GCP Services Every DevOps Engineer Should Know: A Guide

Google Cloud Platform runs more than 150 services across compute, storage, networking, machine learning, and developer tools. For a developer or DevOps engineer getting started with GCP, that number is overwhelming – and honestly, you do not need to know all of them.

This guide organizes the GCP services that matter most into six functional categories. Think of it as a route map: pick the services relevant to your workload and ignore the rest.

How GCP services fit together

Google Cloud services fall into layers that build on each other. At the bottom you have compute – virtual machines, containers, and serverless runtimes that actually run your code. Above that sits storage and databases for persisting data. Networking connects everything, security and IAM control who can access what, DevOps tooling automates the build-deploy cycle, and observability tells you what is happening in production.

If you are new to GCP, start with Compute Engine and Cloud Storage – those are the fundamental building blocks. Add IAM early so you do not accidentally grant broad permissions. From there, expand into managed services as your needs grow.

Compute: where your code runs

Compute services are the execution layer. GCP gives you three tiers depending on how much control you want versus how much you want Google to manage.

Compute Engine is GCP’s IaaS workhorse. You create virtual machines with custom CPU, RAM, and disk configurations, choose from predefined machine types or build custom shapes, and attach persistent disks or local SSDs. Use Compute Engine when you need full OS-level control, are migrating on-prem VMs, or run workloads that do not fit neatly into containers.

Google Kubernetes Engine (GKE) is a fully managed Kubernetes service. It handles control plane upgrades, node auto-repair, and cluster scaling. GKE Autopilot goes further – Google manages the nodes entirely and you pay per pod resource request, not per node. Use GKE when you already run Kubernetes, need multi-cloud portability, or manage microservices at scale.

Cloud Run is serverless containers. You give it a container image, and Cloud Run handles scaling (including scale-to-zero), load balancing, and HTTPS endpoints. It abstracts away infrastructure completely. Use Cloud Run for APIs, web apps, and event-driven workloads where you want zero infrastructure management and pay only for request processing time.

gcloud run deploy my-service –image gcr.io/my-project/my-image –region us-central1Code language: Bash (bash)

Cloud Functions (2nd gen) runs event-driven functions without containers. It is the lightest option – write a function in Node.js, Python, Go, Java, Ruby, PHP, or .NET, and it fires in response to HTTP requests, Pub/Sub messages, or Cloud Storage events. Use it for glue code, webhooks, and lightweight data processing.

When to use which:

– Lift-and-shift VMs or full OS control: Compute Engine

– Container orchestration at scale: GKE

– Serverless containers, scale-to-zero: Cloud Run

– Event-driven functions, minimal overhead: Cloud Functions

Storage and databases: where your data lives

Cloud Storage is GCP’s object store. It holds files, backups, images, logs, and static assets with 99.999999999% (11 nines) durability. Four storage classes let you trade access speed for cost: Standard (frequent access), Nearline (accessed monthly), Coldline (quarterly), and Archive (yearly). Object lifecycle policies automatically transition or delete objects.

gcloud storage cp my-backup.tar.gz gs://my-bucket/backups/
gcloud storage lifecycle set lifecycle-policy.json gs://my-bucketCode language: Bash (bash)

Cloud SQL is managed relational databases supporting MySQL, PostgreSQL, and SQL Server. Google handles backups, replication, patching, and failover. Use Cloud SQL for traditional relational workloads where you need ACID transactions and existing SQL tooling.

BigQuery is a serverless data warehouse for analytics at petabyte scale. It offers on-demand (per-query) and capacity-based (slot reservation) billing, separating compute from storage. Use BigQuery for log analytics, business intelligence, and any scenario where you need to run SQL across massive datasets without managing infrastructure.

Firestore (Datastore mode or Native mode) is a NoSQL document database with real-time sync and offline support. Use it for mobile/web app backends, user profiles, and session data.

Networking: how services talk to each other

Virtual Private Cloud (VPC) creates isolated network environments. You define subnets, firewall rules, and routing. GCP VPCs are global – a single VPC spans regions without complex peering. Shared VPC lets multiple projects share a common network.

Cloud Load Balancing distributes traffic across instances in multiple regions. It is a single anycast IP that handles HTTP(S), TCP/SSL, and UDP traffic, with automatic failover and health checks.

Cloud CDN caches content at Google’s edge locations, reducing latency and origin server load. It integrates directly with Cloud Load Balancing and Cloud Storage.

Cloud Interconnect and Cloud VPN connect on-premises networks to GCP. Use Dedicated Interconnect for 10 Gbps+ links, Partner Interconnect for sub-10 Gbps, or Cloud VPN for encrypted tunnels over the public internet.

Security and IAM: who can access what

Google Cloud’s security model is built on resource hierarchy and identity-based access control.

IAM (Identity and Access Management) uses roles to grant permissions. There are three role types: primitive (Owner, Editor, Viewer – broad, avoid these), predefined (curated by Google for specific services like roles/compute.admin), and custom (you define the exact permissions). The principle of least privilege applies: grant only the permissions needed for a specific task. Service accounts give workloads their own identity so applications do not rely on user credentials.

