GCP¶
Summary
Google Cloud Platform (GCP) is Google's public cloud. This topic covers how to lay out a GCP estate: from a single project with one VPC, through Shared VPC, peering, Network Connectivity Center and Private Service Connect, to multi-region DR and a full enterprise landing zone. A landing zone combines the resource hierarchy (organization, folders, projects), organization policies, IAM, Cloud NGFW firewall policies, and VPC Service Controls. Google's reference implementations are Cloud Foundation Fabric FAST, the enterprise foundations blueprint (terraform-example-foundation), and the console-guided Google Cloud Setup.
Key Facts¶
| Fact | Value |
|---|---|
| Vendor | Google LLC (Google Cloud) |
| Type | Public cloud (IaaS, PaaS, managed Kubernetes, data and AI services) |
| Footprint | 43 regions, 130 zones (2026-09, locations) |
| Resource hierarchy | Organization > Folders (up to 10 levels) > Projects > resources |
| Policy guardrails | Organization Policy Service (legacy and managed constraints), IAM allow/deny policies |
| Secure-by-default | Security baseline constraints enforced on organizations created on or after 2024-05-03 |
| Firewall | Cloud NGFW: Essentials (free), Standard, Enterprise tiers; hierarchical and network firewall policies |
| Latest Version (landing-zone tooling) | Fabric FAST v58.0.0 (2026-09-01); terraform-example-foundation v6.0.0 (2026-09-08); Terraform hashicorp/google provider 8.3.0 (2026-09-15) |
| Docs home | docs.cloud.google.com (moved from cloud.google.com/.../docs in 2025) |
| Licensing | Proprietary service, pay-as-you-go plus committed use discounts. Fabric, CFT modules, and the Terraform provider are Apache 2.0 / MPL 2.0 open source |
Architecture Patterns at a Glance¶
| Pattern | Scope | Complexity | Typical Use Case |
|---|---|---|---|
| Single Project + Single VPC | One project, one VPC | Low | Small teams, prototypes, single-application workloads |
| Multi-VPC (Shared VPC) | Host project + service projects | Medium | Enterprise with centralized networking, multi-team isolation |
| Multi-VPC (VPC Peering) | Peer-to-peer VPC connections | Medium | SaaS offerings, inter-organization connectivity |
| Network Connectivity Center (VPC spokes) | Hub with mesh or star topology | Medium | Many VPCs that need transitive connectivity |
| Private Service Connect | Service-oriented private access | Medium | Consuming/producing managed services privately across VPC boundaries |
| Multi-Project + Folders | Organization hierarchy | High | Large enterprises with regulated environments |
| Multi-Zone / Multi-Region | Cross-zone and cross-region deployments | High | Production workloads requiring HA and DR |
| DR: Pilot Light | Minimal standby in secondary region | Medium | Cost-optimized DR, tolerates hours of downtime |
| DR: Warm Standby | Scaled-down full replica | Medium-High | Most enterprises. Minutes-level RTO/RPO |
| DR: Active-Active | Full duplicate in multiple regions | Very High | Mission-critical apps requiring zero downtime |
| DMZ-Less (Google Recommended) | Private subnets + managed edge | Medium | Modern GCP deployments. No traditional DMZ needed |
| GCP Landing Zone | Org-wide foundation | Very High | Greenfield enterprise adoption of GCP |
The compact diagram shows how the landing-zone layers stack. The full component diagram is in the Explanation.
graph TD
Org["Organization node<br/>org policies, hierarchical firewall policy"] --> Folders["Folders<br/>Production, Non-Production, Shared"]
Folders --> Host["Shared VPC host project<br/>VPC, Cloud NAT, Interconnect"]
Folders --> Svc["Service projects<br/>GKE, Cloud Run, Cloud SQL"]
Svc -->|"networkUser on subnets"| Host
Folders --> Sec["Security and logging projects<br/>SCC, KMS, org log sink"]
VPCSC["VPC Service Controls perimeter"] -.-> Svc
Key GCP Services¶
Networking¶
- VPC -- global virtual network with regional subnets
- Shared VPC -- centralized networking across projects via host/service model
- VPC Network Peering -- non-transitive internal connectivity between two VPCs
- Network Connectivity Center -- hub-and-spoke with VPC spokes (mesh or star) and hybrid spokes
- Private Service Connect -- service-oriented private access to managed services and Google APIs
- Cloud NAT -- managed outbound NAT for private resources
- Cloud Interconnect / Cloud VPN / Cross-Cloud Interconnect -- hybrid and multicloud connectivity
- Cloud Load Balancing -- Application (L7) and Network (L4, proxy or passthrough) load balancers, global or regional
- Cloud DNS -- managed DNS with health-check-based routing policies
- Cloud NGFW -- hierarchical, global, and regional firewall policies; secure tags; IDPS in the Enterprise tier
- VPC Service Controls -- perimeter-based data-exfiltration protection for Google APIs
- Cloud Armor -- DDoS protection and WAF for external load balancers
Compute and Orchestration¶
- Compute Engine -- VMs (zonal). Regional MIGs for cross-zone HA
- GKE -- managed Kubernetes. Since 2025-09 a single offering: fleets, Config Sync, and Policy Controller are included; service mesh, Backup for GKE, and multi-cluster Gateway are add-on SKUs
- Cloud Run -- serverless containers and Cloud Run functions (formerly Cloud Functions)
Data¶
- Cloud SQL -- managed MySQL, PostgreSQL, SQL Server. Enterprise and Enterprise Plus editions, HA and cross-region replicas
- Spanner -- globally distributed relational DB. Multi-region (99.999% SLA) needs Enterprise Plus edition
- AlloyDB -- PostgreSQL-compatible with cross-region secondary clusters
