Deploying Data and Networking Resources with IaC Automation

Deploy Cloud SQL, BigQuery, Cloud Storage; configure VPC, load balancers, Cloud Interconnect; use Marketplace; automate with Terraform — six GCP-ACE domains from an operational perspective.

Deployment Is Where Operations Begin

The moment you provision your first Google Cloud infrastructure, the real challenge starts. Bringing up a database, connecting networks, and accepting external traffic are not isolated tasks — they form a tightly interlocked flow. As data accumulates you must adjust storage classes. As traffic grows you must tune load balancers and firewall rules. When hybrid connectivity becomes a requirement you must choose between Cloud Interconnect and Cloud VPN. When the same environment needs to be provisioned repeatedly for multiple teams, you need a Terraform pipeline.

The "Deploying and Implementing" domain of the ACE exam does not ask how to create resources. It asks which service to choose under which constraints. This post compresses six sub-domains — data solution deployment, networking resource deployment, load balancers, Marketplace, IaC, and in-life configuration changes — into scenario-driven decision frameworks.

---

 

Deploying Data Resources: Cloud SQL, BigQuery, and Cloud Storage

Cloud SQL delivers MySQL, PostgreSQL, and SQL Server as fully managed engines. When configured for high availability, a standby instance is automatically provisioned in a different zone within the same region, and automatic failover triggers on instance failure. Read replicas distribute read load, but they also replicate data corruption — so for data protection you must rely on automated backups and Point-in-time Recovery (PITR), not replicas.

| Cloud SQL Feature | Purpose | Caveat | |---|---|---| | Read Replica | Distribute read workload | Also replicates corruption — not a protection mechanism | | HA (High Availability) | Automatic recovery from instance failure | Guards against zonal failure | | Automated Backup + PITR | Restore to a specific point in time | Up to 7 days of rollback |

BigQuery is a serverless OLAP engine. To estimate query costs before execution under the on-demand pricing model, use the flag. A dry run returns only the number of bytes the query would process — it does not execute the query and incurs no charges. Do not confuse EXPLAIN with dry run: EXPLAIN is for analyzing execution plans, not estimating costs. To analyze BigQuery data without SQL, connect via Connected Sheets or Looker Studio. To query files stored in Cloud Storage directly, create an External Table.

Cloud Storage storage classes and Object Lifecycle policies appear on the exam repeatedly.

| Storage Class | Minimum Duration | Access Frequency | Typical Use Case | |---|---|---|---| | Standard | None | Frequent | Active data, web serving | | Nearline | 30 days | Less than once per month | Monthly backups | | Coldline | 90 days | Less than once per quarter | Compliance archives | | Archive | 365 days | Less than once per year | Long-term log retention |

Object Lifecycle rules automatically transition objects to cheaper classes or delete them after a configured age. Retention Policy is a deletion-lock feature — distinct from Object Lifecycle, which handles transitions and deletions. For time-limited external sharing of objects, use Signed URLs.

---

 

Deploying Networking Resources: VPC, Cloud NAT, Cloud VPN, and Cloud Interconnect

GCP VPC is a global resource. A single VPC can span subnets across multiple regions. Subnet primary IP ranges can be expanded but cannot be shrunk. To allow VMs without external IPs to reach Google APIs, enable Private Google Access on the subnet.

Firewall rules control ingress and egress traffic based on network tags or service accounts. Lower numeric priority values are evaluated first. Within a single VPC, isolating services using subnet segmentation plus tag-based firewall rules is the correct approach — it enforces isolation without altering the existing topology. For internal communication between VPCs in different projects, use VPC Network Peering, but remember that peering is non-transitive: if A peers with B and B peers with C, A and C cannot communicate unless explicitly peered.

| Hybrid Connectivity | Path | Max Bandwidth | Key Characteristic | |---|---|---|---| | Cloud VPN (HA) | Public internet (IPsec) | 3 Gbps per tunnel | BGP dynamic routing | | Dedicated Interconnect | Private physical circuit | 200 Gbps | SLA 99.9%+, no internet transit | | Partner Interconnect | Via partner provider | 50 Mbps – 10 Gbps | Dedicated-line effect without colocation |

Cloud NAT exposes a stable NAT IP to the internet regardless of changes to underlying VM IPs. Scenarios that simultaneously require high-throughput transfers and a fixed egress IP for allowlist management are best served by pairing Dedicated Interconnect with Cloud NAT. To protect public Cloud DNS zones against DNS response spoofing, enable DNSSEC.

---

 

Configuring Load Balancers and Backend Services

Selecting the right GCP load balancer depends on the OSI layer (L4 vs. L7) and the scope (global vs. regional).

| Load Balancer Type | Layer | Scope | Key Characteristics | |---|---|---|---| | External HTTP(S) LB | L7 | Global | Anycast IP, CDN and Armor integration, multi-region failover | | External Network LB | L4 | Regional | UDP/TCP passthrough, lowest latency | | Internal HTTP(S) LB | L7 | Regional | HTTP distribution between microservices inside a VPC | | Internal TCP/UDP LB | L4 | Regional | TCP/UDP inside a VPC |

The global external HTTP(S) load balancer integrates with Google-managed SSL certificates to fully automate certificate renewal. Backend Services define the instance groups or Network Endpoint Groups (NEGs) that receive traffic, and health checks automatically remove unhealthy instances from rotation. Reserving a static external IP for the load balancer frontend locks the IP address so backends can be replaced without updating DNS records.

Exam trap: when a scenario demands global Anycast, CDN integration, or multi-region failover, a regional network load balancer is wrong. You must select the global external HTTP(S) load balancer.

---

 

Getting Started Fast with Marketplace

Google Cloud Marketplace is a catalog of pre-configured solutions deployable in a few clicks. Open-source stacks such as Cassandra, WordPress, and Jenkins come bundled with licensing, VM configuration, and network setup.

| Marketplace Deployment Type | Description | |---|---| | VM Image Solution | Compute Engine VM with pre-installed software; software licensing may be billed separately | | Kubernetes App | Helm chart deployed to a GKE cluster | | Terraform Module | IaC-based, code reusable | | SaaS Subscription | Externally vendor-managed service |

When you select a Marketplace solution and supply only the project, region, and machine type, the VPC, firewall rules, and VM are created automatically. On the exam, when you see the keywords "minimize operational overhead" combined with "rapidly deploy a proven solution," Marketplace is the answer. For fine-grained customization or repeatable, code-managed deployments, Terraform is the better fit.

---

 

Infrastructure as Code: Deployment Manager, Config Connector, and Terraform

IaC is the practice of declaring infrastructure as version-controlled code.

| Tool | Language | Coverage | Primary Use Case | |---|---|---|---| | Deployment Manager | YAML / Jinja2 / Python | GCP only | Legacy GCP environments | | Config Connector | YAML (K8s CRD) | GCP (GKE-based) | GKE GitOps integration | | Terraform | HCL | Multi-cloud | Standard for new projects |

Deployment Manager supports the flag to show changes before they are applied. It is GCP-native but lacks multi-cloud support and has a smaller community ecosystem.

Terraform is the IaC tool that appears most frequently in ACE exam scenarios. Use to preview changes and to apply them. Terraform is idempotent — running the same code multiple times always produces the same result — which makes repeated deployments safe. Storing Terraform code in Cloud Source Repositories and connecting it to Cloud Build triggers enables automatic plan and apply runs on every pull request merge. Cloud Foundation Toolkit (CFT) is a curated collection of validated Terraform modules for quickly applying org policies, VPC defaults, and IAM baselines.

!3 IaC tools on GCP

For scenarios that require repeatedly provisioning a standard environment — VPC, Cloud SQL, IAM policies, Cloud Storage buckets — across multiple teams, Terraform combined with a Cloud Build pipeline is the correct answer.

---

 

In-Life Changes: Lifecycle Policies, Permissions, and Firewall Rules

This section covers the operational change scenarios that appear most frequently after initial deployment.

Cloud Storage Object Lifecycle policies can be added or modified on existing buckets at any time and apply retroactively to existing objects. For fine-grained per-object access control, use ACLs — but enabling Uniform bucket-level access disables ACLs and consolidates access control under IAM exclusively.

Change Data Capture (CDC) for Cloud SQL integrates with Datastream. Datastream reads the binary log and streams row-level change events to Pub/Sub or Cloud Storage. Automating scheduled backups without managing servers is cleanly implemented using Cloud Scheduler combined with Cloud Functions.

Running a Dataproc cluster continuously for batch jobs that execute only once or twice a month wastes money on idle resources. The cost-optimal pattern is to create a cluster only when a job is needed and delete it immediately upon completion — the ephemeral cluster pattern. To prevent in-progress tasks from being forcibly terminated during scale-down, use Graceful Decommissioning.

| Operational Change | Method | Caveat | |---|---|---| | Add Cloud Storage lifecycle policy | gsutil lifecycle set | Applies retroactively to existing objects | | Add Cloud SQL read replica | Console / gcloud | Replicas are not a data protection mechanism | | Modify firewall rule | gcloud compute firewall-rules update | Verify priority conflicts | | Set static Cloud NA

Back to blog list