Google Cloud Developer Training & Resource Guide

Technology: google-cloud · Category: hosting · Last reviewed: 2026-08-23

Source: https://tech-stack.codeamanilabs.org/guide/google-cloud

Insight:

Google Cloud is the heavyweight option — a full compute spectrum (Functions → Cloud Run → GKE → Compute Engine), every database shape (Cloud SQL, AlloyDB, Spanner, Firestore, Bigtable, BigQuery), and first-class AI via Vertex + Gemini. Two ideas unlock the rest: IAM (every API call resolves to a roles/* check, so scope service accounts tightly and prefer Workload Identity Federation over JSON keys) and the pricing model (serverless bills only while serving, with a real always-free tier; VMs bill 24/7). Cloud Shell gives you a pre-authed gcloud terminal in the browser. Prices below are us-central1 / Tier-1 list, reviewed 2026-08-23 — always reconcile against the official Pricing Calculator. Note the Maps key is NOT a Gemini key (see google-ai-studio), and Gemini on Vertex now goes through the Google Gen AI SDK (google-genai / @google/genai) — the old vertexai.generative_models modules were removed 2026-06-24.

 ██████╗  ██████╗  ██████╗  ██████╗ ██╗     ███████╗     ██████╗██╗      ██████╗ ██╗   ██╗██████╗
██╔════╝ ██╔═══██╗██╔═══██╗██╔════╝ ██║     ██╔════╝    ██╔════╝██║     ██╔═══██╗██║   ██║██╔══██╗
██║  ███╗██║   ██║██║   ██║██║  ███╗██║     █████╗      ██║     ██║     ██║   ██║██║   ██║██║  ██║
██║   ██║██║   ██║██║   ██║██║   ██║██║     ██╔══╝      ██║     ██║     ██║   ██║██║   ██║██║  ██║
╚██████╔╝╚██████╔╝╚██████╔╝╚██████╔╝███████╗███████╗    ╚██████╗███████╗╚██████╔╝╚██████╔╝██████╔╝
 ╚═════╝  ╚═════╝  ╚═════╝  ╚═════╝ ╚══════╝╚══════╝     ╚═════╝╚══════╝ ╚═════╝  ╚═════╝ ╚═════╝

Google Cloud Developer Training & Resource Guide

Focus: A developer's working map of Google Cloud — what each service is for, how to implement it (gcloud + SDK), what it costs (officially-sourced list prices + free tier), and where it bites. Sourced from cloud.google.com and docs.cloud.google.com; pricing reviewed 2026-08-23. Pricing changes — always confirm on the Pricing Calculator.


How to use this guide

This is a training resource, not just an integration cheat-sheet. Read it in three passes:

  1. Mental model → The GCP spine and the compute decision tree. Internalise these and 80% of "which service?" questions answer themselves.
  2. Service-by-service → each section below gives Use case · Implement · Cost · Gotcha. Skim the table, dive where you need.
  3. Hands-on → the interactive learn module above this page (Cloud Run cost explorer), the official learning paths, and the codeAmani notes for East-Africa-specific guidance.

💡 Per the codeAmani docs policy: when you implement against any of these APIs, pull current docs via the Context7 MCP (resolve-library-id → query-docs) or the official URL in each section — don't code from memory. GCP ships fast.


The GCP spine (a mental model)

Google Cloud is the same infrastructure Google runs Search, Gmail, and YouTube on, rented out. Ignore the 200-product catalogue; a product developer reaches for ~30 services across eight layers:

Layer Services you'll actually use
Compute Cloud Run · Cloud Run functions · GKE · Compute Engine · App Engine
Databases Cloud SQL · AlloyDB · Spanner · Firestore · Bigtable · Memorystore
Analytics BigQuery · Dataflow · Pub/Sub
Storage Cloud Storage · Persistent Disk · Filestore
AI / ML Vertex AI · Gemini API · Agent Builder / Agent Engine · Vector Search
Networking VPC · Cloud Load Balancing · Cloud CDN · Cloud Armor · Cloud DNS
Security & Identity IAM · Secret Manager · Cloud KMS · Workload Identity Federation
DevOps & Ops Cloud Build · Artifact Registry · Cloud Deploy · Cloud Logging/Monitoring · Cloud Scheduler · Cloud Tasks · Workflows · Eventarc

