on a different street and has its own opening hours. Learn the street names once, and everything you already know about bread still applies.

Google Cloud services a GKE platform uses

Organisation, identity and security

Service / term What it is What GKE uses it for
Organization The root node for a company's resources, tied to its Google Workspace or Cloud Identity domain Org-wide policies and IAM; the top of the resource hierarchy
Folder A group of projects (and other folders) Grouping by environment or business unit; policies inherited downwards
Project The container for resources, APIs, IAM, quotas and billing One or more projects per environment; clusters live in a project
Billing account Pays for one or more projects Cost reporting per project and label
IAM (roles, principals, allow policies) Who may do what on which resource Admin, developer and CI access to GKE; pod access to Google APIs
Service account (Google) A non-human identity for workloads and automation Node identity, CI identity, workload identity targets
Cloud Identity / Google Groups Users and groups Grant IAM and Kubernetes RBAC to groups, not people
Organization Policy Service Constraints on what may be created (allowed regions, no external IPs, required settings) Org-wide guard-rails
Cloud KMS Managed encryption keys Application-layer encryption of Kubernetes Secrets; customer-managed keys (CMEK) for disks
Secret Manager Stores secrets App secrets, mounted into pods or synced (Secret Manager add-on, External Secrets)
Cloud Audit Logs Who called which API, when Who changed the cluster, IAM or network
Security Command Center Security findings across the organisation Misconfigurations and threats, including GKE findings

Networking

Service / term What it is What GKE uses it for
Region, zone A geographic area and its isolated locations (usually 3+ zones) Regional clusters spread over zones; zonal clusters live in one
VPC network A global private network Nodes and Pods get IPs from its subnets
Subnet A regional IP range inside the VPC, with optional secondary ranges Primary range: nodes. Secondary ranges: Pods and Services (lesson 04)
Shared VPC One host project owns the VPC; service projects use its subnets Central network team, clusters in team or environment projects (lesson 03)
Firewall rules / policies Stateful allow and deny rules on VPC traffic GKE creates the rules it needs; you add your own and org-level policies
Cloud Router, Cloud NAT Dynamic routing; outbound internet for private VMs Egress for private nodes (image pulls from outside Google, external APIs)
Private Google Access Reach Google APIs from VMs without external IPs Private nodes pulling from Artifact Registry, writing logs
Private Service Connect Private endpoints to Google or partner services Private access to APIs; also used by GKE's control plane connection
Cloud Load Balancing Global and regional, external and internal, L4 and L7 load balancers Services, Ingress and Gateway (lesson 07)
Cloud Armor WAF and DDoS protection on external Application Load Balancers Protecting public apps
Cloud DNS Managed DNS App hostnames; optionally in-cluster DNS (Cloud DNS for GKE)
Cloud Interconnect, Cloud VPN Private links to on-prem or other clouds Hybrid connectivity

Compute, containers and storage

Service / term What it is What GKE uses it for
Compute Engine, machine type Virtual machines and their sizes (e2, n2, n4, c3, t2d…) Nodes in Standard clusters
Container-Optimized OS (COS) Google's minimal, hardened node OS The default node image (Ubuntu is the alternative)
Spot VMs Spare capacity at a large discount, reclaimable with short notice Cheap, interruption-tolerant node pools
Artifact Registry Private registry for images and packages Your images; scanning, cleanup policies, remote (cache) repositories
Persistent Disk, Hyperdisk Block storage for VMs ReadWriteOnce volumes through the CSI driver
Filestore Managed NFS ReadWriteMany volumes
Cloud Storage Object storage App data, backups; mountable through the Cloud Storage FUSE CSI driver

Observability and cost

Service / term What it is What GKE uses it for
Cloud Logging Log collection, storage, routing (sinks) Node, system and container logs, collected by default
Cloud Monitoring Metrics, dashboards, alerting System metrics by default; your metrics via Managed Service for Prometheus
Managed Service for Prometheus Prometheus-compatible collection and storage, queried with PromQL Workload and kube-state metrics without running Prometheus storage
Cloud Trace Distributed tracing OpenTelemetry traces from apps
Recommender / Active Assist Usage-based recommendations Rightsizing, idle clusters, deprecated API usage before upgrades

