Skip to content

GCP

Summary

Google Cloud Platform (GCP) is Google's public cloud. This topic covers how to lay out a GCP estate: from a single project with one VPC, through Shared VPC, peering, Network Connectivity Center and Private Service Connect, to multi-region DR and a full enterprise landing zone. A landing zone combines the resource hierarchy (organization, folders, projects), organization policies, IAM, Cloud NGFW firewall policies, and VPC Service Controls. Google's reference implementations are Cloud Foundation Fabric FAST, the enterprise foundations blueprint (terraform-example-foundation), and the console-guided Google Cloud Setup.

Key Facts

Fact Value
Vendor Google LLC (Google Cloud)
Type Public cloud (IaaS, PaaS, managed Kubernetes, data and AI services)
Footprint 43 regions, 130 zones (2026-09, locations)
Resource hierarchy Organization > Folders (up to 10 levels) > Projects > resources
Policy guardrails Organization Policy Service (legacy and managed constraints), IAM allow/deny policies
Secure-by-default Security baseline constraints enforced on organizations created on or after 2024-05-03
Firewall Cloud NGFW: Essentials (free), Standard, Enterprise tiers; hierarchical and network firewall policies
Latest Version (landing-zone tooling) Fabric FAST v58.0.0 (2026-09-01); terraform-example-foundation v6.0.0 (2026-09-08); Terraform hashicorp/google provider 8.3.0 (2026-09-15)
Docs home docs.cloud.google.com (moved from cloud.google.com/.../docs in 2025)
Licensing Proprietary service, pay-as-you-go plus committed use discounts. Fabric, CFT modules, and the Terraform provider are Apache 2.0 / MPL 2.0 open source

Architecture Patterns at a Glance

Pattern Scope Complexity Typical Use Case
Single Project + Single VPC One project, one VPC Low Small teams, prototypes, single-application workloads
Multi-VPC (Shared VPC) Host project + service projects Medium Enterprise with centralized networking, multi-team isolation
Multi-VPC (VPC Peering) Peer-to-peer VPC connections Medium SaaS offerings, inter-organization connectivity
Network Connectivity Center (VPC spokes) Hub with mesh or star topology Medium Many VPCs that need transitive connectivity
Private Service Connect Service-oriented private access Medium Consuming/producing managed services privately across VPC boundaries
Multi-Project + Folders Organization hierarchy High Large enterprises with regulated environments
Multi-Zone / Multi-Region Cross-zone and cross-region deployments High Production workloads requiring HA and DR
DR: Pilot Light Minimal standby in secondary region Medium Cost-optimized DR, tolerates hours of downtime
DR: Warm Standby Scaled-down full replica Medium-High Most enterprises. Minutes-level RTO/RPO
DR: Active-Active Full duplicate in multiple regions Very High Mission-critical apps requiring zero downtime
DMZ-Less (Google Recommended) Private subnets + managed edge Medium Modern GCP deployments. No traditional DMZ needed
GCP Landing Zone Org-wide foundation Very High Greenfield enterprise adoption of GCP

The compact diagram shows how the landing-zone layers stack. The full component diagram is in the Explanation.

graph TD
    Org["Organization node<br/>org policies, hierarchical firewall policy"] --> Folders["Folders<br/>Production, Non-Production, Shared"]
    Folders --> Host["Shared VPC host project<br/>VPC, Cloud NAT, Interconnect"]
    Folders --> Svc["Service projects<br/>GKE, Cloud Run, Cloud SQL"]
    Svc -->|"networkUser on subnets"| Host
    Folders --> Sec["Security and logging projects<br/>SCC, KMS, org log sink"]
    VPCSC["VPC Service Controls perimeter"] -.-> Svc

Key GCP Services

Networking

  • VPC -- global virtual network with regional subnets
  • Shared VPC -- centralized networking across projects via host/service model
  • VPC Network Peering -- non-transitive internal connectivity between two VPCs
  • Network Connectivity Center -- hub-and-spoke with VPC spokes (mesh or star) and hybrid spokes
  • Private Service Connect -- service-oriented private access to managed services and Google APIs
  • Cloud NAT -- managed outbound NAT for private resources
  • Cloud Interconnect / Cloud VPN / Cross-Cloud Interconnect -- hybrid and multicloud connectivity
  • Cloud Load Balancing -- Application (L7) and Network (L4, proxy or passthrough) load balancers, global or regional
  • Cloud DNS -- managed DNS with health-check-based routing policies
  • Cloud NGFW -- hierarchical, global, and regional firewall policies; secure tags; IDPS in the Enterprise tier
  • VPC Service Controls -- perimeter-based data-exfiltration protection for Google APIs
  • Cloud Armor -- DDoS protection and WAF for external load balancers

Compute and Orchestration

  • Compute Engine -- VMs (zonal). Regional MIGs for cross-zone HA
  • GKE -- managed Kubernetes. Since 2025-09 a single offering: fleets, Config Sync, and Policy Controller are included; service mesh, Backup for GKE, and multi-cluster Gateway are add-on SKUs
  • Cloud Run -- serverless containers and Cloud Run functions (formerly Cloud Functions)