Two cross-cutting ideas hold it together:


Official Documentation

Resource URL
Google Cloud Docs (root) https://cloud.google.com/docs
gcloud CLI reference https://cloud.google.com/sdk/gcloud
Pricing Calculator (source of truth) https://cloud.google.com/products/calculator
Free Tier & $300 trial https://cloud.google.com/free/docs/free-cloud-features
Architecture Center (reference patterns) https://cloud.google.com/architecture
Cloud Skills Boost (training/labs) https://www.cloudskillsboost.google/
Cloud Run https://cloud.google.com/run/docs
Compute Engine https://cloud.google.com/compute/docs
GKE (Kubernetes) https://cloud.google.com/kubernetes-engine/docs
BigQuery https://cloud.google.com/bigquery/docs
Cloud SQL https://cloud.google.com/sql/docs
Firestore https://cloud.google.com/firestore/docs
Cloud Storage https://cloud.google.com/storage/docs
Vertex AI https://cloud.google.com/vertex-ai/docs
IAM & Admin https://cloud.google.com/iam/docs
Secret Manager https://cloud.google.com/secret-manager/docs
Pub/Sub https://cloud.google.com/pubsub/docs
Cloud Build https://cloud.google.com/build/docs
Cloud Shell https://cloud.google.com/shell/docs

Getting started: SDK, auth, and your first project

Install the Google Cloud SDK (gcloud)

# macOS
brew install --cask google-cloud-sdk

# Linux / WSL
curl https://sdk.cloud.google.com | bash
exec -l $SHELL

# Windows — download the installer:
# https://cloud.google.com/sdk/docs/install

gcloud init          # interactive: pick account + project + region
gcloud components install gke-gcloud-auth-plugin   # if you'll use GKE

No install at all? Open Cloud Shell — a pre-authed gcloud terminal in the browser.

The three ways to authenticate

# 1. You, interactively (local dev, console-style work)
gcloud auth login

# 2. Application Default Credentials — what the SDKs/libraries pick up
gcloud auth application-default login

# 3. A service account (CI/CD, servers). Prefer Workload Identity Federation
#    (below) over downloading a JSON key whenever you can.
gcloud auth activate-service-account --key-file=service-account.json

gcloud config set project my-project-id
gcloud config set run/region africa-south1     # set a default region

★ Why ADC matters — Google's client libraries don't take a key argument; they walk the Application Default Credentials chain (env var GOOGLE_APPLICATION_CREDENTIALS → gcloud user creds → attached service account on GCP). Authenticate once with gcloud auth application-default login and every SDK call "just works" locally with your identity. On Cloud Run/GKE/Compute Engine, the attached service account is the identity — no key files in production.

Enable an API before you call it

Nearly every "permission/404" on a fresh project is a disabled API:

gcloud services enable run.googleapis.com bigquery.googleapis.com \
  secretmanager.googleapis.com aiplatform.googleapis.com
gcloud services list --enabled

Cost & billing model (the part that bites)

All figures below are us-central1 / Tier-1 list prices, reviewed 2026-08-23, from cloud.google.com. Regional pricing varies; cold-tier storage adds retrieval + egress fees. Treat the Pricing Calculator as canonical.

Always-Free tier (per billing account, every month — not the trial)

Source: Free cloud features.