GKE terms

Term Meaning
Autopilot Mode where Google manages nodes, scaling and security defaults; you pay for the resources your Pods request
Standard Mode where you manage node pools (machine types, scaling, upgrades); you pay for the VMs
Regional / zonal cluster Control plane replicated across a region's zones, or in one zone (lesson 02)
Node pool Nodes with the same configuration in one cluster
Release channel Rapid, Regular, Stable or Extended: how quickly the cluster receives new versions (lesson 13)
Maintenance window / exclusion When automatic upgrades may run, and periods when they may not
VPC-native cluster Pods and Services use alias IP ranges from the subnet (the default)
Dataplane V2 GKE's eBPF data plane, based on Cilium, with built-in network policy enforcement
Workload Identity Federation for GKE Kubernetes ServiceAccounts act as IAM principals
GKE metadata server Answers pods' credential requests and hides the node's identity
Compute class A named set of node preferences (machine families, Spot, fallbacks) workloads can ask for
Node auto-provisioning (NAP) GKE creates and deletes node pools to fit pending Pods
NEG Network endpoint group: lets load balancers send traffic straight to Pod IPs
Fleet A group of clusters (GKE, on-prem, other clouds) managed together (lesson 14)
Config Sync, Policy Controller Google's GitOps sync and policy (Gatekeeper-based) features for fleets
Backup for GKE Managed backup and restore of cluster resources and volumes

Coming from AWS and EKS

AWS / EKS Google Cloud / GKE Watch out for
Account, Organizations OU, SCP Project, folder, organization policy Policies are constraints, not permission ceilings like SCPs
IAM role (assumed) Google service account, or a principal from Workload Identity Federation Humans use their own Google identity; no role-switching between accounts
VPC (regional), subnet per AZ VPC (global), subnet per region One subnet covers every zone of its region
VPC CNI (pods on ENIs) VPC-native alias IP ranges Pods use a secondary range, not the node subnet; size it up front
Security groups VPC firewall rules and policies, Kubernetes network policy Firewall rules target network tags or service accounts, not ENIs
NAT gateway, VPC endpoints Cloud NAT, Private Google Access, Private Service Connect Private Google Access is a subnet setting, not one endpoint per service
EKS control plane GKE control plane (regional or zonal) Zonal control planes have no zone redundancy
Managed node groups / Karpenter Node pools + cluster autoscaler / node auto-provisioning, compute classes Autopilot removes node management entirely
Fargate Autopilot Autopilot is a whole cluster mode, not a per-pod profile
Access entries / aws-auth IAM roles for GKE + Kubernetes RBAC IAM grants are project-wide; namespace scope comes from RBAC
IRSA / EKS Pod Identity Workload Identity Federation for GKE Grant IAM roles directly to the Kubernetes ServiceAccount principal
AWS Load Balancer Controller (ALB/NLB) Built-in: Services, Ingress, GKE Gateway controller No controller to install; container-native load balancing with NEGs
ECR Artifact Registry Path is REGION-docker.pkg.dev/PROJECT/REPO/IMAGE
EBS / EFS CSI Persistent Disk / Hyperdisk CSI, Filestore CSI Drivers are managed by GKE, not installed by you
CloudWatch, Container Insights Cloud Logging, Cloud Monitoring, Managed Service for Prometheus Logs are collected by default; control their volume
EKS version support, manual upgrades Release channels with automatic upgrades Upgrades happen to you unless you set windows and exclusions
EKS Anywhere / hybrid nodes Google Distributed Cloud, attached clusters, fleets Fleets manage clusters wherever they run

Recap

  • The hierarchy is organization → folders → projects; a project is the unit for resources, IAM, quotas and billing.
  • A VPC is global, subnets are regional, and Pods use secondary ranges of a subnet.
  • Autopilot or Standard, regional or zonal, and a release channel shape every cluster.
  • Workload Identity Federation gives pods their own Google Cloud identity.
  • If you know EKS, most concepts map one-to-one; the differences are global VPCs, IP ranges, automatic upgrades and Autopilot.

This site is a public version of my personal engineering knowledge hub. It intentionally excludes confidential company information and internal operational details.