Data

  • Cloud SQL -- managed MySQL, PostgreSQL, SQL Server. Enterprise and Enterprise Plus editions, HA and cross-region replicas
  • Spanner -- globally distributed relational DB. Multi-region (99.999% SLA) needs Enterprise Plus edition
  • AlloyDB -- PostgreSQL-compatible with cross-region secondary clusters
  • Bigtable -- wide-column NoSQL with multi-cluster replication
  • Cloud Storage -- regional, dual-region (optional turbo replication), and multi-region buckets
  • Firestore -- document DB with regional and multi-region locations

Management and Governance

  • Resource Manager -- organization, folder, project hierarchy and tags
  • Organization Policy Service -- org-level constraints (location, OS Login, external IPs, SA keys, and others)
  • IAM -- allow, deny, and principal access boundary policies; Privileged Access Manager for just-in-time access
  • Security Command Center -- posture and threat detection (Standard free, Premium paid; Enterprise tier deprecated, shuts down 2027-05-21)
  • Cloud Build / Cloud Deploy -- CI/CD for infrastructure and applications
  • Terraform: Cloud Foundation Fabric / Cloud Foundation Toolkit -- IaC for landing-zone automation

Evaluation

Strengths

  • Global VPC: one network spans all regions, so multi-region designs need no inter-region peering or transit gateways
  • Folder-based policy inheritance (org policies, IAM, hierarchical firewall policies) gives central guardrails without per-project work
  • Shared VPC separates network ownership from workload ownership cleanly
  • VPC Service Controls add an API-level data perimeter that most other clouds lack as a first-party feature
  • Secure-by-default constraints on new organizations reduce common mistakes (for example SA key sprawl)

Weaknesses and Caveats

  • VPC Peering is non-transitive and has per-network limits. Large estates need NCC or Shared VPC planning early
  • VPC Service Controls are powerful but easy to misconfigure. Always roll out in dry-run mode
  • Product renames and doc moves (Cloud Functions to Cloud Run functions, GKE editions, SCC tiers) make older guides stale quickly
  • Landing-zone blueprints (Fabric FAST especially) ship frequent major versions with breaking changes

When It Fits

  • Organizations that want strong central governance with delegated project ownership
  • Data-heavy estates (BigQuery, Spanner) that benefit from VPC SC perimeters
  • Kubernetes-centric platforms using GKE fleets

Real-World Examples

Scenario Pattern(s) Used
Startup running a monolithic web app Single Project + Single VPC
Mid-size SaaS company with 10+ microservices teams Shared VPC with service projects per team
Large bank migrating to GCP with regulatory requirements Full landing zone: folders, Shared VPC, VPC Service Controls, SCC Premium
E-commerce platform needing 99.99% uptime Multi-zone deployment with global Application LB, Cloud SQL HA, warm standby DR
Global payments processor Active-active multi-region with Spanner, global LB, GKE fleet
Manufacturing company with on-premises data center Hub-and-spoke Shared VPC + Cloud Interconnect + pilot light DR

Topic Map

  • How-to Guides -- project factory, org policies (v2 Terraform), Shared VPC, PSC, firewall policies, VPC SC, Cloud Armor, IAP, DR runbooks, troubleshooting
  • Reference -- product renames, hierarchy limits, baseline constraints, IP ranges, IAM roles, NGFW tiers and pricing, blueprint versions, security checklist
  • Explanation -- connectivity decision flow, org policy evaluation, firewall evaluation order, VPC SC request flow, DR patterns, threat model
  • AWS -- the equivalent AWS landing-zone patterns (Control Tower, SCPs, Transit Gateway)
  • Multi-Cloud Governance -- identity federation, networking, and policy across clouds
  • Kubernetes -- platform concepts behind GKE
  • Terraform -- the IaC tool used by Fabric FAST and the CFT blueprints
  • OpenTofu -- open-source Terraform fork, also usable with the Google provider
  • Public Cloud Landing Zones -- AWS vs Google Cloud vs Alibaba Cloud vs Tencent Cloud landing zones, hierarchy, network hubs and guardrails
  • Infrastructure comparisons -- all domain comparison pages

Sources

Questions

  • What is the cost differential between pilot light, warm standby, and active-active DR for a typical 3-tier web application? Open: needs a priced worked example with the pricing calculator.
  • Will Google consolidate Fabric FAST and the enterprise foundations blueprint into one recommended landing zone? Open: both had major releases in 2026 (FAST v58, example foundation v6).
  • How far will managed constraints (compute.managed.*, iam.managed.*) replace legacy constraints, and when will legacy ones be deprecated? Open: no deprecation date published as of 2026-09.

Answered since the last review: Shared VPC vs VPC Peering (see the connectivity decision flow); the baseline org-policy set (see Baseline Organization Policy Constraints); PSC vs peering for SaaS consumption (PSC avoids CIDR coordination and peering limits, see Private Service Connect).