Product Always-free monthly allowance
$300 trial credit Spendable over 90 days (one-time, new accounts)
Compute Engine 1 e2-micro VM (us-west1/us-central1/us-east1) + 30 GB-mo standard PD
Cloud Storage 5 GB-mo regional (US regions)
Cloud Run 2M requests + 180,000 vCPU-s + 360,000 GiB-s (free-tier doc)
Cloud Run functions 2M invocations + 200,000 GHz-s + 400,000 GB-s
BigQuery 1 TiB queried + 10 GiB storage
Firestore 1 GiB stored + 50k reads / 20k writes / 20k deletes per day
Pub/Sub 10 GiB messages
Cloud Build 2,500 build-minutes
Secret Manager 6 active secret versions + 10,000 access ops
Cloud Logging first 50 GiB ingested per project

⚠️ The Cloud Run pricing page lists the free tier as 240,000 vCPU-s + 450,000 GiB-s (applied as a spend-based discount at Tier-1 rates), while the free-tier doc lists 180,000 / 360,000. They're published in two places — reconcile on the Calculator for your region.

Headline rates (us-central1, Tier-1 list)

Service What you pay for Rate
Cloud Run (instance-based) vCPU-second $0.00001800 / vCPU-s
memory $0.00000200 / GiB-s
requests (request-based mode) $0.40 / million
GKE cluster management $0.10 / cluster / hour (all clusters)
Autopilot per-second vCPU + memory + ephemeral-storage requested by Pods
BigQuery (on-demand) bytes scanned $6.25 / TiB (first 1 TiB/mo free)
active storage ~$0.02 / GiB-mo (first 10 GiB free)
Cloud Storage Standard at-rest (regional, US) ~$0.020 / GB-mo
Nearline / Coldline / Archive descending (~$0.010 / ~$0.004 / ~$0.0012) + retrieval fees
Compute Engine E2 VMs billed 24/7; Spot 60–91% off, CUD up to 55%

Discount levers (provisioned services)

Don't get surprised

# Set a budget + alert (do this on day one)
gcloud billing budgets create --billing-account=BILLING_ID \
  --display-name="codeamani-monthly" \
  --budget-amount=50USD \
  --threshold-rule=percent=0.5 --threshold-rule=percent=0.9

# Egress (data leaving Google) is the silent cost — same-region traffic
# between your services is usually free; cross-region and internet egress are not.

Compute

Pick the right compute primitive in one decision — start at the top and follow the arrows:

flowchart TD
  Q1{"Stateless container<br/>serving requests?"} -->|Yes| Q2{"One function<br/>covers it?"}
  Q1 -->|No| Q3{"Need Kubernetes?"}
  Q2 -->|Yes| F["Cloud Run functions"]
  Q2 -->|No| R["Cloud Run"]
  Q3 -->|Yes| G["GKE Autopilot"]
  Q3 -->|No| C["Compute Engine VM"]

Choosing compute: the decision tree

Is it a stateless container that responds to requests/events?
├─ Yes → does a single function/endpoint cover it?
│        ├─ Yes → Cloud Run functions   (smallest unit, event triggers)
│        └─ No  → Cloud Run             (any container, scale-to-zero, websockets, jobs)
└─ No  → do you need Kubernetes / multi-container orchestration / service mesh?
         ├─ Yes → GKE  (Autopilot first; Standard for node-level control)
         └─ No  → need a full OS, GPU, long-running daemon, or custom kernel?
                  ├─ Yes → Compute Engine (VMs; Spot for batch)
                  └─ Legacy/managed PaaS → App Engine

Rule of thumb for codeAmani: start every service on Cloud Run. Graduate to GKE only when you genuinely need Kubernetes primitives, and to Compute Engine only for stateful/GPU/long-running work. Most M-Pesa + Next.js products never leave Cloud Run.