For a deeper dive into GCP IAM with practical examples, see our GCP IAM Access Control guide.

gcloud projects add-iam-policy-binding my-project \
  –member="serviceAccount:[email protected]" \
  –role="roles/storage.objectViewer"Code language: Bash (bash)

Secret Manager stores API keys, passwords, and certificates with encryption at rest and audit logging. It supports versioning and automatic rotation schedules.

Cloud KMS (Key Management Service) manages encryption keys for data at rest and in transit. Use it for envelope encryption, signing, and verifying data.

Cloud Armor provides DDoS protection and WAF capabilities for applications behind Cloud Load Balancing. It integrates with reCAPTCHA Enterprise for bot detection.

DevOps and CI/CD: shipping code

Cloud Build runs CI/CD pipelines as serverless jobs. You define steps in YAML or JSON, and Cloud Build executes them in ephemeral environments. It integrates with GitHub, GitLab, and Bitbucket, and can produce container images pushed directly to Artifact Registry.

gcloud builds submit –config=cloudbuild.yaml .Code language: Bash (bash)

Artifact Registry stores build artifacts: container images, language packages (npm, Maven, Python), and OS packages. It provides vulnerability scanning and access control per repository. It replaced Container Registry (gcr.io) as the recommended artifact store.

Cloud Deploy is a managed continuous delivery service for GKE, Cloud Run, and Compute Engine targets. It defines delivery pipelines with target stages (dev → staging → prod), supports canary and rolling deployments, and provides approval gates between stages.

Cloud Code is an IDE plugin (VS Code, IntelliJ) that brings GCP integration into your editor. It provides YAML linting for Kubernetes manifests, one-click deployment, and a local development environment. While it is a productivity tool rather than a core service, it is worth knowing if you spend most of your day in an IDE.

Pub/Sub is GCP’s messaging backbone and deserves a mention – it powers event-driven architectures between services. While not a service you directly manage day-to-day, it is the glue layer behind Cloud Functions triggers, log routing, and streaming analytics pipelines.

Observability: what is happening in production

Cloud Monitoring collects metrics, dashboards, and alerts from GCP services and custom applications. It provides out-of-the-box dashboards for Compute Engine, GKE, Cloud Run, and other services, plus uptime checks for external endpoints.

Cloud Logging centralizes logs from all GCP services into a single searchable interface. It supports log-based metrics, log routing to Pub/Sub or Cloud Storage, and structured logging for application logs.

gcloud logging read 'resource.type="gce_instance" AND severity>=ERROR' –limit=50Code language: Bash (bash)

Cloud Trace provides distributed tracing for latency analysis across microservices. It shows request paths through your distributed system and identifies bottlenecks.

Error Reporting aggregates and notifies on application crashes. It groups similar errors, tracks their frequency, and integrates with Cloud Monitoring alerting.

Decision guide: picking the right service

If you need to…Use
Run a VM with full OS controlCompute Engine
Orchestrate containers at scaleGKE
Deploy a container without managing infraCloud Run
Run a function on an event triggerCloud Functions (2nd gen)
Store files, backups, or static assetsCloud Storage
Run a managed relational databaseCloud SQL
Analyze terabytes of data with SQLBigQuery
Store secrets and API keysSecret Manager
Build and test code on every pushCloud Build
Store container images and packagesArtifact Registry
Deploy to GKE with progressive deliveryCloud Deploy
Create isolated network environmentsVPC
Control who can access resourcesIAM
Monitor and alert on production issuesCloud Monitoring + Logging

Do I need to learn all GCP services

No. Most DevOps engineers regularly work with 10-15 GCP services. Start with Compute Engine, Cloud Storage, and IAM, then expand as your projects demand. The services in this guide cover the majority of real-world workloads.

How is GCP different from AWS

GCP and AWS cover similar ground but with different philosophies. GCP projects are flat containers for resources (compared to AWS accounts), VPCs are global by default (vs regional), and GKE offers a deeper Kubernetes integration since Google created Kubernetes. For a side-by-side comparison of how cloud federation works across providers, read our Cloud Federation guide.

What is the best way to install the GCP CLI

The gcloud CLI is available for Linux, macOS, and Windows. The simplest approach is downloading the Google Cloud SDK installer, which includes gcloud, gcloud storage (replacing the deprecated gsutil), and bq. We have a step-by-step GCP CLI installation guide if you run into issues.

Which GCP services come up most in interviews

GKE, IAM, Cloud Storage, Compute Engine, and Cloud Run are the most commonly discussed in DevOps interviews. Our GCP Interview Questions guide covers the most frequent questions with example answers.

Is GCP cheaper than other clouds

It depends on the workload. GCP’s sustained-use discounts apply automatically to Compute Engine instances, and committed-use contracts offer deeper discounts. Cloud Run’s scale-to-zero model can be cost-effective for intermittent workloads. The best approach is to estimate costs for your specific usage patterns with the Google Cloud Pricing Calculator.

Sergio Bremming Avatar

Leave a Reply

Your email address will not be published. Required fields are marked *