Group 4: Container & Kubernetes
Container orchestration and registry services: Google Kubernetes Engine (GKE) (managed Kubernetes), Cloud Run (serverless containers), Artifact Registry (container/artifact storage), Container Registry (legacy), Binary Authorization (container security). Choose based on orchestration complexity, scaling patterns, and security requirements.
Services & Core Identity
Google Kubernetes Engine (GKE)
Managed Kubernetes with Standard (full control) and Autopilot (simplified) modes, integrated security, and auto-scaling.
Cloud Run
Fully managed serverless platform for containerized applications with automatic scaling and pay-per-request billing.
Artifact Registry
Universal artifact management for containers, packages, and other artifacts with security scanning and access controls.
Container Registry (Legacy)
Docker container registry service - migrating to Artifact Registry for enhanced features and security.
Binary Authorization
Policy-based deployment validation ensuring only trusted container images are deployed to production.
Key Differences
| Dimension | GKE Standard | GKE Autopilot | Cloud Run | Artifact Registry | Binary Authorization |
|---|---|---|---|---|---|
| Management Level | Full control | Google-managed | Fully managed | Registry service | Security policy |
| Complexity | High | Medium | Low | Low | Medium |
| Scaling Model | Manual/HPA | Automatic | Automatic | N/A | N/A |
| Cost Model | Node-based | Pod-based | Request-based | Storage-based | Policy evaluation |
| Use Case | Complex workloads | Standard apps | Stateless services | Artifact storage | Security compliance |
| Networking | Full VPC control | Simplified | HTTPS only | Private/public | Policy enforcement |
Mathematical Selection Model
Criteria [0..10]. Higher scores indicate better service fit.
Interpretation Rules
- GKE Standard: Complex microservices, custom networking, advanced Kubernetes features, multi-cloud portability
- GKE Autopilot: Standard containerized applications, reduced operational overhead, cost optimization
- Cloud Run: Stateless APIs, event-driven services, simple web applications, rapid prototyping
- Artifact Registry: Secure artifact storage, vulnerability scanning, multi-format repositories
- Binary Authorization: Regulated environments, supply chain security, policy-based deployment controls
When NOT to Use Containers
- Simple static websites (consider Firebase Hosting or Cloud Storage)
- Legacy applications with OS dependencies (consider Compute Engine)
- Windows-specific workloads requiring Windows containers at scale
- High-performance computing with specialized hardware requirements
Summary
GCP container services provide a spectrum from fully managed serverless (Cloud Run) to full Kubernetes control (GKE Standard). Choose based on operational complexity, Kubernetes expertise, networking requirements, and scaling patterns. Use Artifact Registry for secure artifact management and Binary Authorization for supply chain security in regulated environments.