Cloud Run — serverless containers (start here)

# Deploy straight from source — Cloud Build builds the container for you
gcloud run deploy my-api --source . --region africa-south1 --allow-unauthenticated

# …or from a prebuilt image in Artifact Registry (gcr.io/Container Registry was
# shut down 2025-03-18 — new images live in *-docker.pkg.dev)
gcloud run deploy my-api \
  --image africa-south1-docker.pkg.dev/PROJECT/app/my-image:latest --region africa-south1

gcloud run services logs tail my-api --region africa-south1
gcloud run jobs create nightly-recon \
  --image africa-south1-docker.pkg.dev/PROJECT/app/recon:latest && \
gcloud run jobs execute nightly-recon

Cloud Run functions — event-driven snippets

gcloud functions deploy thumb-maker \
  --gen2 --runtime=nodejs24 --region=africa-south1 \
  --trigger-bucket=codeamani-uploads --entry-point=makeThumb

GKE — managed Kubernetes

gcloud container clusters create-auto my-cluster --region africa-south1   # Autopilot
gcloud container clusters get-credentials my-cluster --region africa-south1
kubectl apply -f deployment.yaml

Compute Engine — virtual machines (the escape hatch)

gcloud compute instances create dev-box \
  --zone=africa-south1-a --machine-type=e2-small \
  --image-family=debian-12 --image-project=debian-cloud --tags=http-server
gcloud compute ssh dev-box --zone=africa-south1-a
gcloud compute instances stop dev-box --zone=africa-south1-a   # stop to save $$

Databases

Service Shape Reach for it when…
Cloud SQL Managed Postgres / MySQL / SQL Server You want relational + familiar SQL with zero ops. The default OLTP DB.
AlloyDB Postgres-compatible, HTAP Heavy Postgres workloads needing 4× throughput + analytics on the same data.
Spanner Globally-distributed relational Horizontal scale and strong consistency at global scale.
Firestore Serverless document DB Mobile/web apps, real-time listeners, scale-to-zero, offline sync.
Bigtable Wide-column NoSQL Massive low-latency key/value (time-series, IoT, ad-tech).
Memorystore Managed Redis / Memcached Caching, sessions, rate-limit counters.
BigQuery Serverless analytics warehouse Analytics/BI/petabyte SQL — not an app DB.

Cloud SQL — managed relational (default OLTP)

gcloud sql instances create app-db --database-version=POSTGRES_16 \
  --tier=db-f1-micro --region=africa-south1
gcloud sql databases create app --instance=app-db
# From Cloud Run, connect via the built-in Cloud SQL connector (no public IP needed):
gcloud run deploy my-api --add-cloudsql-instances PROJECT:africa-south1:app-db

Firestore — serverless document DB

import { Firestore } from "@google-cloud/firestore";
const db = new Firestore();
await db.collection("payments").doc(checkoutRequestId).set({ status: "PENDING" });

codeAmani pattern: store the M-Pesa CheckoutRequestID as a Firestore doc ID on STK Push, then dedupe on callback — idempotency for free, and it scales to zero between transactions.


Storage

Cloud Storage — object store

gcloud storage buckets create gs://codeamani-uploads --location=africa-south1
gcloud storage cp ./file.pdf gs://codeamani-uploads/
# Signed URL for a time-limited client upload (no creds on the client):
gcloud storage sign-url gs://codeamani-uploads/file.pdf --duration=15m

AI / ML

Vertex AI + Gemini

# pip install google-genai   — the unified Google Gen AI SDK.
# The old vertexai.generative_models modules were REMOVED 2026-06-24; use this instead.
from google import genai

# vertexai=True routes to Vertex (IAM/residency); drop it + pass api_key for AI Studio.
client = genai.Client(vertexai=True, project="PROJECT", location="us-central1")
resp = client.models.generate_content(
    model="gemini-2.5-flash",
    contents="Andika salamu fupi kwa Kiswahili.",
)
print(resp.text)

Agent Builder / Agent Engine — managed agent runtime

pip install "google-cloud-aiplatform[agent_engines,adk]"
gcloud storage buckets create gs://codeamani-agents-staging --location=us-central1   # staging bucket first
import vertexai
from google.adk.agents import Agent
from vertexai.agent_engines import AdkApp

client = vertexai.Client(project="PROJECT", location="us-central1")
agent = Agent(name="support_bot", model="gemini-2.5-pro",
              instruction="Swahili-fluent support agent for codeAmani M-Pesa flows.", tools=[])
engine = client.agent_engines.create(agent_engine=AdkApp(agent=agent), config={
    "staging_bucket": "gs://codeamani-agents-staging",
    "requirements": ["google-cloud-aiplatform[agent_engines,adk]"],
})
print(engine.api_resource.name)

