Kubernetes on GKE: Operate the Managed Platform
Deck 2 of 7. Design, secure and operate production Kubernetes on Google Kubernetes Engine: Autopilot and Standard, VPC-native networking, Gateway API, identity, scaling, upgrades, storage, observability, cost, troubleshooting and a worked Shopwave migration.
Slides
Kubernetes on GKE
Cover for Kubernetes on GKE.
Deck 2 turns the Kubernetes API into a production GKE platform
The seven-deck course map.
GKE is Kubernetes plus managed control loops around it
A five-step GKE mental model.
Choose the operating boundary before the cluster
Module 1 orientation and key questions.
Google operates the control plane; Shopwave operates the service
Ownership comparison across Autopilot, Standard and RKE2.
Regional clusters keep the API available through a zonal failure
Regional and zonal topology choices.
Autopilot is the default answer until a requirement proves otherwise
Decision flow for Autopilot versus Standard.
Autopilot prices intent; Standard prices capacity
GKE billing models by operating mode.
Editions package capabilities; mode still defines infrastructure control
How GKE editions relate to modes and fleets.
Plan addresses before workloads arrive
Module 2 orientation and key questions.
VPC-native GKE gives nodes and Pods routable VPC identities
VPC-native address allocation model.
A 110-Pod node can reserve 256 Pod addresses
Worked Pod secondary-range sizing example.
Private nodes still need an explicit path to dependencies
Private-node egress and control-plane access flow.
Dataplane V2 turns Kubernetes intent into eBPF programs
Dataplane V2 reconciliation and packet flow.
NetworkPolicy closes Kubernetes' default-open east-west network
NetworkPolicy baseline for Shopwave.
Container-native load balancing removes the node hop
NEG-backed container-native load-balancing request path.
Internal and external load balancers solve different trust problems
Internal versus external GKE load balancing.
Gateway API separates infrastructure from routes
Module 3 orientation and key questions.
GatewayClass chooses infrastructure; HTTPRoute chooses application behavior
GKE Gateway API resource chain.
The GatewayClass name is an architecture decision
Current GKE GatewayClass selection matrix.
One HTTPS listener can route checkout and catalog by path
Worked Shopwave HTTPS Gateway design.
TLS and Cloud Armor protect the request before it reaches a Pod
Animated secured Gateway request path.
The config cluster is the single source of multi-cluster Gateway intent
Multi-cluster Gateway config-cluster flow.
Inference Gateway routes on model-serving signals, not round robin alone
GKE Inference Gateway concepts.
Give every workload a short-lived identity
Module 4 orientation and key questions.
Workload Identity Federation exchanges a Pod identity for a short-lived token
Workload Identity Federation for GKE token exchange.
IAM gets you to the cluster; RBAC limits what you can do inside it
IAM and Kubernetes RBAC mapping.
Shielded nodes verify the host; Binary Authorization verifies the release
Node integrity and image admission controls.
Secret Manager can deliver secrets without baking them into images
Secret Manager integration flow.
Sandbox, policy and posture tools answer different security questions
GKE Sandbox and posture tool responsibilities.
Scale workloads, nodes and change risk separately
Module 5 orientation and key questions.
Node pools isolate compute policy; Spot trades continuity for price
GKE node pool patterns including Spot.
ComputeClasses make infrastructure choice declarative
Custom ComputeClass and node pool auto-creation flow.
HPA creates demand; cluster autoscaling creates capacity
GKE workload-to-node autoscaling chain.
Release channels trade feature freshness for observation time
GKE release channel decision matrix.
Maintenance windows schedule change; exclusions create bounded freezes
Maintenance window and exclusion policy.
Surge upgrades add new capacity before draining old nodes
Animated GKE surge upgrade sequence.
Blue-green upgrades buy validation and rollback with temporary duplication
Surge versus blue-green node upgrades.
GKE deprecation insights are a warning, not a complete inventory
GKE deprecated API insight workflow.
Choose storage by semantics, not by product name
Module 6 orientation and key questions.
Persistent Disk is the default block choice; Hyperdisk adds tunable performance
Persistent Disk and Hyperdisk choices.
Filestore shares files; Cloud Storage FUSE exposes objects through file calls
Filestore and Cloud Storage FUSE comparison.
Backup for GKE restores workloads into a cluster that already exists
Backup for GKE backup and restore flow.
Storage selection is a workload contract
GKE storage decision guide.
Troubleshoot from Kubernetes symptom to cloud dependency
Module 7 orientation and key questions.
Cloud Operations combines platform signals with Prometheus metrics
GKE observability signal stack.
GKE cost allocation explains requested cost, not application value
GKE cost allocation workflow.
A Pending Pod tells you which constraint failed
GKE Pending Pod troubleshooting flow.
Quota and IP exhaustion look alike until you inspect the failed resource
Quota versus IP exhaustion diagnosis.
A failing admission webhook can block the entire API path
Admission webhook troubleshooting sequence.
The fastest GKE runbook moves from object to controller to cloud resource
Cross-layer GKE troubleshooting pattern.
Shopwave migrates by preserving contracts and redesigning edges
Module 8 orientation and key questions.
Shopwave chooses Autopilot regional GKE for the default path
Shopwave GKE migration decision record.
Fleets unify governance; specialized compute serves AI without changing the core
GKE fleet and AI workload expansion.
Use this GKE operating checklist before every production change
GKE production operations cheat sheet.
You are ready to operate GKE when you can explain every managed boundary
Final GKE recap checklist.
Quiz 1–3: architecture and networking
Quiz questions 1 to 3.
Quiz 4–6: Gateway and identity
Quiz questions 4 to 6.
Quiz 7–9: security and scaling
Quiz questions 7 to 9.
Quiz 10–12: upgrades and storage
Quiz questions 10 to 12.
Quiz 13–15: troubleshooting and synthesis
Quiz questions 13 to 15 and final score.