Quick reference for gcloud commands, IAM roles, Compute Engine, storage, and the resource hierarchy.
GCPCompute EngineIAMgcloud
gcloud Setup & Config
# Auth + init
gcloud auth login
gcloud init
# Project / region defaults
gcloud config set project my-app-2026
gcloud config set compute/region us-central1
gcloud config set compute/zone us-central1-a
gcloud config list
# Named configs (switch accounts/projects)
gcloud config configurations create work
gcloud config configurations activate work
# Enable APIs
gcloud services enable compute.googleapis.com storage.googleapis.com
Resource Hierarchy
| Level | Notes |
| Organization | Root, tied to a domain |
| Folder | Optional grouping for policy |
| Project | Billing + API boundary |
| Resource | VM, bucket, DB, etc. |
IAM
Bind & Manage
# Grant a role
gcloud projects add-iam-policy-binding PROJECT \
--member="user:dev@example.com" --role="roles/viewer"
# Service account
gcloud iam service-accounts create app-sa --display-name="App SA"
# View effective policy
gcloud projects get-iam-policy PROJECT
Member Prefixes
| Prefix | Identity |
| user: | A single Google account |
| group: | A Google Group |
| serviceAccount: | A workload identity |
| domain: | All accounts in a Workspace domain |
Compute Engine
# Create + SSH + delete
gcloud compute instances create web-1 \
--machine-type=e2-medium --image-family=debian-12 \
--image-project=debian-cloud --zone=us-central1-a
gcloud compute ssh web-1 --zone=us-central1-a
gcloud compute instances list
gcloud compute instances delete web-1 --zone=us-central1-a
# Firewall rule
gcloud compute firewall-rules create allow-http \
--allow=tcp:80 --target-tags=http-server
# Managed instance group + autoscaling
gcloud compute instance-groups managed create web-mig \
--template=web-tmpl --size=2 --zone=us-central1-a
gcloud compute instance-groups managed set-autoscaling web-mig \
--zone=us-central1-a --max-num-replicas=10 --target-cpu-utilization=0.6
Storage & Data
# Cloud Storage
gcloud storage buckets create gs://my-bucket --location=us-central1
gcloud storage cp file.txt gs://my-bucket/
gcloud storage ls gs://my-bucket/
gcloud storage rm gs://my-bucket/file.txt
# Cloud SQL
gcloud sql instances create pg1 --database-version=POSTGRES_16 \
--tier=db-f1-micro --region=us-central1
# BigQuery query
bq query --use_legacy_sql=false 'SELECT COUNT(*) FROM `proj.ds.tbl`'
Storage Classes
| Class | Min Duration |
| STANDARD | None (hot data) |
| NEARLINE | 30 days |
| COLDLINE | 90 days |
| ARCHIVE | 365 days |
Cross-Cloud Map
| AWS | Azure | GCP |
| EC2 | VMs | Compute Engine |
| S3 | Blob | Cloud Storage |
| RDS | Azure SQL | Cloud SQL |
| EKS | AKS | GKE |
| Redshift | Synapse | BigQuery |