Architecture guides
| Technology category | Brief description | Line hints |
|---|---|---|
| Fundamentals | Design guides, reference architectures, and best practices for foundational cloud architectures, landing zones, and deployment archetypes. | Lines 19-46 |
| AI and ML | Design guides, reference architectures, and best practices for AI, MLOps, generative AI, and agentic workflows. | Lines 47-95 |
| Application development | Design guides, reference architectures, and best practices for building, deploying, and running applications in the cloud. | Lines 96-125 |
| Security, privacy, and compliance | Design guides, reference architectures, and best practices for security, privacy, and compliance. | Lines 126-195 |
| Reliability and disaster recovery | Design guides, reference architectures, and best practices for reliability and disaster recovery. | Lines 196-217 |
| Data and analytics | Design guides, reference architectures, and best practices for data warehousing, data mesh, data analytics, and data streaming. | Lines 218-233 |
| Databases | Design guides, reference architectures, and best practices for planning and implementing databases for cloud workloads. | Lines 234-254 |
| Migration | Methodologies, assessment frameworks, and guides for migrating VMs, databases, and applications to Google Cloud. | Lines 255-281 |
| Networking | Design guides, reference architectures, and best practices for planning and implementing networking for cloud workloads. | Lines 282-302 |
| Hybrid, multi-cloud, and distributed cloud | Design guides, reference architectures, and best practices for hybrid, multi-cloud, and distributed cloud environments. | Lines 303-324 |
| Financial services | Design guides, reference architectures, and best practices for financial services workloads. | Lines 325-328 |
| Monitoring and logging | Best practices and operational patterns for observability, log streaming, and infrastructure monitoring. | Lines 329-341 |
| Storage | Design guides, reference architectures, and best practices to help you plan and implement storage for cloud workloads. | Lines 342-348 |
<a id="fundamentals"></a>Fundamentals
- Authentication and authorization: Introduces how to use Cloud Identity to manage identities for accessing Google Cloud services.
- Comparative analysis of Google Cloud deployment archetypes: Compares the cloud deployment archetypes in terms of the availability they provide, resilience to zone and region outages, cost, and operational complexity.
- Decide a resource hierarchy for your Google Cloud landing zone: Provides guidance to help you decide the resource hierarchy for your Google Cloud landing zone.
- Decide how to onboard identities to Google Cloud: Describes identity provisioning options for Google Cloud and the decisions that you must make when you onboard your users to Cloud Identity or Google Workspace.
- Decide the network design for your Google Cloud landing zone: Describes common network designs for landing zones, and helps you choose the option that best meets your requirements.
- Decide the security for your Google Cloud landing zone: Provides guidance to help you decide the security design for your Google Cloud landing zone.
- Deploy the blueprint: Describes the process to deploy an enterprise foundation using a blueprint.
- Deployment methodology: Provides guidance to use declarative infrastructure to deploy an enterprise foundations blueprint.
- Detective controls: Describes the threat detection and monitoring controls that are incorporated into an enterprise foundations blueprint.
- Enterprise foundations blueprint: Describes a blueprint to deploy foundational resources, configurations, and capabilities to help ensure consistent governance, security, scaling, and observability for your workloads in Google Cloud.
- Google Cloud deployment archetypes: Describes the deployment archetypes that you can use for cloud applications, the use cases for each deployment archetype and the design considerations.
- Google Cloud global deployment archetype: Describes the global deployment archetype, and its use cases and design considerations.
- Google Cloud hybrid deployment archetype: Describes the hybrid deployment archetype, and its use cases and design considerations.
- Google Cloud multi-regional deployment archetype: Describes the multi-regional deployment archetype, and its use cases and design considerations.
- Google Cloud multicloud deployment archetype: Describes the multicloud deployment archetype, and its use cases and design considerations.
- Google Cloud regional deployment archetype: Describes the regional deployment archetype, and its use cases and design considerations.
- Google Cloud zonal deployment archetype: Describes the zonal deployment archetype, and its use cases and design considerations.
- Implement your Google Cloud landing zone network design: Provides steps and guidance to implement your chosen network design for your landing zone.
- Landing zone design in Google Cloud: This series shows how to design and build a landing zone in Google Cloud, guiding you through high-level decisions about identity onboarding, resource hierarchy, network design, and security.
- Operations best practices: Provides best practices for deploying and operating workloads in a Google Cloud environment that's based on an enterprise foundations blueprint.
- Organization structure: Describes how the resources in an enterprise foundations blueprint are organized.
- Preventative controls for acceptable resource configurations: Describes preventative controls that you can incorporate into an enterprise foundations blueprint.
- Well-Architected Framework: Cost optimization pillar: Provides principles and recommendations to help you optimize the cost of your workloads in Google Cloud.
- Well-Architected Framework: Performance optimization pillar: Provides principles and recommendations to help you optimize the performance of your workloads in Google Cloud.
- Well-Architected Framework: Sustainability pillar: Provides principles and recommendations to help you design, build, and manage workloads in Google Cloud that are energy-efficient and carbon-aware.
<a id="ai-ml"></a>AI and ML
- Agentic AI use case: Administer interactive learning: Design a single-agent AI system that assesses a user's knowledge on a specific topic and generates a personalized learning experience.
- Agentic AI use case: Automate data science workflows: Design a multi-agent AI system that automates complex data analytics and machine learning tasks.
- Agentic AI use case: Build a borderless open data lakehouse: A high-level architecture to build a borderless open data lakehouse that establishes a highly governed, secure pipeline from raw borderless silos to AI and agentic driven actions.
- Agentic AI use case: Classify multimodal data: A high-level architecture to design a multi-agent AI system that analyzes disparate multimodal data and produces a high-confidence classification.
