HTML Deck

Kubernetes on GKE: Operate the Managed Platform

Deck 2 of 7. Design, secure and operate production Kubernetes on Google Kubernetes Engine: Autopilot and Standard, VPC-native networking, Gateway API, identity, scaling, upgrades, storage, observability, cost, troubleshooting and a worked Shopwave migration.

61 slides16:9 widescreenHTML + CSS + JSGoogle Blue, Teal, Amber & Violet
Live preview

Slides

01Preview slide

Kubernetes on GKE

Cover for Kubernetes on GKE.

02Preview slide

Deck 2 turns the Kubernetes API into a production GKE platform

The seven-deck course map.

03Preview slide

GKE is Kubernetes plus managed control loops around it

A five-step GKE mental model.

04Preview slide

Choose the operating boundary before the cluster

Module 1 orientation and key questions.

05Preview slide

Google operates the control plane; Shopwave operates the service

Ownership comparison across Autopilot, Standard and RKE2.

06Preview slide

Regional clusters keep the API available through a zonal failure

Regional and zonal topology choices.

07Preview slide

Autopilot is the default answer until a requirement proves otherwise

Decision flow for Autopilot versus Standard.

08Preview slide

Autopilot prices intent; Standard prices capacity

GKE billing models by operating mode.

09Preview slide

Editions package capabilities; mode still defines infrastructure control

How GKE editions relate to modes and fleets.

10Preview slide

Plan addresses before workloads arrive

Module 2 orientation and key questions.

11Preview slide

VPC-native GKE gives nodes and Pods routable VPC identities

VPC-native address allocation model.

12Preview slide

A 110-Pod node can reserve 256 Pod addresses

Worked Pod secondary-range sizing example.

13Preview slide

Private nodes still need an explicit path to dependencies

Private-node egress and control-plane access flow.

14Preview slide

Dataplane V2 turns Kubernetes intent into eBPF programs

Dataplane V2 reconciliation and packet flow.

15Preview slide

NetworkPolicy closes Kubernetes' default-open east-west network

NetworkPolicy baseline for Shopwave.

16Preview slide

Container-native load balancing removes the node hop

NEG-backed container-native load-balancing request path.

17Preview slide

Internal and external load balancers solve different trust problems

Internal versus external GKE load balancing.

18Preview slide

Gateway API separates infrastructure from routes

Module 3 orientation and key questions.

19Preview slide

GatewayClass chooses infrastructure; HTTPRoute chooses application behavior

GKE Gateway API resource chain.

20Preview slide

The GatewayClass name is an architecture decision

Current GKE GatewayClass selection matrix.

21Preview slide

One HTTPS listener can route checkout and catalog by path

Worked Shopwave HTTPS Gateway design.

22Preview slide

TLS and Cloud Armor protect the request before it reaches a Pod

Animated secured Gateway request path.

23Preview slide

The config cluster is the single source of multi-cluster Gateway intent

Multi-cluster Gateway config-cluster flow.

24Preview slide

Inference Gateway routes on model-serving signals, not round robin alone

GKE Inference Gateway concepts.

25Preview slide

Give every workload a short-lived identity

Module 4 orientation and key questions.

26Preview slide

Workload Identity Federation exchanges a Pod identity for a short-lived token

Workload Identity Federation for GKE token exchange.

27Preview slide

IAM gets you to the cluster; RBAC limits what you can do inside it

IAM and Kubernetes RBAC mapping.

28Preview slide

Shielded nodes verify the host; Binary Authorization verifies the release

Node integrity and image admission controls.

29Preview slide

Secret Manager can deliver secrets without baking them into images

Secret Manager integration flow.

30Preview slide

Sandbox, policy and posture tools answer different security questions

GKE Sandbox and posture tool responsibilities.

31Preview slide

Scale workloads, nodes and change risk separately

Module 5 orientation and key questions.

32Preview slide

Node pools isolate compute policy; Spot trades continuity for price

GKE node pool patterns including Spot.

33Preview slide

ComputeClasses make infrastructure choice declarative

Custom ComputeClass and node pool auto-creation flow.

34Preview slide

HPA creates demand; cluster autoscaling creates capacity

GKE workload-to-node autoscaling chain.

35Preview slide

Release channels trade feature freshness for observation time

GKE release channel decision matrix.

36Preview slide

Maintenance windows schedule change; exclusions create bounded freezes

Maintenance window and exclusion policy.

37Preview slide

Surge upgrades add new capacity before draining old nodes

Animated GKE surge upgrade sequence.

38Preview slide

Blue-green upgrades buy validation and rollback with temporary duplication

Surge versus blue-green node upgrades.

39Preview slide

GKE deprecation insights are a warning, not a complete inventory

GKE deprecated API insight workflow.

40Preview slide

Choose storage by semantics, not by product name

Module 6 orientation and key questions.

41Preview slide

Persistent Disk is the default block choice; Hyperdisk adds tunable performance

Persistent Disk and Hyperdisk choices.

42Preview slide

Filestore shares files; Cloud Storage FUSE exposes objects through file calls

Filestore and Cloud Storage FUSE comparison.

43Preview slide

Backup for GKE restores workloads into a cluster that already exists

Backup for GKE backup and restore flow.

44Preview slide

Storage selection is a workload contract

GKE storage decision guide.

45Preview slide

Troubleshoot from Kubernetes symptom to cloud dependency

Module 7 orientation and key questions.

46Preview slide

Cloud Operations combines platform signals with Prometheus metrics

GKE observability signal stack.

47Preview slide

GKE cost allocation explains requested cost, not application value

GKE cost allocation workflow.

48Preview slide

A Pending Pod tells you which constraint failed

GKE Pending Pod troubleshooting flow.

49Preview slide

Quota and IP exhaustion look alike until you inspect the failed resource

Quota versus IP exhaustion diagnosis.

50Preview slide

A failing admission webhook can block the entire API path

Admission webhook troubleshooting sequence.

51Preview slide

The fastest GKE runbook moves from object to controller to cloud resource

Cross-layer GKE troubleshooting pattern.

52Preview slide

Shopwave migrates by preserving contracts and redesigning edges

Module 8 orientation and key questions.

53Preview slide

Shopwave chooses Autopilot regional GKE for the default path

Shopwave GKE migration decision record.

54Preview slide

Fleets unify governance; specialized compute serves AI without changing the core

GKE fleet and AI workload expansion.

55Preview slide

Use this GKE operating checklist before every production change

GKE production operations cheat sheet.

56Preview slide

You are ready to operate GKE when you can explain every managed boundary

Final GKE recap checklist.

57Preview slide

Quiz 1–3: architecture and networking

Quiz questions 1 to 3.

58Preview slide

Quiz 4–6: Gateway and identity

Quiz questions 4 to 6.

59Preview slide

Quiz 7–9: security and scaling

Quiz questions 7 to 9.

60Preview slide

Quiz 10–12: upgrades and storage

Quiz questions 10 to 12.

61Preview slide

Quiz 13–15: troubleshooting and synthesis

Quiz questions 13 to 15 and final score.