- Bigtable -- wide-column NoSQL with multi-cluster replication
- Cloud Storage -- regional, dual-region (optional turbo replication), and multi-region buckets
- Firestore -- document DB with regional and multi-region locations
Management and Governance¶
- Resource Manager -- organization, folder, project hierarchy and tags
- Organization Policy Service -- org-level constraints (location, OS Login, external IPs, SA keys, and others)
- IAM -- allow, deny, and principal access boundary policies; Privileged Access Manager for just-in-time access
- Security Command Center -- posture and threat detection (Standard free, Premium paid; Enterprise tier deprecated, shuts down 2027-05-21)
- Cloud Build / Cloud Deploy -- CI/CD for infrastructure and applications
- Terraform: Cloud Foundation Fabric / Cloud Foundation Toolkit -- IaC for landing-zone automation
Evaluation¶
Strengths¶
- Global VPC: one network spans all regions, so multi-region designs need no inter-region peering or transit gateways
- Folder-based policy inheritance (org policies, IAM, hierarchical firewall policies) gives central guardrails without per-project work
- Shared VPC separates network ownership from workload ownership cleanly
- VPC Service Controls add an API-level data perimeter that most other clouds lack as a first-party feature
- Secure-by-default constraints on new organizations reduce common mistakes (for example SA key sprawl)
Weaknesses and Caveats¶
- VPC Peering is non-transitive and has per-network limits. Large estates need NCC or Shared VPC planning early
- VPC Service Controls are powerful but easy to misconfigure. Always roll out in dry-run mode
- Product renames and doc moves (Cloud Functions to Cloud Run functions, GKE editions, SCC tiers) make older guides stale quickly
- Landing-zone blueprints (Fabric FAST especially) ship frequent major versions with breaking changes
When It Fits¶
- Organizations that want strong central governance with delegated project ownership
- Data-heavy estates (BigQuery, Spanner) that benefit from VPC SC perimeters
- Kubernetes-centric platforms using GKE fleets
Real-World Examples¶
| Scenario | Pattern(s) Used |
|---|---|
| Startup running a monolithic web app | Single Project + Single VPC |
| Mid-size SaaS company with 10+ microservices teams | Shared VPC with service projects per team |
| Large bank migrating to GCP with regulatory requirements | Full landing zone: folders, Shared VPC, VPC Service Controls, SCC Premium |
| E-commerce platform needing 99.99% uptime | Multi-zone deployment with global Application LB, Cloud SQL HA, warm standby DR |
| Global payments processor | Active-active multi-region with Spanner, global LB, GKE fleet |
| Manufacturing company with on-premises data center | Hub-and-spoke Shared VPC + Cloud Interconnect + pilot light DR |
Topic Map¶
- How-to Guides -- project factory, org policies (v2 Terraform), Shared VPC, PSC, firewall policies, VPC SC, Cloud Armor, IAP, DR runbooks, troubleshooting
- Reference -- product renames, hierarchy limits, baseline constraints, IP ranges, IAM roles, NGFW tiers and pricing, blueprint versions, security checklist
- Explanation -- connectivity decision flow, org policy evaluation, firewall evaluation order, VPC SC request flow, DR patterns, threat model
Related Topics¶
- AWS -- the equivalent AWS landing-zone patterns (Control Tower, SCPs, Transit Gateway)
- Multi-Cloud Governance -- identity federation, networking, and policy across clouds
- Kubernetes -- platform concepts behind GKE
- Terraform -- the IaC tool used by Fabric FAST and the CFT blueprints
- OpenTofu -- open-source Terraform fork, also usable with the Google provider
- Public Cloud Landing Zones -- AWS vs Google Cloud vs Alibaba Cloud vs Tencent Cloud landing zones, hierarchy, network hubs and guardrails
- Infrastructure comparisons -- all domain comparison pages
Sources¶
- Landing zone design in Google Cloud
- Enterprise foundations blueprint and terraform-example-foundation
- Cloud Foundation Fabric FAST and changelog
- Cloud Foundation Toolkit
- About resource hierarchy
- Organization Policy overview and security baseline constraints
- Shared VPC overview
- VPC Network Peering
- NCC VPC spokes overview
- Private Service Connect
- Cloud NGFW overview and pricing
- VPC Service Controls overview
- GKE pricing (single offering since 2025-09)
- Security Command Center service tiers
- Architecting disaster recovery for cloud infrastructure outages
- Google Cloud Well-Architected Framework
- Global locations
- Announcing docs.cloud.google.com
- Landing Zone Accelerator for Canadian PBMM (GitHub)
Questions¶
- What is the cost differential between pilot light, warm standby, and active-active DR for a typical 3-tier web application? Open: needs a priced worked example with the pricing calculator.
- Will Google consolidate Fabric FAST and the enterprise foundations blueprint into one recommended landing zone? Open: both had major releases in 2026 (FAST v58, example foundation v6).
- How far will managed constraints (
compute.managed.*,iam.managed.*) replace legacy constraints, and when will legacy ones be deprecated? Open: no deprecation date published as of 2026-09.
Answered since the last review: Shared VPC vs VPC Peering (see the connectivity decision flow); the baseline org-policy set (see Baseline Organization Policy Constraints); PSC vs peering for SaaS consumption (PSC avoids CIDR coordination and peering limits, see Private Service Connect).