contentintech
Learn/cloud/GCP Fundamentals
Beginner~20 min read

GCP Fundamentals

Core Google Cloud concepts: projects, IAM, compute, storage, networking, and the gcloud CLI.

GCPCompute EngineIAMgcloud

The Resource Hierarchy

Every resource in Google Cloud Platform (GCP) lives inside a hierarchy that controls billing, access, and organization. Understanding this tree is the foundation of everything else, because IAM policies and quotas flow downward through it.

LevelPurpose
OrganizationRoot node tied to a Cloud Identity / Workspace domain; owns everything
FolderOptional grouping (by department, team, or environment) for shared policy
ProjectThe core billing and API boundary; every resource belongs to exactly one project
ResourceA VM, bucket, database, etc. that lives inside a project

Key Idea

A GCP project has three identifiers: a project ID (globally unique, immutable), a project number (auto-assigned), and a display name. Almost every gcloud command needs a project ID.

The gcloud CLI

The gcloud command-line tool is part of the Google Cloud SDK and is the primary way to script GCP. Configure it once with a named configuration so you can switch between accounts and projects.

bash
# Authenticate and initialize
gcloud auth login
gcloud init

# Create a project and set it as the active default
gcloud projects create my-app-2026 --name="My App"
gcloud config set project my-app-2026

# Link a billing account (required before using paid APIs)
gcloud billing projects link my-app-2026 \
  --billing-account=0X0X0X-0X0X0X-0X0X0X

# Enable the APIs you plan to use
gcloud services enable compute.googleapis.com storage.googleapis.com

# Inspect current config and list projects
gcloud config list
gcloud projects list

Identity and Access Management (IAM)

GCP IAM answers the question "who can do what on which resource?". You bind a member (a user, group, or service account) to a role (a bundle of permissions) on a resource. There are three role types:

  • Basic roles — legacy Owner / Editor / Viewer. Too broad; avoid in production.
  • Predefined roles — service-scoped, e.g. roles/storage.objectViewer. The recommended default.
  • Custom roles — you hand-pick the exact permissions for least-privilege needs.
bash
# Grant a user a predefined role on the whole project
gcloud projects add-iam-policy-binding my-app-2026 \
  --member="user:dev@example.com" \
  --role="roles/compute.instanceAdmin.v1"

# Create a service account for a workload (non-human identity)
gcloud iam service-accounts create backend-sa \
  --display-name="Backend service account"

# Give that service account read-only access to a bucket
gsutil iam ch \
  serviceAccount:backend-sa@my-app-2026.iam.gserviceaccount.com:objectViewer \
  gs://my-app-assets

Best Practice

Prefer Workload Identity Federation and attached service accounts over downloaded service-account key files. Long-lived JSON keys are the most common source of GCP credential leaks.

Compute Engine — Virtual Machines

Compute Engine provides Infrastructure-as-a-Service VMs. Instances run in a specific zone (e.g. us-central1-a), and zones group into regions. Machine types define vCPU and memory; pricing improves automatically with sustained use and can drop up to ~91% with Spot VMs.

bash
# Create an e2-medium VM running Debian 12
gcloud compute instances create web-1 \
  --zone=us-central1-a \
  --machine-type=e2-medium \
  --image-family=debian-12 \
  --image-project=debian-cloud \
  --tags=http-server

# Open port 80 with a firewall rule
gcloud compute firewall-rules create allow-http \
  --allow=tcp:80 --target-tags=http-server

# SSH into the instance (keys managed automatically)
gcloud compute ssh web-1 --zone=us-central1-a

# List and clean up
gcloud compute instances list
gcloud compute instances delete web-1 --zone=us-central1-a

Managed Instance Groups

For production you rarely manage single VMs. A Managed Instance Group (MIG) uses an instance template to create identical VMs, then adds autohealing and autoscaling on top.

bash
gcloud compute instance-templates create web-tmpl \
  --machine-type=e2-small --image-family=debian-12 --image-project=debian-cloud

gcloud compute instance-groups managed create web-mig \
  --template=web-tmpl --size=2 --zone=us-central1-a

gcloud compute instance-groups managed set-autoscaling web-mig \
  --zone=us-central1-a --max-num-replicas=10 --target-cpu-utilization=0.6

Storage Options

GCP separates storage by access pattern. Picking the right one is a common exam and design question.

ServiceUse for
Cloud StorageObject storage for files, images, backups, data lakes
Persistent Disk / HyperdiskBlock storage attached to Compute Engine VMs
Cloud SQLManaged MySQL, PostgreSQL, SQL Server (relational, regional)
FirestoreServerless document NoSQL for app data
BigQueryServerless data warehouse for analytics at petabyte scale
bash
# Create a regional bucket and upload a file
gcloud storage buckets create gs://my-app-assets --location=us-central1
gcloud storage cp ./logo.png gs://my-app-assets/

# List objects and set a lifecycle to move old data to a cheaper class
gcloud storage ls gs://my-app-assets/
gcloud storage buckets update gs://my-app-assets \
  --lifecycle-file=lifecycle.json

Cloud Storage storage classes trade retrieval cost for storage cost: STANDARD for hot data, then NEARLINE, COLDLINE, and ARCHIVE for progressively colder data.

Cross-Cloud Service Mapping

If you already know AWS or Azure, mapping the equivalent GCP service accelerates learning.

CategoryAWSAzureGCP
VMsEC2Virtual MachinesCompute Engine
Object storageS3Blob StorageCloud Storage
Managed SQLRDSAzure SQLCloud SQL
KubernetesEKSAKSGKE
FunctionsLambdaAzure FunctionsCloud Run functions
Data warehouseRedshiftSynapseBigQuery

Billing and Cost Control

GCP bills per second for most compute with a one-minute minimum. Guard against surprises with budgets and alerts, and always tear down lab resources.

bash
# Create a monthly budget with an alert at 90% of $50
gcloud billing budgets create \
  --billing-account=0X0X0X-0X0X0X-0X0X0X \
  --display-name="Lab budget" \
  --budget-amount=50USD \
  --threshold-rule=percent=0.9

Practice Exercises

  1. Create a new project, link a billing account, and enable the Compute Engine and Cloud Storage APIs entirely from gcloud.
  2. Launch an e2-micro VM, add a firewall rule for port 80, install nginx, and reach it in a browser.
  3. Create a service account, grant it roles/storage.objectViewer on a bucket, and verify it cannot delete objects.
  4. Create a bucket, upload three files, and apply a lifecycle rule that moves objects to NEARLINE after 30 days.
  5. Build an instance template and a managed instance group of size 2, then enable autoscaling to a max of 5 on 60% CPU.
  6. Set a $10 budget with alerts at 50% and 90%, then delete every resource you created and confirm the project shows no billable usage.

Section navigation