- Agentic AI use case: Enable live bidirectional multimodal streaming: A high-level architecture to build and deploy a multi-agent AI system that provides technical guidance and automated safety monitoring through a continuous, bidirectional stream of multimodal data.
- Agentic AI use case: Multimodal GraphRAG resource orchestration: A high-level architecture to build and deploy a multi-agent AI system that consolidates fragmented multimodal data into a searchable knowledge graph.
- Agentic AI use case: Orchestrate access to disparate enterprise systems: Use agentic AI to orchestrate access to disparate enterprise systems.
- Agentic AI use case: Orchestrate security operations workflows: A high-level architecture to build a multi-agent AI system that orchestrates complex investigation and triage processes in a security operations center (SOC).
- Architecture for MLOps using TensorFlow Extended, Agent Platform Pipelines, and Cloud Build: Describes the architecture of a machine learning (ML) system using TensorFlow Extended (TFX) libraries.
- Automate utilization-review of health insurance claims using generative AI: A reference architecture for health insurance companies to automate prior authorization (PA) request processing and improve their utilization review (UR) processes.
- Best practices for implementing machine learning on Google Cloud: Introduces best practices for implementing machine learning (ML) on Google Cloud, with a focus on custom-trained models based on your data and code.
- Build an ML vision analytics solution with Dataflow and Cloud Vision API: How to deploy a Dataflow pipeline to process large-scale image files with Cloud Vision. Dataflow stores the results in BigQuery so that you can use them to train BigQuery ML pre-built models.
- Build and deploy generative AI and machine learning models in an enterprise: Describes the generative AI and machine learning (ML) blueprint, which deploys a pipeline for creating AI models.
- Build trusted AI agents with Google Maps Platform: A high-level architecture to build trusted and effective AI agents by grounding them in real-world contextual data from Google Maps Platform and Google Calendar.
- C3 AI architecture on Google Cloud: Develop applications using C3 AI and Google Cloud.
- Choose a design pattern for your agentic AI system: Learn how to select an agent design pattern to build your agentic system.
- Choose your agentic AI architecture components: Learn how to select architecture components to build your agentic AI system.
- Confidential computing for data analytics, AI, and federated learning: "Learn about how you can use confidential computing in Google Cloud to encrypt data in use for confidential data analytics, AI machine learning, and federated learning."
- Cross-silo and cross-device federated learning on Google Cloud: Provides guidance to help you create a federated learning platform that supports either a cross-silo or cross-device architecture.
- Deploy an ML vision analytics solution with Dataflow and Cloud Vision API: Describes how to deploy a Dataflow pipeline that processes image files at scale with Cloud Vision API and then stores the processed output in BigQuery for analytics and model training.
- Deploy and operate generative AI applications: Discusses techniques for building and operating generative AI applications using MLOps and DevOps principles.
- Generative AI use case: Generate content for personalized marketing campaigns: Use AI to generate personalized content for targeted marketing campaigns.
- Generative AI use case: Generate personalized product recommendations: Use AI to generate personalized product recommendations for a retail application.
- Generative AI use case: Generate podcasts from audio files: Use AI to generate podcasts based on audio input.
- Generative AI use case: Generate solutions for customer-support questions: Use AI to generate responses to support questions from customers.
- Generative AI with RAG: Provides a list of reference architectures to deploy generative AI applications with retrieval-augmented generation (RAG) in Google Cloud.
- GraphRAG infrastructure for generative AI using Agent Platform and Spanner Graph: Design infrastructure for a generative AI application with GraphRAG using Spanner Graph.
- Guidelines for developing high-quality, predictive ML solutions: Collates some guidelines to help you assess, ensure, and control quality in machine learning (ML) solutions.
- Harness CI/CD pipeline for RAG applications: Shows you how to implement a Harness CI/CD pipeline for a RAG-capable application in Google Cloud.
- Implement agentic analytics workflows for distributed data: A high-level architecture for implementing cross-cloud analytics workflows that use AI agents.
- Implement two-tower retrieval for large-scale candidate generation: Learn how to implement an end-to-end two-tower candidate generation workflow with Vertex AI.
- MLOps: Continuous delivery and automation pipelines in machine learning: Discusses techniques for implementing and automating continuous integration (CI), continuous delivery (CD), and continuous training (CT) for machine learning (ML) systems.
- Model development and data labeling with Google Cloud and Labelbox: Provides guidance for building a standardized pipeline to help accelerate the development of ML models.
- Multi-agent AI system in Google Cloud: Design robust multi-agent AI systems in Google Cloud.
- Multi-tenant agentic AI system: Design a multi-tenant agentic AI system on Google Cloud.
- Networking for AI inference model serving on all backends: Guidance to help you create a unified frontend for multiple AI models that are hosted on-premises or by any provider, including third-party and Google Cloud.
- Networking for AI inference model serving on GKE: Guidance to help you create a multiple-model inference service using GKE.
- Optimize AI and ML workloads with Cloud Storage FUSE: Use Cloud Storage FUSE to optimize the performance of AI and ML workloads.
- Optimize AI and ML workloads with Google Cloud Managed Lustre: Shows how to use Managed Lustre to optimize the performance of AI and ML workloads.
- Private connectivity for RAG-capable generative AI applications: Implement network infrastructure to help improve security for your RAG-capable applications.
- RAG infrastructure for generative AI using Agent Platform and AlloyDB for PostgreSQL: Design infrastructure to run a generative AI application with retrieval-augmented generation using AlloyDB as the vector store.
- RAG infrastructure for generative AI using Agent Platform and Vector Search: Design infrastructure for a generative AI application with retrieval-augmented generation (RAG) using the vector search capabilities of Gemini Enterprise Agent Platform.
- RAG infrastructure for generative AI using Gemini Enterprise and Agent Platform: Design infrastructure for a generative AI application with retrieval-augmented generation (RAG) using Gemini Enterprise and Gemini Enterprise Agent Platform.
