Skip to content
Back to skills

Gcp Pro

ASecurity

Google Cloud guidance — core services, IAM, VPC networking, GKE/Cloud Run choices, BigQuery, and cost control.

  • 2 stars
  • 0 votes
  • 0 copies
  • 0 views
  • Added September 29, 2026
ai-agentsgosqlnoderailskubernetesgcpdebuggingapidatabaseperformance

Works with

  • api

Security analysis

A100/100

Scanned September 29, 2026

npx -y skills add aicodedecode/awesome-muse-skills --skill gcp-pro --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of Gcp Pro?

Add the live security badge to your README. It updates with every re-scan.

Security grade badge for Gcp Pro
[![Security: A — Skills Directory](https://www.skillsdirectory.com/api/skills/aicodedecode-gcp-pro/badge)](https://www.skillsdirectory.com/skills/aicodedecode-gcp-pro)

More formats (shields.io, HTML) on the badges page. Keep it an A: scan every change in CI with Pro.

Download with Pro
SKILL.md
---
name: gcp-pro
description: Google Cloud guidance — core services, IAM, VPC networking, GKE/Cloud Run choices, BigQuery, and cost control.
category: development
---

## Overview

Google Cloud Platform combines Google's infrastructure heritage (global networking, Kubernetes origins, BigQuery) with a developer-friendly service set. Its networking model is distinctive — a single global VPC rather than per-region networks — and its IAM, while powerful, has its own learning curve around hierarchy and organization policies.

GCP rewards understanding a few core ideas: projects as the isolation boundary, IAM's resource hierarchy, the global VPC, and choosing between GCE/GKE/Cloud Run/Cloud Functions for compute. This skill covers those fundamentals, the key services, and cost control.

## When to use

- Designing architecture on GCP (choosing services).
- Setting up IAM (hierarchy, roles, service accounts, least privilege).
- Building VPC networking (subnets, firewall rules, Private Google Access).
- Choosing compute (GCE, GKE, Cloud Run, Cloud Functions).
- Using BigQuery for analytics (modeling, partitioning, cost control).
- Controlling GCP costs (budgets, committed use, BigQuery slot pricing).
- Securing a GCP organization (baseline, auditing).

## Core concepts

- **Resource hierarchy.** Organization → folders → projects. Projects are the isolation and billing boundary — one per environment/team/service. IAM policies inherit downward; organization policies constrain what children can do.
- **IAM.** Members (users, groups, service accounts) get roles (predefined, custom) on resources. Prefer predefined roles, then custom roles with minimal permissions; avoid primitive roles (Owner/Editor) beyond break-glass. Service accounts are the workload identity — use them, not user credentials.
- **Service account impersonation.** Short-lived credentials via impersonation instead of downloadable keys. Keys that exist get leaked — design so they don't need to exist.
- **Global VPC.** One VPC spans all regions with regional subnets — no peering needed for cross-region traffic. Firewall rules (stateful, deny-by-default posture available) and hierarchical firewall policies for org-wide rules.
- **Private Google Access.** Reach Google APIs from private subnets without NAT — keeps traffic on Google's network and avoids NAT costs.
- **Compute choices.** GCE (VMs, full control), GKE (managed Kubernetes — Autopilot for hands-off, Standard for control), Cloud Run (serverless containers, scales to zero, the default for services), Cloud Functions (event-driven snippets). Cloud Run is the sweet spot for most services.
- **Cloud Run well.** Concurrency per instance, CPU allocation (always-allocated for background work), min instances for latency-sensitive paths, max instances to bound cost, VPC connectors only when needed.
- **GKE.** Autopilot removes node management; workload identity binds K8s service accounts to GCP service accounts (no keys). Use it when you need Kubernetes semantics, not by default.
- **Cloud SQL / AlloyDB.** Managed Postgres/MySQL (Cloud SQL) with HA and backups; AlloyDB for high-performance Postgres-compatible workloads. Private IP, no public exposure.
- **BigQuery.** Serverless data warehouse: columnar storage, SQL interface, partitioning + clustering for performance and cost. On-demand vs flat-rate/slot pricing — understand which fits your query pattern before the bill arrives.
- **GCS.** Object storage with storage classes (Standard/Nearline/Coldline/Archive), lifecycle policies, versioning, and uniform bucket-level access (prefer over fine-grained ACLs).
- **Pub/Sub.** Managed messaging: topics, subscriptions (push/pull), exactly-once delivery options, dead-letter topics, ordering keys. The decoupling primitive for event-driven GCP.
- **Cloud Armor.** WAF + DDoS protection at the edge, integrated with load balancers — rate limiting, geo-blocking, and managed OWASP rules.
- **Operations suite.** Cloud Logging/Monitoring/Trace/Profiler — the default observability stack. Structured JSON logs, log-based metrics, SLO monitoring with alerting.
- **Budgets and cost control.** Budgets with alert thresholds, committed use discounts for steady workloads, BigQuery cost controls (query quotas, custom quotas), and regular rightsizing.
- **Cloud Run jobs.** Run-to-completion container tasks (batch, migrations) — the serverless answer to one-off jobs without standing up GKE.
- **VPC Service Controls.** A data-exfiltration perimeter around GCP resources — complexity worth paying for regulated workloads.

## Practical workflow

1. **Set up the hierarchy.** Organization → folders (prod/non-prod) → projects per service/environment; organization policies (allowed regions, no public IPs, OS Login) as guardrails.
2. **Configure IAM.** Groups for humans (never individual bindings at scale), service accounts per workload, least-privilege custom roles where predefined are too broad; workload identity for GKE, impersonation elsewhere.
   ```hcl
   # least-privilege binding sketch
   resource "google_project_iam_member" "api_reader" {
     project = var.project_id
     role    = "roles/pubsub.subscriber"
     member  = "serviceAccount:${google_service_account.api.email}"
   }
   ```
3. **Build the VPC.** Shared VPC for multi-project networking or per-project VPCs; private subnets for workloads, Private Google Access on, firewall rules deny-by-default with explicit allows, Cloud NAT only where public egress is needed.
4. **Choose compute per workload.** Services → Cloud Run (scale-to-zero, concurrency tuned); event handlers → Cloud Functions/Eventarc; Kubernetes needs → GKE Autopilot; VMs → GCE with managed instance groups.
5. **Put data on managed services.** Cloud SQL private-IP with automated backups and point-in-time recovery; GCS with lifecycle policies; BigQuery datasets with partitioned tables.
6. **Decouple with Pub/Sub.** Events between services via topics; pull subscriptions for workers with dead-letter topics; ordering keys only where order truly matters.
7. **Protect the edge.** Global load balancer + Cloud Armor policies (rate limits, WAF rules); Cloud CDN for static content; IAP (Identity-Aware Proxy) for internal apps instead of VPNs.
8. **Observe and control cost.** Cloud Monitoring dashboards + SLO alerts; budgets at project/folder level with webhook notifications; BigQuery slot/quota monitoring; committed use discounts after baselines stabilize.

   ```hcl
   resource "google_compute_firewall" "deny_all_ingress" {
     name    = "deny-all-ingress"
     network = google_compute_network.main.name
     deny { protocol = "all" }
     source_ranges = ["0.0.0.0/0"]
     priority      = 65535 # last-resort deny; explicit allows take precedence
   }
   ```

## Common pitfalls

- **Primitive roles (Owner/Editor)** — org-wide blast radius; use granular roles.
- **Downloaded service account keys** — leaked credentials; impersonation and workload identity instead.
- **Public Cloud SQL** — databases with public IPs; private IP + authorized networks only.
- **BigQuery cost surprise** — unpartitioned full-table scans on terabytes; partition, cluster, and set quotas.
- **Cloud Run max instances unset** — runaway scaling bills; always bound max instances.
- **Flat project structure** — everything in one project; use folders and per-service projects.
- **No organization policies** — no guardrails on regions, public IPs, or external sharing; set them early.
- **NAT for Google API traffic** — paying NAT data-processing for API calls; Private Google Access instead.
- **Ignoring budgets** — cost alerts configured but unmonitored; budgets need owners and runbooks.
- **GKE by default** — Kubernetes operational overhead for services Cloud Run would handle; choose the simplest compute that fits.
- **Uniform bucket access ignored** — legacy ACL sprawl; enable uniform access on new buckets.
- **No dead-letter on Pub/Sub** — poison messages redelivering forever; configure dead-letter topics.
- **Firewall rules wide open** — `0.0.0.0/0` ingress left from debugging; audit and restrict.

Attribution

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments

Loading comments…