Skip to content

Blog

Features in Google Cloud for Securing Virtual Machines(VMs)

Shielded VMs use verification on hardware IDs and chips to defend against Linux bootkits and rootkits. They also provide self-healing security features such as integrity monitoring and healing.

It uses Secure Boot, Virtual trusted platform module(vTPM)-enabled Measured Boot, and Integrity monitoring.

You can monitor your VMs in a few ways with Shielded VMs:

  • You can monitor the boot integrity of shielded VMs with cloud monitoring.
  • You can automatically take action on integrity failures with cloud functions.

These Virtual Machines use encryption-in-use and encrypt the data in memory. You provision this type of VM with the type N2D:

  • n2d-standard-2
  • n2d-standard-4
  • n2d-standard-8
  • n2d-standard-16
  • n2d-standard-32
  • n2d-standard-48
  • n2d-standard-64
  • n2d-standard-80
  • n2d-standard-96
  • n2d-standard-128
  • n2d-standard-224

VPC Service Controls can define perimeters around sets of services within a VPC and can have their access limited. Traffic that crosses perimeters have Ingress and Egress rules. This affords us the following benefits:

  • Unauthorized networks with stolen credentials are blocked
  • Data exfiltration blocked.
  • Safety net for misconfigured over-permissive IAM policies.
  • Honeypot perimetering and additional monitoring.
  • Extend perimeters to on-premiss networks
  • Context-aware access to resources

image

Comparison of Google Cloud Database Options

There are many pros to using Bigtable: it handles large amounts of data, scales up or down as needed, and supports a variety of data types. Additionally, Bigtable is designed to be highly available and can provide near-real-time access to data, resizing without downtime, with simple administration and scalability.

BigQuery is a powerful tool that can handle large amounts of data efficiently. It is also easy to use and has many features that make it a good fit for data analysis. On the downside, BigQuery can be expensive to use, and it can be challenging to get started if you are not familiar with it.

Google Cloud SQL is fully managed, flexible, automatically replicated across multiple zones, encrypted at rest and in transit, automatic updates.

Cloud Spanner uses TrueTime to execute the same query on multiple regions to ensure consistency. If your data needs to be consistent and cannot wait for replication, choose Cloud Spanner.

Running a database cluster on Compute VM, you take all the management upon yourself. If you select the wrong compute sizes, either too big or too small, you run risks of rising costs or falling performance.

ProductRelationalStructuredUnstructuredHeavy R/WLow LatencyGlobal Consistency
Bigtable🔴🟢🟢🟢🟢🔴
BigQuery🟢🟢🟢✝🔴✝✝🔴🔴
Cloud Firestore🔴🔴🟢🔴🔴🔴
Firebase Realtime Database🟢🟢🟢✝🔴✝✝🔴🟢
Cloud SQL🟢🟢🟢🔴🔴🔴
Cloud Spanner🟢🟢🔴🔴🔴🟢
Compute VM🟢🟢🟢🔴🔴🔴
SymbolMeaning
🟢Yes
🔴No
Semi Unstructured Data with the Json type
✝✝Read / Append Only

Comparison of Standard and Flexible App Engine Environments

Table of App Engine Distinguishing Features

Section titled “Table of App Engine Distinguishing Features”
ProductAccess GCP ServicesAny LanguageScalingScale to ZeroBackground threadsBackground ProcessesModify the RuntimeWebsocketsWrite to Disk
Standard🔴🔴🟢🟢🟢🔴🔴🔴Java: /tmp
Flexible🟢🟢🟢🔴🟢🟢🟢🟢🟢
SymbolMeaning
🟢Yes
🔴No

Contrasting Preemptible and Spot Virtual Machines(VMs)

Table of Preemptible vs Spot Distinguishing Features

Section titled “Table of Preemptible vs Spot Distinguishing Features”
ProductUnlimited Runtimepreemptive deletepreemptive pauseSLA CoverageCost ReductionMigrate to Standard VMRestart on EventLive Migration
Preemptible VMs🔴🔴🟢🔴🟢🔴🔴🔴
Spot VMs🟢🟢🟢🔴🟢🔴🔴🔴
SymbolMeaning
🟢Yes
🔴No

Differences in Google Cloud Platform(GCP) Premium Network Tiers

This tier uses more resources to think out the best route. This tier has more than 100 Points-of-Presence(PoP) which lets the packets leave Google’s network nearest to the customer. Packets use a more direct route a “cold potato” algorithm. This Tier support global load balancers.

Using the “Hot Potato” method, the Standard Tier network tries rid itself of the packet by sending it to the earliest responding route. This is a less direct path and may not egress through a PoP as near to the destination. This Tier can only support Load Balancers which are regional.

ProductGlobal LBPoP Closest HopNext Hop AlgorythmHigh PerformanceInter-Regional TrafficCloud CDNCloud VPN/Router
Premium🟢🟢Cold Potato🟢Google Network🟢🟢
Standard🔴🔴Hot PotatoStandard ISPEncrypted over Public ISPs🔴🔴
SymbolMeaning
🟢Yes
🔴No

GCP Network Tier Decision Tree