- RAG infrastructure for generative AI using GKE and Cloud SQL: Shows you how to design the infrastructure for a generative AI application with RAG using GKE.
- Single-agent AI system using ADK and Cloud Run: Shows you how to build a single-agent AI system by using ADK and Cloud Run with Gemini and MCP.
- Well-Architected Framework: AI and ML perspective: Provides principles and recommendations to help you design, build, and manage AI and ML workloads in Google Cloud that meet your operational, security, reliability, cost, and performance goals.
<a id="application-development"></a>Application development
- Architecture decision records overview: Explains when and how to use architecture decision records (ADRs) to document and explain design choices for applications on Google Cloud.
- Best practices for automatically provisioning and configuring edge and bare metal systems and servers: Describes best practices for automatically provisioning and configuring edge devices and bare metal systems and servers.
- Best practices for running cost-optimized Kubernetes applications on GKE: Discusses best practices for running cost-optimized applications on Google Kubernetes Engine (GKE).
- CI/CD pipeline for developing and delivering containerized apps: Describes how to set up and use a development, continuous integration (CI), and continuous delivery (CD) system using an integrated set of Google Cloud tools.
- Configure Active Directory for VMs to automatically join a domain: Shows you how to configure Active Directory and Compute Engine so that Windows virtual machine (VM) instances can automatically join an Active Directory domain.
- Connected device architectures on Google Cloud: An overview on a series of approaches for connected device IoT architectures on Google Cloud.
- Cymbal Bank application architecture: Describes a sample containerized application that incorporates best practices from a blueprint for an enterprise developer platform.
- Deploy an Active Directory forest on Compute Engine: Shows you how to deploy an Active Directory forest on Compute Engine in a way that follows the best practices.
- Deploy an enterprise developer platform on Google Cloud: Describes the enterprise application blueprint, which deploys an internal developer platform that provides managed software development and delivery.
- Deploy the blueprint: Describes the steps to deploy a blueprint for an enterprise developer platform.
- Deployment methodology: Describes the automated systems and pipelines that are used to deploy a blueprint for an enterprise developer platform.
- Develop and deploy containerized apps using a CI/CD pipeline: Describes how to design and deploy a system for continuous integration (CI) and continuous delivery (CD) by using an integrated set of Google Cloud services and tools.
- DevOps capabilities
- From edge to multi-cluster mesh: Deploy globally distributed applications through GKE Gateway and Cloud Service Mesh: Shows how to deploy globally distributed applications that are exposed through Google Kubernetes Engine (GKE) Gateway and Cloud Service Mesh.
- From edge to multi-cluster mesh: Globally distributed applications exposed through GKE Gateway and Cloud Service Mesh: Describes exposing applications externally through Google Kubernetes Engine (GKE) Gateways running on multiple GKE clusters within a service mesh.
- IoT platform product architecture on Google Cloud: Describes basic architectural considerations and recommendations for deploying an IoT platform product architecture on Google Cloud.
- Manage costs and attributions for the developer platform: Provide guidance to manage costs when using a blueprint for an enterprise developer platform.
- Multi-regional deployment on Compute Engine: Provides a reference architecture for a multi-tier application that runs on Compute Engine VMs in multiple regions and describes the design factors to consider when you build a multi-regional architecture.
- Reference architecture: Resource management with ServiceNow: Provides architectural recommendations to integrate Google Cloud assets into ServiceNow discovery tools.
- Regional deployment on Compute Engine: Learn how to architect a multi-tier application that runs on Compute Engine VMs in multiple zones within a Google Cloud region.
- Select a managed container runtime environment: Learn about managed runtime environments and assess your requirements to choose between Cloud Run and GKE Autopilot.
- Service architecture: Describes the service architecture of a blueprint for an enterprise developer platform.
- Set up Chrome Remote Desktop for Linux on Compute Engine: Shows you how to set up the Chrome Remote Desktop service on a Debian Linux virtual machine (VM) instance on Compute Engine. Chrome Remote Desktop allows you to remotely access applications with a graphical user interface.
- Set up Chrome Remote Desktop for Windows on Compute Engine: Shows you how to set up the Chrome Remote Desktop service on a Microsoft Windows virtual machine (VM) instance on Compute Engine. Chrome Remote Desktop allows you to remotely access applications with a graphical user interface.
- Single-zone deployment on Compute Engine: Provides a reference architecture for a multi-tier application that runs on Compute Engine VMs in a single-zone region and describes the design factors to consider when you build a single-zone architecture.
- Standalone MQTT broker architecture on Google Cloud: Describes an architecture for deploying an MQTT broker (the core application in an MQTT deployment) on Google Cloud.
- Website hosting: How to host a website on Google Cloud. Google Cloud provides a robust, flexible, reliable, and scalable platform for serving websites.
<a id="security-privacy-and-compliance"></a>Security, privacy, and compliance
- Active Directory single sign-on: Shows how to set up single sign-on (SSO) between your Active Directory environment and your Cloud Identity or Google Workspace account by using Microsoft Active Directory Federation Services (AD FS) and SAML Federation.
- Active Directory user account provisioning: Shows how to set up user and group provisioning between Active Directory and your Cloud Identity or Google Workspace account by using Google Cloud Directory Sync (GCDS).
- Architecture patterns: Discusses patterns that are designed based on the required communication models between applications residing in Google Cloud and in other environments.
- Assess existing user accounts: Describes how to assess different types of existing user accounts when you're planning to manage identities across an organization.
- Assess onboarding plans: Provides guidance to onboard existing identities and new identities to Cloud Identity or Google Workspace.
- Assess the impact of user account consolidation on federation: Describes how to assess the impact of user account consolidation on identity federation.
- Automate malware scanning for files uploaded to Cloud Storage: This document shows you how to build an event-driven pipeline that can help you automate the evaluation of files for malicious code.