Eventing, scheduling & orchestration

Service Use case One-liner
Pub/Sub Async messaging / fan-out / decoupling gcloud pubsub topics create payments
Eventarc Route GCP events (e.g. GCS upload) → Cloud Run Trigger services from 90+ event sources
Cloud Tasks Reliable async task queues with rate-limit/retry Deferred work, outbound webhooks
Cloud Scheduler Cron-as-a-service gcloud scheduler jobs create http nightly --schedule="0 2 * * *"
Workflows Serverless orchestration of API/service steps YAML state machine across services

DevOps: build, registry, deploy, CI/CD

# cloudbuild.yaml — build, test, push, deploy to Cloud Run
steps:
  - { name: node:24, entrypoint: npm, args: [ci] }
  - { name: node:24, entrypoint: npm, args: [test] }
  - { name: gcr.io/cloud-builders/docker,
      args: [build, -t, "$_REGION-docker.pkg.dev/$PROJECT_ID/app/$_SVC:$COMMIT_SHA", .] }
  - { name: gcr.io/cloud-builders/docker,
      args: [push, "$_REGION-docker.pkg.dev/$PROJECT_ID/app/$_SVC:$COMMIT_SHA"] }
  - { name: gcr.io/google.com/cloudsdktool/cloud-sdk, entrypoint: gcloud,
      args: [run, deploy, "$_SVC", "--image=$_REGION-docker.pkg.dev/$PROJECT_ID/app/$_SVC:$COMMIT_SHA",
             "--region=$_REGION"] }
substitutions: { _SVC: my-api, _REGION: africa-south1 }
options: { logging: CLOUD_LOGGING_ONLY }

Networking (the essentials)

Service What it does
VPC Your private software-defined network; subnets are regional, the VPC is global
Cloud Load Balancing Global anycast L7/L4 LB with a single anycast IP
Cloud CDN Edge caching in front of the LB
Cloud Armor WAF + DDoS protection (rules, rate-limiting, geo)
Cloud DNS Managed authoritative DNS (100% SLA)

Security & Identity

IAM — every call is a permission check

Concept Meaning
Principal Who — user, group, service account, or federated workload identity
Role A permission bundle, e.g. roles/run.invoker, roles/bigquery.dataViewer
Binding A (principal, role, resource) triple — the grant itself
gcloud projects get-iam-policy PROJECT_ID
gcloud projects add-iam-policy-binding PROJECT_ID \
  --member="serviceAccount:claude-bot@PROJECT_ID.iam.gserviceaccount.com" \
  --role="roles/run.developer"

Least-privilege rules of thumb: predefined roles over roles/owner; bind at the narrowest scope (one bucket / one service, not the whole project); one service account per service.

Secret Manager — runtime secrets

gcloud secrets create DARAJA_KEY --data-file=./key.txt
gcloud secrets versions access latest --secret=DARAJA_KEY
# Mount straight into Cloud Run (never bake secrets into env vars/images):
gcloud run deploy my-api --update-secrets=DARAJA_KEY=DARAJA_KEY:latest

Workload Identity Federation — kill the JSON key

For GitHub Actions and other external CI, federate instead of downloading a service-account key:

# GitHub Actions — short-lived token, no long-lived secret to leak
- uses: google-github-actions/auth@v2
  with:
    workload_identity_provider: projects/123/locations/global/workloadIdentityPools/gh/providers/gh
    service_account: deployer@PROJECT.iam.gserviceaccount.com

See https://cloud.google.com/iam/docs/workload-identity-federation. Service-account JSON keys are radioactive — never commit, never ship to a client.

