Lesson 01 of 18 · Part 1 — Foundations
Google Cloud & GKE services and terms
The vocabulary every later lesson assumes: the Google Cloud services a GKE platform is built from, the GKE-specific terms you'll hear in design reviews, and a map from every EKS and AWS term to its GKE equivalent.
How to use this page
Keep it open while you work through the track. Every later lesson uses these words without explaining them again. If you know AWS and EKS, start with the map at the bottom: most GKE ideas have a direct equivalent, and the few that don't are where the surprises are.
Moving from AWS to Google Cloud is like moving to a new city that has the same kinds of shops with different names. The bakery is still a bakery, but it's on a different street and has its own opening hours. Learn the street names once, and everything you already know about bread still applies.
Google Cloud services a GKE platform uses
Organisation, identity and security
| Service / term | What it is | What GKE uses it for |
|---|---|---|
| Organization | The root node for a company's resources, tied to its Google Workspace or Cloud Identity domain | Org-wide policies and IAM; the top of the resource hierarchy |
| Folder | A group of projects (and other folders) | Grouping by environment or business unit; policies inherited downwards |
| Project | The container for resources, APIs, IAM, quotas and billing | One or more projects per environment; clusters live in a project |
| Billing account | Pays for one or more projects | Cost reporting per project and label |
| IAM (roles, principals, allow policies) | Who may do what on which resource | Admin, developer and CI access to GKE; pod access to Google APIs |
| Service account (Google) | A non-human identity for workloads and automation | Node identity, CI identity, workload identity targets |
| Cloud Identity / Google Groups | Users and groups | Grant IAM and Kubernetes RBAC to groups, not people |
| Organization Policy Service | Constraints on what may be created (allowed regions, no external IPs, required settings) | Org-wide guard-rails |
| Cloud KMS | Managed encryption keys | Application-layer encryption of Kubernetes Secrets; customer-managed keys (CMEK) for disks |
| Secret Manager | Stores secrets | App secrets, mounted into pods or synced (Secret Manager add-on, External Secrets) |
| Cloud Audit Logs | Who called which API, when | Who changed the cluster, IAM or network |
| Security Command Center | Security findings across the organisation | Misconfigurations and threats, including GKE findings |
Networking
| Service / term | What it is | What GKE uses it for |
|---|---|---|
| Region, zone | A geographic area and its isolated locations (usually 3+ zones) | Regional clusters spread over zones; zonal clusters live in one |
| VPC network | A global private network | Nodes and Pods get IPs from its subnets |
| Subnet | A regional IP range inside the VPC, with optional secondary ranges | Primary range: nodes. Secondary ranges: Pods and Services (lesson 04) |
| Shared VPC | One host project owns the VPC; service projects use its subnets | Central network team, clusters in team or environment projects (lesson 03) |
| Firewall rules / policies | Stateful allow and deny rules on VPC traffic | GKE creates the rules it needs; you add your own and org-level policies |
| Cloud Router, Cloud NAT | Dynamic routing; outbound internet for private VMs | Egress for private nodes (image pulls from outside Google, external APIs) |
| Private Google Access | Reach Google APIs from VMs without external IPs | Private nodes pulling from Artifact Registry, writing logs |
| Private Service Connect | Private endpoints to Google or partner services | Private access to APIs; also used by GKE's control plane connection |
| Cloud Load Balancing | Global and regional, external and internal, L4 and L7 load balancers | Services, Ingress and Gateway (lesson 07) |
| Cloud Armor | WAF and DDoS protection on external Application Load Balancers | Protecting public apps |
| Cloud DNS | Managed DNS | App hostnames; optionally in-cluster DNS (Cloud DNS for GKE) |
| Cloud Interconnect, Cloud VPN | Private links to on-prem or other clouds | Hybrid connectivity |
Compute, containers and storage
| Service / term | What it is | What GKE uses it for |
|---|---|---|
| Compute Engine, machine type | Virtual machines and their sizes (e2, n2, n4, c3, t2d…) | Nodes in Standard clusters |
| Container-Optimized OS (COS) | Google's minimal, hardened node OS | The default node image (Ubuntu is the alternative) |
| Spot VMs | Spare capacity at a large discount, reclaimable with short notice | Cheap, interruption-tolerant node pools |
| Artifact Registry | Private registry for images and packages | Your images; scanning, cleanup policies, remote (cache) repositories |
| Persistent Disk, Hyperdisk | Block storage for VMs | ReadWriteOnce volumes through the CSI driver |
| Filestore | Managed NFS | ReadWriteMany volumes |
| Cloud Storage | Object storage | App data, backups; mountable through the Cloud Storage FUSE CSI driver |
Observability and cost
| Service / term | What it is | What GKE uses it for |
|---|---|---|