- Best practices for federating Google Cloud with an external identity provider: Describes best practices for federating Google Cloud with an external identity provider.
- Best practices for planning accounts and organizations: Provides guidance to determine the number of Cloud Identity or Google Workspace accounts, Google Cloud organizations, and billing accounts you need based on your security and organizational requirements.
- Best practices for running an IoT backend on Google Cloud: Describes best practices for running an IoT backend on Google Cloud.
- Best practices for securing apps and resources by using context-aware access: Describes best practices for using context-aware access to secure apps and resources.
- Best practices for securing your applications and APIs using Apigee: Describes best practices that can help you to secure your applications and APIs using Apigee API management, Google Cloud Armor, reCAPTCHA Enterprise, and Cloud CDN.
- Configure networks for FedRAMP and DoD in Google Cloud: Provides configuration guidance to help you to comply with design requirements for FedRAMP High and DoD IL2, IL4, and IL5 when you deploy Google Cloud networking policies.
- De-identification and re-identification of PII in large-scale datasets using Sensitive Data Protection: Discusses how to use Sensitive Data Protection to create an automated data transformation pipeline to de-identify sensitive data like personally identifiable information (PII).
- Deploy a secured serverless architecture using Cloud Run functions: Provides guidance on how to help protect serverless applications that use Cloud Functions (2nd gen) by layering additional controls onto your existing foundation.
- Deploy a secured serverless architecture using Cloud Run: Provides guidance on how to help protect serverless applications that use Cloud Run by layering additional controls onto your existing foundation.
- Deploy automated malware scanning for files uploaded to Cloud Storage: Describes how to deploy an architecture for automated malware scanning of data in Cloud Storage.
- Design considerations: Discusses some of the most common design considerations to analyze and take into account as part of your hybrid and multicloud networking design.
- Design secure deployment pipelines: Describes best practices for designing secure deployment pipelines based on your confidentiality, integrity, and availability requirements.
- Evict consumer accounts: Describes how to mitigate social engineering risks by removing (evicting) corporate email addresses from consumer accounts.
- Example announcement: Provides an example of an email to announce the migration of consumer accounts to managed accounts.
- Federate Google Cloud with Active Directory: Describes how you can configure Cloud Identity or Google Workspace to use Active Directory as IdP and authoritative source.
- Federate Google Cloud with Microsoft Entra ID (formerly Azure AD): Describes how to configure Cloud Identity or Google Workspace to use Microsoft Entra ID as the IdP and source for identities.
- FortiGate architecture in Google Cloud: Describes the overall concepts around deploying a FortiGate Next Generation Firewall (NGFW) in Google Cloud.
- Gated egress and gated ingress: Discusses scenarios that demand bidirectional usage of selected APIs between workloads that run in various environments.
- Gated egress: Discusses how the gated egress pattern is based on exposing select APIs from various environments to workloads that are deployed in Google Cloud.
- Gated ingress: Discusses exposing select APIs of workloads running in Google Cloud to the private computing environment without exposing them to the public internet.
- Gated patterns: Discusses how gated patterns can be adapted to various applications with diverse requirements.
- General best practices: Discusses several common best practices that you can use for hybrid and multicloud architectures.
- Handover patterns: Discusses how to connect a private computing environment to projects in Google Cloud.
- Hybrid and multicloud secure networking architecture patterns: Discusses several common secure network architecture patterns that you can use for hybrid and multicloud architectures.
- Hybrid and multicloud secure networking architecture patterns: Describes common hybrid and multicloud architecture patterns, the scenarios that these patterns are best suited for, and best practices for using the paterns.
- Identify and prioritize security risks with Wiz Security Graph and Google Cloud: Describes how to identify and prioritize security risks in your cloud workloads with Wiz Security Graph and Google Cloud.
- Import data into a secured BigQuery data warehouse: Describes an architecture that you can use to help secure a data warehouse in a production environment, and provides best practices for data governance of a data warehouse in Google Cloud.
- Keycloak single sign-on: Shows how to set up single sign-on (SSO) between Keycloak and your Cloud Identity or Google Workspace account by using SAML federation.
- Limiting scope of compliance for PCI environments in Google Cloud: Describes best practices for architecting your cloud environment for Payment Card Industry (PCI) Security Standards Council compliance.
- Mapping BeyondProd security principles to the blueprint: Provides the mapping between BeyondProd security principles and a blueprint for an enterprise developer platform.
- Meshed pattern: Discusses a meshed pattern architecture that's based on establishing a hybrid network architecture that spans multiple computing environments.
- Microsoft Entra ID (formerly Azure AD) B2B user provisioning and single sign-on: Shows how to extend Microsoft Entra ID user provisioning and single sign-on to enable single sign-on (SSO) for Microsoft Entra ID B2B collaboration users.
- Microsoft Entra ID (formerly Azure AD) user provisioning and single sign-on: Shows how to set up user provisioning and single sign-on (SSO) between a Microsoft Entra ID tenant and your Cloud Identity or Google Workspace account.
- Microsoft My Apps portal integration: Shows how to add Google services and Identity-Aware Proxy (IAP) web-secured web applications to the Microsoft My Apps portal and how to enable automatic sign-on for these applications.
- Migrate consumer accounts: Describes how to migrate consumer accounts to managed user accounts that are controlled by Cloud Identity or by Google Workspace.
- Mirrored pattern: Discusses replicating the design of a certain existing environment or environments to a new environment or environments.
- Network security for distributed applications in Cross-Cloud Network: Describes how to design Cross-Cloud Network security for distributed applications.
- Networking for secure intra-cloud access: Reference architectures: Describes security and network connectivity architectures for intra-cloud access.
- Okta user provisioning and single sign-on: Shows how to set up user provisioning and single sign-on (SSO) between an Okta organization and your Cloud Identity or Google Workspace account.
- Overview of consolidating accounts: Describes how to consolidate existing consumer accounts so that you can manage and control user accounts.
- Overview of Google identity management: Explains the domain model that Google services rely on for authentication and identity management.
- Overview of identity and access management: Explores the general practice of identity and access management (generally referred to as IAM) and the individuals who are subject to it, including corporate identities, customer identities, and service identities.
- Patterns and practices for identity and access governance on Google Cloud: Describes patterns and practices for identity and access governance on Google Cloud.
- PCI Data Security Standard compliance: Shows how to implement the Payment Card Industry Data Security Standard (PCI DSS) for your business on Google Cloud.
- PCI DSS compliance on GKE: Provides guidance to address the requirements of the Payment Card Industry Data Security Standard (PCI DSS) for Google Kubernetes Engine (GKE) applications.
- Plan the onboarding process for your corporate identities: Provides guidance to assess requirements and develop a plan for onboarding corporate identities to Cloud Identity or Google Workspace.
- Prepare your Google Workspace or Cloud Identity account: Describes how to create a Cloud Identity or Google Workspace account and how to prepare the account for a production deployment.
- Reconcile orphaned managed user accounts: Describes how to identify and reconcile orphaned user accounts.
- Reference architectures: Provides architectures that you can use as references for managing corporate identities.
- Remove Gmail from consumer accounts: Describes how to remove Gmail from an existing consumer account to enable the user account to be migrated to Cloud Identity or Google Workspace.
- Sanitize Gmail accounts: Describes how to sanitize existing Gmail accounts by deliberately removing any corporate email addresses from them.
- Secure apps and resources by using context-aware access: Describes how you can enforce context-aware access for different types of apps and resources.
- Secure data environments in Google Cloud: A high-level architecture to secure sensitive datasets against accidental exposure and malicious exfiltration.
- Secure virtual private cloud networks with the Palo Alto VM-Series NGFW: Describes the networking concepts that you need to understand to deploy Palo Alto Networks VM-Series next generation firewall (NGFW) in Google Cloud.
- Security blueprint: PCI on GKE: Provides a Terraform-based blueprint for a Google Kubernetes Engine (GKE) environment that aligns with the Payment Card Industry Data Security Standard (PCI DSS).
- Security log analytics in Google Cloud: Shows how to collect, export, and analyze logs from Google Cloud to help you audit usage and detect threats to your data and workloads. Use the included threat detection queries for BigQuery or Chronicle, or bring your own SIEM.
- Single sign-on: Describes how to configure your Cloud Identity or Google Workspace account to use single sign-on (SSO).
- Tokenizing sensitive cardholder data for PCI DSS: Shows how to set up an access-controlled credit and debit card tokenization service on Cloud Functions.
- VMware Engine network security using centralized appliances: Provides guidance to design advanced network security for VMware Engine workloads to provide network protection features like DDoS mitigation, SSL offloading, NGFW, IPS/IDS, and DPI.
- Well-Architected Framework: Security, privacy, and compliance pillar: Provides principles and recommendations to help you design, deploy, and operate Google Cloud workloads that meet your requirements for security, privacy, and compliance.
<a id="reliability-and-disaster-recovery"></a>Reliability and disaster recovery
- Architecting disaster recovery for cloud infrastructure outages: Describes how Google Cloud is designed for resilience, discusses the process for architecting resilient workloads on Google Cloud, and provides product-specific disaster recovery (DR) guidance for zonal and regional outages.
- Architecting disaster recovery for locality-restricted workloads: Discusses how to architect disaster recovery (DR) for locality-restricted workloads.
- Architectures for high availability of PostgreSQL clusters on Compute Engine: Several architectures that provide high availability (HA) for PostgreSQL deployments on Google Cloud.
- Assess the reliability requirements for your cloud workloads: Provides guidelines to help you assess the reliability requirements of your cloud workloads.
- Building blocks of reliability in Google Cloud: Introduces the building blocks of reliability in Google Cloud.
- Business continuity hybrid and multicloud patterns: Discusses how the business continuity pattern relies on a redundant deployment of applications across multiple computing environments.
- Business continuity with CI/CD on Google Cloud: "Learn about developing a business continuity plan (BCP) for the CI/CD process."
- Design reliable infrastructure for your workloads in Google Cloud: Provides architectural recommendations to design reliable infrastructure for your cloud workloads.
- Disaster recovery building blocks: Discusses Google Cloud services and products that you can use as building blocks for your disaster recovery (DR) plan.
- Disaster recovery planning guide: The first part of a series that discusses disaster recovery (DR) in Google Cloud. This part provides an overview of the DR planning process: what you need to know in order to design and implement a DR plan.
- Disaster recovery scenarios for applications: Explores common disaster recovery (DR) scenarios for applications.
- Disaster recovery scenarios for data: Discusses disaster recovery (DR) scenarios for backing up and recovering data.
- Disaster recovery use cases: locality-restricted data analytics applications: Describes disaster recovery (DR) use cases for locality-restricted data analytics applications.
- Google Cloud infrastructure reliability guide: Introduces the building blocks of reliability in Google Cloud, and provides architectural recommendations to design reliable infrastructure for your cloud workloads.
- Manage and monitor your Google Cloud infrastructure: Summarizes guidelines to manage and monitor your infrastructure resources for reliability.
- Manage traffic and load for your workloads in Google Cloud: Describes traffic-management and load-management techniques that you can use to improve the reliability of your cloud workloads.
- Migrate across Google Cloud regions: Design resilient single-region environments on Google Cloud: Design resilient, single-region environments on Google Cloud.
- Patterns for scalable and resilient apps: Introduces some patterns and practices for creating apps that are resilient and scalable, two essential goals of many modern architecture exercises.
- Well-Architected Framework: Reliability pillar: Provides principles and recommendations to help you design, deploy, and manage reliable workloads in Google Cloud.
<a id="data-and-analytics"></a>Data and analytics
- Analytics hybrid and multicloud pattern: Discusses that the objective of the analytics hybrid and multicloud pattern is to capitalize on the split between transactional and analytics workloads.
- Architecture and functions in a data mesh: Describes the architecture and components of a data mesh that's deployed in Google Cloud.
- Build data products in a data mesh: Describes design considerations for building data products in a data mesh.
- Continuous data replication to BigQuery using Striim: Demonstrates how to migrate a MySQL database to BigQuery using Striim. Striim is a comprehensive streaming extract, transform, and load (ETL) platform.
- Continuous data replication to Spanner using Striim: How to migrate a MySQL database to Cloud Spanner using Striim.
- Data management with Cohesity Helios and Google Cloud: How Cohesity works with Google Cloud Storage. Cohesity is a hyperconverged secondary storage system for consolidating backup, test/dev, file services, and analytic datasets onto a scalable data platform.
- Deploy an enterprise data management and analytics platform: Describes an enterprise-ready data mesh architecture that you can deploy to protect confidential data.
- Deploy scalable BigQuery backup automation: Build a solution to automate recurrent BigQuery backup operations at scale, with two backup methods: BigQuery snapshots and exports to Cloud Storage.
- Design a self-service data platform for a data mesh: Describes how to design a self-service data-mesh platform that domain teams can use to create and consume data products.
- Device on Pub/Sub connection to Google Cloud: Describes architectural considerations when you directly connect an IoT aggregation device or gateway to Pub/Sub.
- Discover and consume data products in a data mesh: Discusses how domain teams can discover and consume data products in a data mesh.
- Migrate to Google Cloud: Transfer your large datasets: Provides guidance for transferring large datasets efficiently for workloads that you migrate to Google Cloud.
- Scalable BigQuery backup automation: Build a solution to automate recurrent BigQuery backup operations at scale, with two backup methods: BigQuery snapshots and exports to Cloud Storage.
<a id="databases"></a>Databases
- Apache Guacamole on GKE and Cloud SQL: Describes an architecture for hosting Apache Guacamole on Google Kubernetes Engine (GKE) and Cloud SQL. Apache Guacamole offers a fully browser-based way to access remote desktops through Remote Desktop Protocol (RDP).
- Database migration: Concepts and principles (Part 1): Introduces concepts, principles, terminology, and architecture of near-zero downtime database migration from on-premises or other cloud environments.
- Database migration: Concepts and principles (Part 2): Discusses how to set up and execute the database migration process, including failure scenarios.
- Define the scope of your migration to Redis Enterprise Cloud: Describes how to define the scope of a migration that uses RIOT Live Migration to migrate to fully managed Redis Enterprise Cloud in Google Cloud.
- Deploy Apache Guacamole on GKE and Cloud SQL: Describes how to deploy Apache Guacamole on Google Kubernetes Engine (GKE) and Cloud SQL.
- Deploy RIOT Live Migration to migrate to Redis Enterprise Cloud: Describes how to deploy an architecture to migrate from Redis-compatible sources to fully managed Redis Enterprise Cloud in Google Cloud using RIOT Live Migration service.
- Enterprise application on Compute Engine with Oracle Exadata: Provides a reference architecture for an application that's hosted on Compute Engine VMs with connectivity to Oracle Cloud Infrastructure (OCI) Exadata databases in Google Cloud.
- Enterprise application with Oracle Database on Compute Engine: Provides a reference architecture to host an application that uses an Oracle database, deployed on Compute Engine VMs.
- Global deployment with Compute Engine and Spanner: Learn how to architect a multi-tier application that runs on Compute Engine VMs and Spanner in a global topology on Google Cloud.
- Microsoft SQL Server Always On availability group in Google Cloud: Provides a reference architecture for implementing high-availability (HA) Microsoft SQL Server databases in Google Cloud by using Always On availability groups
- Migrate from AWS to Google Cloud: Migrate from Amazon RDS and Amazon Aurora for MySQL to Cloud SQL for MySQL: Describes how to design, implement, and validate a plan to migrate from Amazon Relational Database Service (RDS) or Aurora to Cloud SQL for MySQL.
- Migrate from AWS to Google Cloud: Migrate from Amazon RDS and Amazon Aurora for PostgreSQL to Cloud SQL and AlloyDB for PostgreSQL: Describes how to design, implement, and validate a plan to migrate from Amazon Relational Database Service (RDS) or Aurora to Cloud SQL for PostgreSQL or AlloyDB for PostgreSQL.
- Migrate from AWS to Google Cloud: Migrate from Amazon RDS for SQL Server to Cloud SQL for SQL Server: Describes how to design, implement, and validate a plan to migrate from Amazon Relational Database Service (RDS) to Cloud SQL for SQL Server.
- Multicloud database management: Architectures, use cases, and best practices: Describes architectures, use cases, and best practices for multicloud database management.
- Oracle E-Business Suite on Compute Engine with Oracle Exadata: Shows how to build the infrastructure to run Oracle E-Business Suite applications with Oracle Cloud Infrastructure Exadata in Google Cloud.
- Oracle E-Business Suite with Oracle Database on Compute Engine: Shows how to build the infrastructure to run Oracle E-Business Suite applications with Oracle Database on Compute Engine VMs in Google Cloud.
- Oracle PeopleSoft on Compute Engine with Oracle Exadata: Shows how to build the infrastructure to run Oracle PeopleSoft applications with Oracle Cloud Infrastructure Exadata in Google Cloud.
- Use RIOT Live Migration to migrate to Redis Enterprise Cloud: Describes an architecture to migrate from Redis-compatible sources to fully managed Redis Enterprise Cloud in Google Cloud using RIOT Live Migration service.
<a id="migration"></a>Migration
- Architect your workloads: Design resilient, single-region environments on Google Cloud.
- Designing networks for migrating enterprise workloads: Architectural approaches: Provides an overview of networking and security architectures for enterprises that are migrating workloads to Google Cloud.
- Log and monitor on-premises resources with BindPlane: Describes considerations and design patterns for using Cloud Logging, Cloud Monitoring, and BindPlane to provide logging and monitoring services for on-premises resources.
- Log on-premises resources with BindPlane: Describes how to use Cloud Logging and BindPlane to log on-premises resources.
- Migrate across Google Cloud regions: Get started: Start preparing your workloads and data for migration across Google Cloud regions.
- Migrate across Google Cloud regions: Prepare data and batch workloads for migration across regions: Prepare data and batch workloads for migration across regions.
- Migrate containers to Google Cloud: Migrate from Kubernetes to GKE: Describes how to design, implement, and validate a plan to migrate from Kubernetes to Google Kubernetes Engine (GKE).
- Migrate from AWS to Google Cloud: Get started: Describes how to design, implement, and validate a plan to migrate from AWS to Google Cloud.
- Migrate from AWS to Google Cloud: Migrate from Amazon EC2 to Compute Engine: Describes how to design, implement, and validate a plan to migrate from Amazon EC2 to Compute Engine.
- Migrate from AWS to Google Cloud: Migrate from Amazon EKS to GKE: Design, implement, and validate a plan to migrate from Amazon EKS to Google Kubernetes Engine.
- Migrate from AWS to Google Cloud: Migrate from Amazon S3 to Cloud Storage: Describes how to design, implement, and validate a plan to migrate from Amazon S3 to Cloud Storage.
- Migrate from AWS to Google Cloud: Migrate from AWS Lambda to Cloud Run: Describes how to design, implement, and validate a plan to migrate from AWS Lambda to Cloud Run.
- Migrate from Azure to Google Cloud: Get started: Describes how to design, implement, and validate a plan to migrate from Azure to Google Cloud.
- Migrate on-premises VMs to Google Cloud: Provides links to guides for migrating on-premises VM workloads to Google Cloud.
- Migrate to a Google Cloud VMware Engine platform: Describes the VMware Engine blueprint, which deploys a platform for VM workloads.
- Migrate to Google Cloud: Assess and discover your workloads: Describes the activities in the assessment phase of the process to migrate to Google Cloud.
- Migrate to Google Cloud: Best practices for validating a migration plan: Describes how to design, implement, and validate a plan to migrate to Google Cloud.
- Migrate to Google Cloud: Deploy your workloads: Describes the activities in the deployment phase of the process to migrate to Google Cloud.
- Migrate to Google Cloud: Get started: Helps you plan, design, and implement the process of migrating your application and infrastructure workloads to Google Cloud, including computing, database, and storage workloads.
- Migrate to Google Cloud: Migrate from manual deployments to automated, containerized deployments: Describes how to plan and design a migration path from manual deployments to automated, containerized deployments in Google Cloud.
- Migrate to Google Cloud: Minimize costs: Provide guidance to help you optimize the costs of workloads that you migrate to single-region and multi-region environments in Google Cloud.
- Migrate to Google Cloud: Optimize your environment: Provides guidance to help you continuously optimize the environment for a workload that you've migrated to Google Cloud.
- Migrate to Google Cloud: Plan and build your foundation: Describes how to plan and build a foundation on Google Cloud.
- Monitor on-premises resources with BindPlane: Describes how to use Cloud Monitoring and BindPlane to monitor on-premises resources.
<a id="networking"></a>Networking
- Best practices and reference architectures for VPC design: This guide introduces best practices and typical enterprise architectures for the design of virtual private clouds (VPCs) with Google Cloud.
- Cross-Cloud Network for distributed applications: Describes how to design Cross-Cloud Network for distributed applications.
- Cross-Cloud Network inter-VPC connectivity using Network Connectivity Center: Describes how to design the network segmentation structure and connectivity of Cross-Cloud Network with Network Connectivity Center.
- Cross-Cloud Network inter-VPC connectivity using VPC Network Peering: Describes how to design the network segmentation structure and connectivity of Cross-Cloud Network for distributed applications.
- Deploy Windows applications on managed Kubernetes: Describes how to deploy a reference architecture to manage and scale networking for Windows applications that run on managed Kubernetes.
- From edge to mesh: Deploy service mesh applications through GKE Gateway: Shows how to combine Cloud Service Mesh with Cloud Load Balancing to expose applications in a service mesh to internet clients.
- From edge to mesh: Expose service mesh applications through GKE Gateway: Combines Cloud Service Mesh with Cloud Load Balancing to expose applications in a service mesh to internet clients.
- Hub-and-spoke network architecture: Discusses the architectural options for designing hub-and-spoke network topologies in Google Cloud.
- Manage and scale networking for Windows applications that run on managed Kubernetes: Discusses how to manage networking for Windows applications that run on Google Kubernetes Engine using Cloud Service Mesh and Envoy gateways.
- Multi-agent private networking patterns in Google Cloud: Guidance to help you design private networking infrastructure that supports a publicly accessible, multi-agent, Gemini Enterprise app with private connections between agents, subagents, and tools.
- NCC Cross-Cloud Network with NVAs and regional failover: Describes how to design the network segmentation structure and connectivity of Cross-Cloud Network for distributed applications.
- Network segmentation and connectivity for distributed applications in Cross-Cloud Network: Describe how to design the network segmentation structure and connectivity of Cross-Cloud Network for distributed applications.
- Networking for hybrid and multi-cloud workloads: Reference architectures: Discusses networking for a scenario where workloads run in more than one place, such as on-premises and the cloud, or in multiple cloud environments.
- Networking for internet-facing application delivery: Reference architectures: Describes reference architectures to help you design networking and security for internet-facing application delivery.
- Patterns for using floating IP addresses in Compute Engine: How to use floating IP address patterns when migrating applications to Compute Engine from an on-premises network.
- Service networking for distributed applications in Cross-Cloud Network: Describes how to design Cross-Cloud Network service networking for distributed applications.
- Use Google Cloud Armor, load balancing, and Cloud CDN to deploy programmable global front ends: Provides an architecture that uses a global front end which incorporates Google Cloud best practices to help scale, secure, and accelerate the delivery of your internet-facing applications.
- VPC Network Peering Cross-Cloud Network with NVAs and regional affinity: Describes how to include NVAs into a regional affinity CCN deployment.
<a id="hybrid-multi-cloud-and-distributed-cloud"></a>Hybrid, multi-cloud, and distributed cloud
- Architectural approaches to adopt a hybrid or multicloud architecture: Provides guidance on common proven approaches and considerations to migrate your workload to the cloud.
- Authenticate workforce users in a hybrid environment: How to extend your identity management solution to Google Cloud to enable your workforce to authenticate and consume services in a hybrid computing environment.
- Build a hybrid render farm: Provides guidance on extending your existing, on-premises render farm to use compute resources on Google Cloud (Google Cloud).
- Build hybrid and multicloud architectures using Google Cloud: Provides practical guidance on planning and architecting your hybrid and multi-cloud environments using Google Cloud.
- Cloud bursting pattern: Discusses how to manage bursty workloads with the cloud bursting architecture pattern.
- Distributed architecture patterns: Discusses how to avoid or overcome design constraints and how to take advantage of each computing environment in a distributed architecture.
- Drivers, considerations, strategy, and approaches: Defines and discusses business objectives, drivers, and requirements, and how these factors can influence your design decisions.
- Edge hybrid pattern: Discusses how the edge hybrid pattern addresses connectivity challenges by running time- and business-critical workloads locally, at the edge of the network.
- Environment hybrid pattern: Discusses how to keep the production environment of a workload in the existing data center but use the public cloud for other, non-production environments.
- Hybrid and multicloud architecture patterns: Discusses common hybrid and multicloud architecture patterns, and describes the scenarios that these patterns are best suited for.
- Hybrid and multicloud architecture patterns: Discusses common hybrid and multicloud architecture patterns. It also describes the scenarios that these patterns are best suited for.
- Hybrid and multicloud monitoring and logging patterns: Discusses monitoring and logging architectures for hybrid and multicloud deployments, and provides best practices for implementing them by using Google Cloud.
- Other considerations: Highlights essential core design considerations that play a pivotal role in shaping your overall hybrid and multicloud architecture.
- Partitioned multicloud pattern: Discusses how the pattern combines multiple public cloud environments that are operated by different CSPs and the flexibility it offers.
- Patterns for authenticating workforce users in a hybrid environment: Discusses patterns for authenticating workforce users in a hybrid cloud environment.
- Patterns for connecting other cloud service providers with Google Cloud: Helps cloud architects and operations professionals decide how to connect Google Cloud with other cloud service providers (CSP) such as Amazon Web Services (AWS) and Microsoft Azure.
- Patterns for using Active Directory in a hybrid environment: Requirements to consider when you deploy Active Directory to Google Cloud and helps you choose the right architecture.
- Plan a hybrid and multicloud strategy: Discusses how to plan your hybrid and multi-cloud strategy.
- Tiered hybrid pattern: Discusses the opportunties and challenges that a tiered hybrid architecture pattern offers.
<a id="financial-services"></a>Financial services
- Well-Architected Framework: Financial services (FS) perspective: Provides principles and recommendations to help you design, build, and manage financial services (FS) applications in Google Cloud that meet your operational, security, reliability, cost, and performance goals.
<a id="monitoring-and-logging"></a>Monitoring and logging
- Cloud Monitoring metric export: Describes a way to export Cloud Monitoring metrics for long-term analysis.
- Deploy a job to import logs from Cloud Storage to Cloud Logging: Learn how to import logs that were previously exported to Cloud Storage back to Cloud Logging.
- Deploy log streaming from Google Cloud to Datadog: Learn how to deploy a solution that sends log files to a Cloud Logging sink and then to Datadog.
- Developer platform controls: Describes the security, networking, and reliability controls that are used in the blueprint for an enterprise developer platform.
- Import logs from Cloud Storage to Cloud Logging: Learn how to import logs that were previously exported to Cloud Storage back to Cloud Logging.
- Logging and monitoring: Describes how logging and monitoring work in a blueprint for an enterprise developer platform.
- Operations for both the developer platform and applications: Provides guidance to efficiently operate an enterprise developer platform and the deployed applications.
- Stream logs from Google Cloud to Datadog: Provides an architecture to send log event data from across your Google Cloud ecosystem to Datadog Log Management.
- Stream logs from Google Cloud to Splunk: Create a production-ready, scalable, fault-tolerant, log export mechanism that streams logs and events from your resources in Google Cloud into Splunk.
- Well-Architected Framework: Operational excellence pillar: Provides principles and recommendations to help you manage and operate workloads efficiently in Google Cloud.
<a id="storage"></a>Storage
- Configuring SaaS data protection for Google Workspace data with Spin.AI: How to configure SpinOne - All-in-One SaaS Data Protection with Cloud Storage.
- Design an optimal storage strategy for your cloud workload: Provides guidance to help you design a storage strategy that's aligned with the requirements of your cloud workload.
- Google Workspace Backup with Afi.ai: Describes how to set up an automated Google Workspace backup using Afi.ai.
- Parallel file systems for HPC workloads: Describes the storage options in Google Cloud for high performance computing (HPC) workloads, and provides guidance for when you should use parallel file systems like Managed Lustre for HPC workloads.