Google Cloud
Understand the cloud beneath the platform.
A practical learning path through Google Cloud's resource model, identity, networking, compute, data and operations—with a direct bridge to Nais.
Google Cloud is easier to learn when it is treated as a system of resources, identities, networks, locations and managed capabilities, not as a catalogue of hundreds of product names. This path starts with that system and moves towards the decisions an application architect or platform user actually makes.
The path is deliberately connected to Nais. Nais removes much of the day-to-day Kubernetes and cloud configuration from product teams, but concepts such as projects, IAM, service accounts, regions, GKE, Cloud SQL, Cloud Storage and BigQuery still explain what happens under the abstraction.
Use Google Cloud directly or through Nais? when you need the operational comparison: what Nais buys you, which flexibility changes, who provides support and what happens when PostgreSQL becomes unavailable.
Examples are conceptual and safe to study without a cloud account. When you practise in a real project, configure a budget first, use a sandbox project, prefer short-lived credentials and remove chargeable resources when the exercise is complete.
Recommended order
From foundations to production
Follow the modules in order if Google Cloud is new to you. Experienced cloud architects can begin with workload selection and use the Nais bridge in every module.
Foundations
Resource model, locations and cost
Learn how organizations, folders, projects, resources, APIs, regions, zones and billing fit together before deploying anything.
- Resource hierarchy
- Regions and zones
- Billing and quotas
Security
Identity, IAM and security controls
Separate authentication from authorization, understand principals, roles and policies, and give workloads short-lived identities without downloaded keys.
- IAM policies
- Service accounts
- Workload identity
Infrastructure
Networking and connectivity
Build a mental model of global VPC networks, regional subnets, routes, firewalls, load balancing, DNS and private service access.
- VPC and subnets
- Ingress and egress
- Hybrid connectivity
Application platform
Compute, containers and workload selection
Choose deliberately between Cloud Run, GKE and Compute Engine, then design stateless services, jobs and event-driven workloads for scaling and failure.
- Cloud Run
- GKE
- Compute Engine
Architecture
Data, integration and production operations
Match storage and messaging to data behavior, then operate the whole system with SLOs, telemetry, resilience, cost controls and the Well-Architected Framework.
- Data services
- Observability and SLOs
- Reliability and cost
Assessment
Google Cloud architecture check
Fifteen scenario-based questions across resource design, IAM, networking, runtime selection, data and operations.
- 15 scenarios
- Explanations
- Official references
The platform layer
Continue from Google Cloud into Nais
Nais runs application workloads on GKE and exposes selected Google Cloud services through safer self-service contracts. The Nais path shows which details remain visible and which are owned by the platform team.