| Cloud Logging | Log collection, storage, routing (sinks) | Node, system and container logs, collected by default |
| Cloud Monitoring | Metrics, dashboards, alerting | System metrics by default; your metrics via Managed Service for Prometheus |
| Managed Service for Prometheus | Prometheus-compatible collection and storage, queried with PromQL | Workload and kube-state metrics without running Prometheus storage |
| Cloud Trace | Distributed tracing | OpenTelemetry traces from apps |
| Recommender / Active Assist | Usage-based recommendations | Rightsizing, idle clusters, deprecated API usage before upgrades |
GKE terms
| Term | Meaning |
|---|---|
| Autopilot | Mode where Google manages nodes, scaling and security defaults; you pay for the resources your Pods request |
| Standard | Mode where you manage node pools (machine types, scaling, upgrades); you pay for the VMs |
| Regional / zonal cluster | Control plane replicated across a region's zones, or in one zone (lesson 02) |
| Node pool | Nodes with the same configuration in one cluster |
| Release channel | Rapid, Regular, Stable or Extended: how quickly the cluster receives new versions (lesson 13) |
| Maintenance window / exclusion | When automatic upgrades may run, and periods when they may not |
| VPC-native cluster | Pods and Services use alias IP ranges from the subnet (the default) |
| Dataplane V2 | GKE's eBPF data plane, based on Cilium, with built-in network policy enforcement |
| Workload Identity Federation for GKE | Kubernetes ServiceAccounts act as IAM principals |
| GKE metadata server | Answers pods' credential requests and hides the node's identity |
| Compute class | A named set of node preferences (machine families, Spot, fallbacks) workloads can ask for |
| Node auto-provisioning (NAP) | GKE creates and deletes node pools to fit pending Pods |
| NEG | Network endpoint group: lets load balancers send traffic straight to Pod IPs |
| Fleet | A group of clusters (GKE, on-prem, other clouds) managed together (lesson 14) |
| Config Sync, Policy Controller | Google's GitOps sync and policy (Gatekeeper-based) features for fleets |
| Backup for GKE | Managed backup and restore of cluster resources and volumes |
Coming from AWS and EKS
| AWS / EKS | Google Cloud / GKE | Watch out for |
|---|---|---|
| Account, Organizations OU, SCP | Project, folder, organization policy | Policies are constraints, not permission ceilings like SCPs |
| IAM role (assumed) | Google service account, or a principal from Workload Identity Federation | Humans use their own Google identity; no role-switching between accounts |
| VPC (regional), subnet per AZ | VPC (global), subnet per region | One subnet covers every zone of its region |
| VPC CNI (pods on ENIs) | VPC-native alias IP ranges | Pods use a secondary range, not the node subnet; size it up front |
| Security groups | VPC firewall rules and policies, Kubernetes network policy | Firewall rules target network tags or service accounts, not ENIs |
| NAT gateway, VPC endpoints | Cloud NAT, Private Google Access, Private Service Connect | Private Google Access is a subnet setting, not one endpoint per service |
| EKS control plane | GKE control plane (regional or zonal) | Zonal control planes have no zone redundancy |
| Managed node groups / Karpenter | Node pools + cluster autoscaler / node auto-provisioning, compute classes | Autopilot removes node management entirely |
| Fargate | Autopilot | Autopilot is a whole cluster mode, not a per-pod profile |
| Access entries / aws-auth | IAM roles for GKE + Kubernetes RBAC | IAM grants are project-wide; namespace scope comes from RBAC |
| IRSA / EKS Pod Identity | Workload Identity Federation for GKE | Grant IAM roles directly to the Kubernetes ServiceAccount principal |
| AWS Load Balancer Controller (ALB/NLB) | Built-in: Services, Ingress, GKE Gateway controller | No controller to install; container-native load balancing with NEGs |
| ECR | Artifact Registry | Path is REGION-docker.pkg.dev/PROJECT/REPO/IMAGE |
| EBS / EFS CSI | Persistent Disk / Hyperdisk CSI, Filestore CSI | Drivers are managed by GKE, not installed by you |
| CloudWatch, Container Insights | Cloud Logging, Cloud Monitoring, Managed Service for Prometheus | Logs are collected by default; control their volume |
| EKS version support, manual upgrades | Release channels with automatic upgrades | Upgrades happen to you unless you set windows and exclusions |
| EKS Anywhere / hybrid nodes | Google Distributed Cloud, attached clusters, fleets | Fleets manage clusters wherever they run |
Recap
- The hierarchy is organization → folders → projects; a project is the unit for resources, IAM, quotas and billing.
- A VPC is global, subnets are regional, and Pods use secondary ranges of a subnet.
- Autopilot or Standard, regional or zonal, and a release channel shape every cluster.
- Workload Identity Federation gives pods their own Google Cloud identity.
- If you know EKS, most concepts map one-to-one; the differences are global VPCs, IP ranges, automatic upgrades and Autopilot.
This site is a public version of my personal engineering knowledge hub. It intentionally excludes confidential company information and internal operational details.