certslothcertsloth
PCSE/Topic 06

Google Cloud / Professional

Secure Build, Release and Platform Automation

3 min read5 recall promptsReviewed 2026-10-09

Memory hook: Build once; attest it; promote the same artifact.

Must remember

Cloud Build executes builds/tests; Artifact Registry stores versioned artifacts; Cloud Deploy manages delivery to supported targets with releases, rollouts, approvals and promotion. Skaffold/Kustomize help render and deploy Kubernetes workloads. GitOps controllers reconcile declared state from version control; they still need trustworthy commits, restricted credentials and a recovery process.

Build once and promote an immutable digest through environments. Scanning identifies known vulnerabilities; provenance records origin and build process; signatures/attestations provide evidence; Binary Authorization can enforce configured deployment policy. SLSA describes supply-chain assurance levels. A clean vulnerability scan alone does not establish trusted provenance or absence of malicious logic.

Use short-lived workload federation for external automation where supported. Separate build, deploy and runtime identities; give each only needed permissions. Secret Manager stores secrets, Parameter Manager serves configuration use cases, and KMS manages cryptographic keys. Runtime secret injection avoids embedding credentials in images; build-time secrets can leak through layers, caches and logs.

Choose rolling, blue/green or canary release from capacity, reversibility and exposure needs. Define success metrics before shifting traffic, including latency/errors and business behavior. ML releases also need model/data quality and drift checks. Feature flags decouple code deployment from activation but create configuration/cleanup work. Database changes require backward-compatible migration if rollback to old code must work.

Bootstrap projects with reviewed Terraform/Infrastructure Manager or blueprints, remote state protection and policy checks. Config Connector manages supported resources through Kubernetes configuration; Helm packages Kubernetes resources. Separate production and temporary environments, enforce expiry/cleanup, and control fleet upgrades. Cloud Workstations offers managed developer environments; AI coding assistants still require review, tests and secret-handling discipline.

Review details

A useful release sequence is source review → repeatable build → unit/integration/security tests → digest and provenance → staging verification → approval where needed → progressive rollout → observed success or rollback. Configure trigger permissions and environment-specific identities as carefully as runtime IAM. Cloud Build logs and audit/deployment records establish which actor promoted which artifact.

Certificate Manager handles supported certificate-management needs, distinct from Secret Manager values and KMS key operations. Parameter Manager holds configuration. A GitOps controller continually reconciles desired state; manually patching production without changing its declared source can be reverted by the controller.

Choose under exam pressure

Requirement Choice and reason
Reproducible promotion Immutable artifact digest plus provenance.
Enforce trusted artifacts at deployment Binary Authorization policy and attestations.
External CI without long-lived keys Workload Identity Federation with scoped impersonation.

Traps

  • Cloud Build and Cloud Deploy have different responsibilities.
  • Rolling back code cannot automatically undo an incompatible database change.

Active recall

1. Why promote a digest?

It identifies the exact built artifact rather than a mutable tag.

2. What does provenance record?

The origin and process used to produce an artifact.

3. Why separate runtime and deploy identities?

Their required privileges and compromise impact differ.

4. When is a canary useful?

To expose a limited audience, measure success and stop/rollback before wider impact.

5. Why is generated code not automatically trusted?

It can contain defects, unsafe dependencies or exposed secrets and still needs normal review.

Sources

CLOSE THE NOTES. EXPLAIN THE CHOICE.

How well could you recall it?

Your next review is based on this answer. Progress stays in this browser.

Search across every published topic.