Production GKE Platform — From Zero to Production›Part 2 · Cheat sheet & self-check

Part 2 — Build the platform · wrap-up

Cheat sheet & self-check

24 questions across 8 lessons. Each answer links back to the lesson it came from.

Pick an answer to see if you got it, and why.

  1. Q1. Why do many organisations put GKE clusters in service projects attached to a Shared VPC?

    Show answer

    B. Shared VPC separates network administration (host project) from workload administration (service projects), with one consistent IP plan and hybrid connectivity.

    From lesson 03 · Organisation, projects & Shared VPC
  2. Q2. Private nodes have no external IPs. How do they reach Artifact Registry and Cloud Logging?

    Show answer

    B. Private Google Access lets VMs without external IPs reach Google APIs; Cloud NAT gives outbound internet access for everything else.

    From lesson 03 · Organisation, projects & Shared VPC
  3. Q3. What must the GKE service agent of the service project be granted in the host project?

    Show answer

    B. GKE in the service project manages firewall rules and uses subnets in the host project, so its service agent needs those roles there.

    From lesson 03 · Organisation, projects & Shared VPC
  4. Q4. A Standard cluster uses the default 110 max Pods per node and a /20 Pod range. How many nodes fit?

    Show answer

    B. At 110 Pods per node each node gets a /24 (256 addresses). A /20 holds 16 /24 blocks, so only 16 nodes fit, however few Pods they run.

    From lesson 04 · VPC-native networking & IP planning
  5. Q5. The Pod range is exhausted. What is the least disruptive fix?

    Show answer

    B. Additional Pod ranges can be attached to new node pools without rebuilding the cluster. The original ranges can't be resized in place.

    From lesson 04 · VPC-native networking & IP planning
  6. Q6. What does Dataplane V2 give you?

    Show answer

    B. Dataplane V2 replaces kube-proxy and iptables with eBPF and enforces network policies without installing Calico.

    From lesson 04 · VPC-native networking & IP planning
  7. Q7. What does 'private nodes' mean in GKE?

    Show answer

    B. Private nodes have no external IP addresses, which removes a large attack surface. Control-plane access is a separate decision.

    From lesson 05 · The cluster: control plane access, node pools & compute
  8. Q8. Why replace the default Compute Engine service account on nodes?

    Show answer

    B. Use a dedicated minimal node service account (logging, monitoring, reading images) and give workloads their own identities with Workload Identity.

    From lesson 05 · The cluster: control plane access, node pools & compute
  9. Q9. How do you keep ordinary workloads off a Spot node pool?

    Show answer

    B. Taints repel Pods without the toleration; node selectors or affinity attract the right Pods. GKE also labels Spot nodes with cloud.google.com/gke-spot=true.

    From lesson 05 · The cluster: control plane access, node pools & compute
  10. Q10. A developer has roles/container.developer on the project. What can they do?

    Show answer

    B. IAM roles for GKE apply project-wide to all clusters and namespaces. For namespace scope, give a lighter IAM role (cluster viewer) and grant RBAC per namespace.

    From lesson 06 · Identity & access: IAM, RBAC and Workload Identity Federation
  11. Q11. How does a pod get Google Cloud permissions with Workload Identity Federation for GKE?

    Show answer

    B. Tokens are short-lived and scoped to the ServiceAccount; there are no key files to leak or rotate.

    From lesson 06 · Identity & access: IAM, RBAC and Workload Identity Federation
  12. Q12. Why use Google Groups for RBAC?

    Show answer

    B. Groups must be members of a designated security group (gke-security-groups@yourdomain) for GKE to see them in RBAC.

    From lesson 06 · Identity & access: IAM, RBAC and Workload Identity Federation
  13. Q13. What does a Service of type LoadBalancer create on GKE by default?

    Show answer

    B. Service LoadBalancer gives an L4 passthrough load balancer (external by default, internal with the internal annotation). HTTP routing needs Ingress or Gateway.

    From lesson 07 · Load balancing: Services, Ingress & Gateway API
  14. Q14. What is container-native load balancing?

    Show answer

    B. With NEGs, health checks and traffic go to Pods directly: better distribution, fewer hops, and readiness that the load balancer understands.

    From lesson 07 · Load balancing: Services, Ingress & Gateway API
  15. Q15. Why choose the Gateway API over Ingress for a new platform?

    Show answer

    B. Ingress still works, but the Gateway API models shared gateways, cross-namespace routing and traffic splitting in a portable standard.

    From lesson 07 · Load balancing: Services, Ingress & Gateway API
  16. Q16. What does an Artifact Registry remote repository do?

    Show answer

    B. Remote repositories cache upstream images: fewer public-registry rate limits, private nodes need no internet, and you control what's pulled.

    From lesson 08 · Artifact Registry & application delivery
  17. Q17. How should a GitHub Actions workflow authenticate to push images?

    Show answer

    B. No long-lived key to leak or rotate; the pool provider can restrict which repository and branch may get credentials.

    From lesson 08 · Artifact Registry & application delivery
  18. Q18. What does image streaming change?

    Show answer

    B. Image streaming reads image data lazily from Artifact Registry, which shortens start-up for large images, especially when scaling.

    From lesson 08 · Artifact Registry & application delivery
  19. Q19. A zonal Persistent Disk is in europe-west1-b, and that zone fails. What happens to the Pod using it?

    Show answer

    B. Zonal disks are tied to one zone. Regional Persistent Disks (replicated across two zones) or app-level replication let the Pod restart in another zone.

    From lesson 09 · Storage: Persistent Disk, Hyperdisk, Filestore & Cloud Storage
  20. Q20. Why do GKE's default StorageClasses use volumeBindingMode WaitForFirstConsumer?

    Show answer

    B. Binding waits until the scheduler picks a node, so the disk lands in that node's zone.

    From lesson 09 · Storage: Persistent Disk, Hyperdisk, Filestore & Cloud Storage
  21. Q21. Which storage gives ReadWriteMany to Pods on many nodes?

    Show answer

    B. Persistent Disk is ReadWriteOnce (one node writes). Filestore is managed NFS and supports ReadWriteMany.

    From lesson 09 · Storage: Persistent Disk, Hyperdisk, Filestore & Cloud Storage
  22. Q22. What triggers the cluster autoscaler to add a node?

    Show answer

    B. The autoscaler works on requests and pending Pods, not on live usage. Wrong requests mean wrong scaling.

    From lesson 10 · Autoscaling: Pods, nodes and compute classes
  23. Q23. What does node auto-provisioning add on top of the cluster autoscaler?

    Show answer

    B. The cluster autoscaler only resizes existing pools. Auto-provisioning (and compute classes) also chooses machine shapes.

    From lesson 10 · Autoscaling: Pods, nodes and compute classes
  24. Q24. Why should you be careful running the HPA and the VPA on the same metric?

    Show answer

    B. Use the HPA on CPU (or custom metrics) and the VPA for memory or in recommendation mode, or GKE's multidimensional Pod autoscaling which combines them deliberately.

    From lesson 10 · Autoscaling: Pods, nodes and compute classes