GCP Production Patterns
gcp-patterns
GCP production patterns: Cloud Run with Terraform, Workload Identity Federation (no service account keys), Cloud SQL with private IP, Memorystore Redis, BigQuery for analytics, Cloud Armor WAF, Secret Manager, VPC Service Controls, IAM least privilege bindings. Use when designing GCP architecture...
SKILL.md
Full skill instructions
GCP Production Patterns
When to Use This Skill
- Deploying containers to Cloud Run
- Setting up Workload Identity Federation (no SA keys)
- Configuring Cloud SQL with private IP
- Writing Terraform for GCP infrastructure
- Querying BigQuery for analytics
Core Principles
- Cloud Run for stateless services — autoscales to 0, no cluster management, pay per request
- Workload Identity Federation, never SA keys — SA keys are persistent credentials; WIF is token-based and short-lived
- Private IP for all data services — Cloud SQL, Memorystore: no public IP, accessed via VPC
- IAM bindings on resources, not members — bind roles to service accounts scoped to specific resources
- BigQuery for analytics over Cloud SQL — even 1B row aggregations run in <10 seconds on BigQuery
References available
references/compute-patterns.md— Cloud Run Terraform, Workload Identity Federation for GitHub Actions, IAM least privilege bindingsreferences/data-patterns.md— Cloud SQL private IP, Memorystore Redis, BigQuery partitioning and clustering, Secret Managerreferences/networking-patterns.md— VPC connector, Cloud Armor WAF, VPC Service Controls, load balancer setup
