The Resource Hierarchy
Every resource in Google Cloud Platform (GCP) lives inside a hierarchy that controls billing, access, and organization. Understanding this tree is the foundation of everything else, because IAM policies and quotas flow downward through it.
| Level | Purpose |
|---|---|
| Organization | Root node tied to a Cloud Identity / Workspace domain; owns everything |
| Folder | Optional grouping (by department, team, or environment) for shared policy |
| Project | The core billing and API boundary; every resource belongs to exactly one project |
| Resource | A VM, bucket, database, etc. that lives inside a project |
Key Idea
A GCP project has three identifiers: a project ID (globally unique, immutable), a project number (auto-assigned), and a display name. Almost every gcloud command needs a project ID.
The gcloud CLI
The gcloud command-line tool is part of the Google Cloud SDK and is the primary way to script GCP. Configure it once with a named configuration so you can switch between accounts and projects.
# Authenticate and initialize
gcloud auth login
gcloud init
# Create a project and set it as the active default
gcloud projects create my-app-2026 --name="My App"
gcloud config set project my-app-2026
# Link a billing account (required before using paid APIs)
gcloud billing projects link my-app-2026 \
--billing-account=0X0X0X-0X0X0X-0X0X0X
# Enable the APIs you plan to use
gcloud services enable compute.googleapis.com storage.googleapis.com
# Inspect current config and list projects
gcloud config list
gcloud projects list
Identity and Access Management (IAM)
GCP IAM answers the question "who can do what on which resource?". You bind a member (a user, group, or service account) to a role (a bundle of permissions) on a resource. There are three role types:
- Basic roles — legacy Owner / Editor / Viewer. Too broad; avoid in production.
- Predefined roles — service-scoped, e.g.
roles/storage.objectViewer. The recommended default. - Custom roles — you hand-pick the exact permissions for least-privilege needs.
# Grant a user a predefined role on the whole project
gcloud projects add-iam-policy-binding my-app-2026 \
--member="user:dev@example.com" \
--role="roles/compute.instanceAdmin.v1"
# Create a service account for a workload (non-human identity)
gcloud iam service-accounts create backend-sa \
--display-name="Backend service account"
# Give that service account read-only access to a bucket
gsutil iam ch \
serviceAccount:backend-sa@my-app-2026.iam.gserviceaccount.com:objectViewer \
gs://my-app-assets
Best Practice
Prefer Workload Identity Federation and attached service accounts over downloaded service-account key files. Long-lived JSON keys are the most common source of GCP credential leaks.
Compute Engine — Virtual Machines
Compute Engine provides Infrastructure-as-a-Service VMs. Instances run in a specific zone (e.g. us-central1-a), and zones group into regions. Machine types define vCPU and memory; pricing improves automatically with sustained use and can drop up to ~91% with Spot VMs.
# Create an e2-medium VM running Debian 12
gcloud compute instances create web-1 \
--zone=us-central1-a \
--machine-type=e2-medium \
--image-family=debian-12 \
--image-project=debian-cloud \
--tags=http-server
# Open port 80 with a firewall rule
gcloud compute firewall-rules create allow-http \
--allow=tcp:80 --target-tags=http-server
# SSH into the instance (keys managed automatically)
gcloud compute ssh web-1 --zone=us-central1-a
# List and clean up
gcloud compute instances list
gcloud compute instances delete web-1 --zone=us-central1-a
Managed Instance Groups
For production you rarely manage single VMs. A Managed Instance Group (MIG) uses an instance template to create identical VMs, then adds autohealing and autoscaling on top.
gcloud compute instance-templates create web-tmpl \
--machine-type=e2-small --image-family=debian-12 --image-project=debian-cloud
gcloud compute instance-groups managed create web-mig \
--template=web-tmpl --size=2 --zone=us-central1-a
gcloud compute instance-groups managed set-autoscaling web-mig \
--zone=us-central1-a --max-num-replicas=10 --target-cpu-utilization=0.6
Storage Options
GCP separates storage by access pattern. Picking the right one is a common exam and design question.
| Service | Use for |
|---|---|
| Cloud Storage | Object storage for files, images, backups, data lakes |
| Persistent Disk / Hyperdisk | Block storage attached to Compute Engine VMs |
| Cloud SQL | Managed MySQL, PostgreSQL, SQL Server (relational, regional) |
| Firestore | Serverless document NoSQL for app data |
| BigQuery | Serverless data warehouse for analytics at petabyte scale |
# Create a regional bucket and upload a file
gcloud storage buckets create gs://my-app-assets --location=us-central1
gcloud storage cp ./logo.png gs://my-app-assets/
# List objects and set a lifecycle to move old data to a cheaper class
gcloud storage ls gs://my-app-assets/
gcloud storage buckets update gs://my-app-assets \
--lifecycle-file=lifecycle.json
Cloud Storage storage classes trade retrieval cost for storage cost: STANDARD for hot data, then NEARLINE, COLDLINE, and ARCHIVE for progressively colder data.
Cross-Cloud Service Mapping
If you already know AWS or Azure, mapping the equivalent GCP service accelerates learning.
| Category | AWS | Azure | GCP |
|---|---|---|---|
| VMs | EC2 | Virtual Machines | Compute Engine |
| Object storage | S3 | Blob Storage | Cloud Storage |
| Managed SQL | RDS | Azure SQL | Cloud SQL |
| Kubernetes | EKS | AKS | GKE |
| Functions | Lambda | Azure Functions | Cloud Run functions |
| Data warehouse | Redshift | Synapse | BigQuery |
Billing and Cost Control
GCP bills per second for most compute with a one-minute minimum. Guard against surprises with budgets and alerts, and always tear down lab resources.
# Create a monthly budget with an alert at 90% of $50
gcloud billing budgets create \
--billing-account=0X0X0X-0X0X0X-0X0X0X \
--display-name="Lab budget" \
--budget-amount=50USD \
--threshold-rule=percent=0.9
Practice Exercises
- Create a new project, link a billing account, and enable the Compute Engine and Cloud Storage APIs entirely from
gcloud. - Launch an
e2-microVM, add a firewall rule for port 80, install nginx, and reach it in a browser. - Create a service account, grant it
roles/storage.objectVieweron a bucket, and verify it cannot delete objects. - Create a bucket, upload three files, and apply a lifecycle rule that moves objects to
NEARLINEafter 30 days. - Build an instance template and a managed instance group of size 2, then enable autoscaling to a max of 5 on 60% CPU.
- Set a $10 budget with alerts at 50% and 90%, then delete every resource you created and confirm the project shows no billable usage.