Scan with Phone

Scan to instantly open and share this page on your mobile device.

Link copied to clipboard!

Group 4: Container & Kubernetes

Container orchestration and registry services: Google Kubernetes Engine (GKE) (managed Kubernetes), Cloud Run (serverless containers), Artifact Registry (container/artifact storage), Container Registry (legacy), Binary Authorization (container security). Choose based on orchestration complexity, scaling patterns, and security requirements.

Orchestration Spectrum: Cloud Run for stateless microservices; GKE Standard for full Kubernetes control; GKE Autopilot for simplified operations; Artifact Registry for secure artifact management; Binary Authorization for supply chain security.

Services & Core Identity

Google Kubernetes Engine (GKE)

Managed Kubernetes with Standard (full control) and Autopilot (simplified) modes, integrated security, and auto-scaling.

Cloud Run

Fully managed serverless platform for containerized applications with automatic scaling and pay-per-request billing.

Artifact Registry

Universal artifact management for containers, packages, and other artifacts with security scanning and access controls.

Container Registry (Legacy)

Docker container registry service - migrating to Artifact Registry for enhanced features and security.

Binary Authorization

Policy-based deployment validation ensuring only trusted container images are deployed to production.

Key Differences

DimensionGKE StandardGKE AutopilotCloud RunArtifact RegistryBinary Authorization
Management LevelFull controlGoogle-managedFully managedRegistry serviceSecurity policy
ComplexityHighMediumLowLowMedium
Scaling ModelManual/HPAAutomaticAutomaticN/AN/A
Cost ModelNode-basedPod-basedRequest-basedStorage-basedPolicy evaluation
Use CaseComplex workloadsStandard appsStateless servicesArtifact storageSecurity compliance
NetworkingFull VPC controlSimplifiedHTTPS onlyPrivate/publicPolicy enforcement

Mathematical Selection Model

Criteria [0..10]. Higher scores indicate better service fit.

Score_GKEStandard = 0.25*C_k8sExpertise + 0.25*C_operationalControl + 0.20*C_complexNetworking + 0.15*C_multiCloudStrategy + 0.10*C_customRequirements + 0.05*(10 - C_developmentSpeed) Score_GKEAutopilot = 0.25*(10 - C_k8sExpertise) + 0.25*C_developmentSpeed + 0.20*C_costOptimization + 0.15*C_standardWorkloads + 0.10*C_securityRequirements + 0.05*(10 - C_operationalControl) Score_CloudRun = 0.30*C_statelessServices + 0.25*C_developmentSpeed + 0.20*C_costOptimization + 0.15*(10 - C_k8sExpertise) + 0.10*(10 - C_complexNetworking) Score_ArtifactRegistry = 0.30*C_securityRequirements + 0.25*C_artifactManagement + 0.20*C_complianceNeeds + 0.15*C_multiFormat + 0.10*C_accessControl Score_BinaryAuth = 0.40*C_securityRequirements + 0.30*C_complianceNeeds + 0.20*C_supplyChainSecurity + 0.10*C_policyEnforcement
{{s.name}}: {{s.val | number:2}}

Interpretation Rules

  • GKE Standard: Complex microservices, custom networking, advanced Kubernetes features, multi-cloud portability
  • GKE Autopilot: Standard containerized applications, reduced operational overhead, cost optimization
  • Cloud Run: Stateless APIs, event-driven services, simple web applications, rapid prototyping
  • Artifact Registry: Secure artifact storage, vulnerability scanning, multi-format repositories
  • Binary Authorization: Regulated environments, supply chain security, policy-based deployment controls

When NOT to Use Containers

  • Simple static websites (consider Firebase Hosting or Cloud Storage)
  • Legacy applications with OS dependencies (consider Compute Engine)
  • Windows-specific workloads requiring Windows containers at scale
  • High-performance computing with specialized hardware requirements

Summary

GCP container services provide a spectrum from fully managed serverless (Cloud Run) to full Kubernetes control (GKE Standard). Choose based on operational complexity, Kubernetes expertise, networking requirements, and scaling patterns. Use Artifact Registry for secure artifact management and Binary Authorization for supply chain security in regulated environments.

next