Cloud KMS — managed encryption keys

Customer-managed encryption keys (CMEK) for data you must control at rest — relevant for KDPA/compliance workloads.


Observability

gcloud logging read 'resource.type=cloud_run_revision severity>=ERROR' --limit 20 --freshness=1h

Cloud Shell (the browser terminal)

A free, pre-authed Debian VM at shell.cloud.google.com: gcloud, gsutil, bq, kubectl, docker, Node, Python; 5 GB persistent $HOME; web preview on port 8080.

gcloud cloud-shell ssh                                   # connect from your terminal
gcloud cloud-shell ssh --command "gcloud run deploy my-api --source ."   # deploy from an iPad

Claude Code integration

gcloud via the Bash tool (most reliable)

// .claude/settings.json
{ "permissions": { "allow": ["Bash(gcloud:*)", "Bash(gsutil:*)", "Bash(bq:*)"] } }

Community MCP server

GCP has no first-party MCP server; community servers wrap the SDK:

{ "mcpServers": { "gcp": { "command": "npx", "args": ["-y", "gcp-mcp"],
  "env": { "GOOGLE_APPLICATION_CREDENTIALS": "${GOOGLE_APPLICATION_CREDENTIALS}",
           "GOOGLE_CLOUD_PROJECT": "${GOOGLE_CLOUD_PROJECT}" } } } }

Slash command: analyze Cloud Run logs

<!-- .claude/commands/gcp-logs.md -->
Analyze recent Cloud Run logs for $ARGUMENTS.
Run: gcloud run services logs tail $ARGUMENTS --region africa-south1 --limit 50
Summarise errors, high-latency requests, and crash loops with root causes + fixes.

Environment variables

GOOGLE_CLOUD_PROJECT=my-project-id
GOOGLE_APPLICATION_CREDENTIALS=/path/to/sa.json   # local only; use ADC/WIF where possible
GOOGLE_CLOUD_REGION=africa-south1

Official learning resources

Train, don't guess. All first-party:

Resource What it is URL
Cloud Skills Boost Google's official courses + hands-on labs (free + paid) https://www.cloudskillsboost.google/
Google Cloud Codelabs Step-by-step build-along tutorials https://codelabs.developers.google.com/
Architecture Center Reference architectures + best-practice patterns https://cloud.google.com/architecture
Well-Architected Framework Design pillars (reliability, security, cost, ops) https://cloud.google.com/architecture/framework
Cloud certifications Associate Cloud Engineer → Professional tracks https://cloud.google.com/learn/certification
Free Tier + $300 trial Build for real at near-zero cost https://cloud.google.com/free
gcloud cheat sheet The 1-pager of essential commands https://cloud.google.com/sdk/docs/cheatsheet

Suggested path for a codeAmani dev: Free Tier sign-up → deploy a container to Cloud Run (Codelab) → wire Firestore + Secret Manager → add a Cloud Build pipeline → layer Vertex/Gemini → read the cost + security pillars of the Well-Architected Framework.


Troubleshooting

Issue Fix
gcloud: command not found Run gcloud init after install; restart shell
403 / API not enabled gcloud services enable <api>.googleapis.com then retry
ADC not configured gcloud auth application-default login
403 permission denied (after API enabled) Grant the role: gcloud projects add-iam-policy-binding …
Cloud Run cold starts --min-instances=1 for latency-sensitive endpoints
Surprise bill Egress / an always-on VM or Cloud SQL — set a budget alert day one
BigQuery quota error Check quotas at console.cloud.google.com/iam-admin/quotas
gcloud compute ssh hangs Open TCP 22: gcloud compute firewall-rules create allow-ssh --allow tcp:22
Agent Engine deploy fails on staging Bucket must exist + match the Agent Engine region
Cloud Shell config gone gcloud config is in a temp dir — persist under $HOME
GKE bill higher than expected The flat $0.10/hr/cluster fee + idle Standard nodes — use Autopilot or Cloud Run

codeAmani notes

Official docs: