Reviewed 10 October 2026. Use the linked official exam guide for your exam version. These are condensed revision notes; the topic pages provide worked distinctions and more recall practice. Google’s 2026 guides use newer Gemini Enterprise Agent Platform names while some APIs and documentation still use Vertex AI.
Memory hook: Design contracts → build once → deploy safely → diagnose by caller and trace.
1. Design scalable, secure applications — 1.1–1.3
Cloud Run fits supported request/event containers, GKE Kubernetes-specific needs, Compute Engine OS/hardware control. Plan region/failure scope, CPU/memory, startup, concurrency and downstream limits. A session must survive instance replacement: externalize durable state; session affinity is not persistence. Caching needs TTL/invalidation and a source of truth.
REST/HTTP and gRPC have different wire contracts; version schemas and error behavior. API Gateway provides gateway capabilities; Apigee addresses broader enterprise API lifecycle/policy. Apply authentication, authorization, rate limits and observability at every boundary.
| Requirement | Service pattern |
|---|---|
| Independent event subscribers | Pub/Sub with safe acknowledgments, retries and deduplication |
| A known endpoint needs controlled task dispatch/rate | Cloud Tasks |
| Ordered API steps and branching | Workflows |
| Clock-based trigger | Cloud Scheduler |
| Route supported event types | Eventarc |
Use Cloud SQL/AlloyDB for suitable relational access, Spanner for scalable consistent transactions, Firestore documents, Bigtable key/range patterns and BigQuery analytics. Cloud Storage object read/write/list operations are strongly consistent; public caches and IAM propagation are distinct. Bigtable multi-cluster replication and relational read replicas require attention to lag/consistency. Use generation preconditions/transactions to prevent conflicting writes where supported.
ADC finds credentials; it does not grant permissions. Use attached workload identity or federation; OAuth access tokens call supported APIs, audience-bound ID tokens authenticate supported service invocations. Verify issuer/audience/expiry/signature. Identity Platform handles application-user identity; it is not the same principal as the runtime service account. Cloud SQL/AlloyDB auth connectors simplify supported authentication/TLS but do not create missing network routes. Secret Manager stores secrets; KMS controls cryptographic keys. Enforce least privilege, private paths where needed, scanning, SCC findings and Binary Authorization. Retention locks can be irreversible.
2. Build and test — 2.1–2.3
Configure CLI project/account and ADC intentionally. Cloud Shell offers managed command tools; Cloud Workstations offers controlled developer environments. Cloud Code, coding assistants and MCP tools still need scoped access and review. Emulators test supported behavior without proving production IAM, quotas or all service differences.
Cloud Build runs tests/builds under its build identity; Artifact Registry stores the resulting digest. Record provenance, scan dependencies and promote the same artifact. Unit tests isolate logic; integration tests exercise real contracts; end-to-end tests verify users. Include permission denial, retry duplicates, failed dependencies, schema compatibility and generated-code failures. Never put secrets in source, image layers or logs.
3. Deploy and scale — 3.1–3.2
For Cloud Run, confirm listening port, runtime service account, ingress, invoker permission, resource settings, concurrency, scaling and secret access. A new revision is not automatically a successful production rollout. Split traffic, watch user metrics, then promote or roll back. Eventarc/Pub/Sub needs the trigger/delivery identity to call the receiver. Maximum instances and bounded connection pools protect database capacity.
For GKE, image access → correct context/namespace → Deployment → Service/Gateway → probes → requests/autoscaling. Readiness controls traffic eligibility, liveness restarts, startup protects slow initialization. HPA changes replicas; requests and available node resources govern whether they can run. Use graceful termination and disruption-aware rollouts; an aggressive liveness check can amplify dependency failures.
4. Integrate and observe — 4.1–4.3
Enable APIs, identify the caller/project, use supported libraries/REST/gRPC, paginate responses, request needed fields and batch only supported operations. Bound exponential backoff with jitter for retryable failures; do not retry permission denials indefinitely or repeat unsafe writes blindly. Pool database connections and size total pools across maximum instances.
Acknowledge after durable processing; failed attempts need idempotent keys and a dead-letter path. Propagate trace context through service and message boundaries. Logging explains events, Monitoring quantifies symptoms, Trace identifies slow spans, Error Reporting groups failures, profiling finds resource-heavy code. Correlate errors with revision/digest and dependencies; AI diagnostics are hypotheses to verify.
Traps to catch
- Invoker, deployer and runtime identity are different. A private endpoint still needs authorization.
- Local memory and affinity do not survive replacement; code rollback may fail after incompatible data migration.
- A successful HTTP acknowledgment before durable work can lose a business event.
Last-pass self-check
1. Which token is typically used for authenticated Cloud Run service invocation?
An ID token with the expected audience where required; distinguish it from an OAuth access token used for Google APIs.
2. The backend can accept 100 connections and each instance opens 20. What must scaling consider?
Total pools across concurrent instances plus operational headroom; adding instances without limiting pools can overwhelm the database.
3. Which probe should fail when a Pod must stop receiving traffic but need not restart?
Readiness.
4. Why not automatically retry every failed payment request?
The original side effect may have succeeded; use idempotency and determine whether the failure is retryable.
5. A public object still looks old after a successful overwrite. What else besides storage consistency matters?
Cache-Control/CDN/browser cache behavior; storage read-after-write consistency does not instantly invalidate every cache.
Sources
- Official exam guide
- Published objective groups (PDF)
- Cloud Storage consistency
- Service authentication
- Cloud Tasks overview
- Cloud Run deployment
Every topic at a glance
Open any topic to revisit its essential facts, decisions and exam traps. Use the full topic for active recall and supporting references.
01 · Application design and data contracts
Memory hook: Stateless compute, explicit state, bounded work.
Must remember
- Choose Cloud Run for managed request/event containers, GKE for Kubernetes control and Compute Engine for VM-level requirements. Compare region, availability, scaling limits, startup time and operational effort.
- Keep durable state outside disposable instances. Session affinity can improve locality but should not be the only way a user session survives a restart; Memorystore can cache or externalize suitable session state.
- Define REST/gRPC contracts, authentication, rate limits, versioning and error behavior. API Gateway provides managed gateway capabilities; Apigee addresses broader API lifecycle and enterprise policy needs.
- Use Pub/Sub for decoupled messaging, Cloud Tasks for controlled task dispatch, Workflows for orchestration and Scheduler for time triggers. Eventarc connects matching events to receivers.
- Select schemas and stores from access patterns: relational joins and transactions, document access, row-key scans or analytical queries. Understand the selected service’s consistency and replication behavior.
- Signed Cloud Storage URLs grant time-limited access to a specific operation/resource. Treat them as bearer capabilities and keep sensitive URLs out of logs; retention locks can be irreversible.
Review details
Cloud Tasks dispatches work to a selected endpoint with controlled scheduling/rate and retries; Pub/Sub decouples publishers from independent subscribers. Neither guarantees exactly-once business effects without the application design. Use a stable operation ID for repeated requests and acknowledge only after durable work.
Cloud Storage object reads/writes/listing are strongly consistent, but public caches and permission propagation have separate behavior. Relational asynchronous replicas can lag; Bigtable multi-cluster routing must be chosen with consistency needs in mind. Use the service's transactions/preconditions to protect invariants instead of assuming all managed storage has identical semantics.
Choose under exam pressure
| Requirement | Choice and reason |
|---|---|
| An HTTP container should scale with traffic | Cloud Run with deliberate concurrency, limits and state handling. |
| A workflow must call several APIs with retries | Workflows with bounded retries and idempotent steps. |
Traps
- Session affinity does not make local memory durable.
- Asynchronous delivery can still duplicate a business operation unless the consumer is designed safely.
02 · Application identity and secure delivery
Memory hook: No embedded keys; authorize every boundary.
Must remember
- Application Default Credentials locate credentials from the execution environment; they are not a permission grant. Use attached service accounts in managed runtimes and Workload Identity Federation for supported external/Kubernetes identities.
- Use OAuth access tokens for supported APIs and audience-bound ID tokens for authenticated service invocation where required. Verify JWT issuer, audience, expiry and signature rather than only decoding it.
- Secret Manager stores versioned secrets; Cloud KMS manages cryptographic keys. Rotate credentials with client coordination and grant only the required secret versions/operations.
- IAP provides identity-aware access to supported applications. Private connectivity, Direct VPC egress, service mesh and Kubernetes NetworkPolicy address different network layers; none replaces application authorization.
- Scan dependencies and container images with supported artifact/security tools. Binary Authorization can enforce deployment policies based on attestations and trusted build evidence.
- Use organization and retention policies intentionally, constrain service identities, and validate input/output at every external boundary. AI-generated code and MCP tools require the same review and privilege limits as other code.
Choose under exam pressure
| Requirement | Choice and reason |
|---|---|
| A CI system outside Google needs short-lived access | Workload Identity Federation instead of a downloaded service-account key. |
| Only approved images may deploy | Trusted build attestations and Binary Authorization policy. |
Traps
- ADC does not mean credentials have the correct role.
- An internal endpoint can still be called by an overprivileged compromised workload.
03 · Build and test reproducible artifacts
Memory hook: One reviewed source, one traceable artifact.
Must remember
- Use Cloud Shell for a managed command environment and Cloud Workstations for controlled development environments. Configure the CLI project/account deliberately; local emulators help test supported services without production data.
- Cloud Code and coding assistants speed development but must operate within scoped repositories and tool permissions. Review generated changes, tests and dependencies before accepting them.
- Cloud Build executes build steps under a service identity; Artifact Registry stores versioned artifacts. Prefer immutable digests in deployment rather than a mutable latest tag.
- Build provenance links an artifact to source and build process. Signing/attestation and Binary Authorization enforce trust at different stages; provenance alone does not prove the source is safe.
- Unit tests isolate logic; integration tests verify real service contracts; end-to-end tests exercise user outcomes. Include failure paths, authorization, retry safety and backward compatibility.
- Keep secrets out of source, image layers and logs. Separate development/test/production projects and use explicit promotion of tested artifacts with rollback history.
Choose under exam pressure
| Requirement | Choice and reason |
|---|---|
| A bug appears only with a real database | Integration tests against an isolated representative service. |
| Need to prove which source produced an image | Build provenance tied to the artifact digest. |
Traps
- A passing emulator test is not proof that every production IAM or quota setting works.
- Rebuilding source independently in each environment can produce different artifacts.
04 · Deploy and scale Cloud Run and GKE
Memory hook: Healthy, authorized, reachable, reversible.
Must remember
- Cloud Run can build from source or deploy a container. Configure the listening port, runtime identity, ingress, invoker permissions, concurrency, resource limits and minimum/maximum instances.
- Eventarc or Pub/Sub invocation needs both a correctly configured receiver and authorized delivery identity. A deployed service is not necessarily publicly callable.
- Cloud Run revisions support traffic migration and rollback. Set maximum instances with downstream connection limits in mind; retries can multiply traffic during an outage.
- GKE Deployments manage replicas and rolling updates; Services provide stable access; Gateway/Ingress expose appropriate traffic. Resource requests influence scheduling and autoscaling.
- Readiness controls traffic eligibility; liveness restarts an unhealthy container; startup probes protect slow initialization. An aggressive liveness probe can turn dependency slowness into a restart storm.
- Horizontal Pod Autoscaler adjusts replicas from supported metrics; node capacity must also exist. Use controlled rollout checks, graceful termination and durable external state.
Choose under exam pressure
| Requirement | Choice and reason |
|---|---|
| A process starts slowly but then works | A suitable startup probe rather than repeated liveness failures. |
| Reduce deployment risk | Shift a small traffic share, compare errors/latency, then promote or roll back. |
Traps
- A ready pod and a healthy external load balancer are separate checks.
- Increasing replicas can overload a database that cannot accept more connections.
05 · Integrations and production diagnosis
Memory hook: Bound the call; follow the trace.
Must remember
- Use supported client libraries, REST or gRPC with an enabled API, correct project, service identity and quota. Paginate large result sets, request only necessary fields, batch supported work and cache safe responses.
- Handle transient errors with bounded exponential backoff and jitter. Respect retry guidance; do not blindly retry non-idempotent writes or permanent permission failures.
- Manage database pools and transaction boundaries explicitly. Acknowledge messages after successful durable processing; design deduplication and dead-letter handling for repeated failures.
- Log structured request identifiers, outcomes and safe diagnostic context. Propagate trace context across HTTP and messaging boundaries so spans can reveal the slow dependency.
- Cloud Logging explains events, Monitoring quantifies behavior, Trace follows request latency and Error Reporting groups failures. Correlate them instead of selecting a tool solely by product name.
- Measure user-relevant latency/error SLOs and dependency saturation. AI-assisted diagnostics can suggest hypotheses, but validate them against telemetry and controlled changes.
Choose under exam pressure
| Requirement | Choice and reason |
|---|---|
| A request is slow across several services | Distributed traces correlated with logs and dependency metrics. |
| API returns a transient quota-related failure | Inspect quotas and rate, then apply bounded retry/backoff when appropriate. |
Traps
- Retrying a denied request repeatedly does not fix IAM.
- Logging full request bodies can expose secrets or personal data.