<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/"><channel><title>GCP on Brave New Geek</title><link>https://bravenewgeek.com/category/gcp/</link><description>Recent content in GCP on Brave New Geek</description><generator>Hugo</generator><language>en-us</language><lastBuildDate>Fri, 15 Nov 2024 09:32:19 -0700</lastBuildDate><atom:link href="https://bravenewgeek.com/category/gcp/index.xml" rel="self" type="application/rss+xml"/><item><title>Automating Infrastructure as Code with Vertex AI</title><link>https://bravenewgeek.com/automating-infrastructure-as-code-with-vertex-ai/</link><pubDate>Tue, 05 Nov 2024 15:23:09 -0700</pubDate><guid>https://bravenewgeek.com/automating-infrastructure-as-code-with-vertex-ai/</guid><description>&lt;p&gt;&lt;a href="https://bravenewgeek.com/wp-content/uploads/2024/11/konfigurate_ai.gif"&gt;&lt;img loading="lazy" src="https://bravenewgeek.com/wp-content/uploads/2024/11/konfigurate_ai.gif"&gt;&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;A lot of companies are trying to figure out how AI can be used to improve their business. Most of them are struggling to not just implement AI, but to even find use cases that aren’t contrived and actually add value to their customers. We recently discovered a compelling use case for AI integration in our &lt;a href="https://konfigurate.com/?utm_source=bravenewgeek.com&amp;amp;utm_campaign=vertex-ai"&gt;Konfigurate platform&lt;/a&gt;, and we found that implementing generative AI doesn’t require a great deal of complexity. I’m going to walk you through what we learned about integrating an AI assistant into our production system. There’s a ton of noise out there about what you “need” to integrate AI into your product. The good news? You don’t need much. The bad news? It took too much time sifting through nonsense to find what actually helps deliver value with AI.&lt;/p&gt;</description></item><item><title>Understanding Konfig’s Opinionation</title><link>https://bravenewgeek.com/understanding-konfigs-opinionation/</link><pubDate>Tue, 11 Jun 2024 13:59:57 -0600</pubDate><guid>https://bravenewgeek.com/understanding-konfigs-opinionation/</guid><description>&lt;p&gt;In my &lt;a href="https://bravenewgeek.com/no-assembly-required-the-benefits-of-an-opinionated-platform/"&gt;last post&lt;/a&gt;, I talked about the benefits of an opinionated platform. An opinionated platform allows your engineers to focus on things that matter to your business, such as shipping and improving customer-facing products and services. This is in contrast to engineers spending substantial time on non-differentiating work like platform infrastructure. Rather than infrastructure architecture, developers can focus more on the product architecture. &lt;a href="https://konfigurate.com/?utm_source=bravenewgeek.com&amp;amp;utm_campaign=understanding-opinionation"&gt;Konfig&lt;/a&gt; is an opinionated platform which provides two key value drivers: 1) reducing the investment and total cost of ownership needed to have an enterprise cloud platform and 2) minimizing the time to deliver new software products.&lt;/p&gt;</description></item><item><title>No assembly required: the benefits of an opinionated platform</title><link>https://bravenewgeek.com/no-assembly-required-the-benefits-of-an-opinionated-platform/</link><pubDate>Thu, 23 May 2024 15:28:49 -0600</pubDate><guid>https://bravenewgeek.com/no-assembly-required-the-benefits-of-an-opinionated-platform/</guid><description>&lt;p&gt;&lt;img loading="lazy" src="https://bravenewgeek.com/wp-content/uploads/2024/05/assembly-1024x697.png"&gt;&lt;/p&gt;
&lt;p&gt;When you talk to a doctor about a medical issue they will often present you with all of the options but shy away from providing an unambiguous recommendation. When you talk to a lawyer about a legal matter they frequently do the same. While it’s important to understand your options and their trade-offs or associated risks, when you go to these specialists you are likely seeking the counsel of an experienced and knowledgeable expert in their field who can help you make an informed decision. What most people are probably looking for is the answer to “what would you, someone who knows a lot about this stuff, do if you were in this situation?” After all, many of us are probably capable of finding the options ourselves, but the difficult part is determining what the right course of action is for a particular situation.&lt;/p&gt;</description></item><item><title>How Konfig provides an enterprise platform with GitLab and Google Cloud</title><link>https://bravenewgeek.com/how-konfig-provides-an-enterprise-platform-with-gitlab-and-google-cloud/</link><pubDate>Mon, 29 Apr 2024 14:24:31 -0600</pubDate><guid>https://bravenewgeek.com/how-konfig-provides-an-enterprise-platform-with-gitlab-and-google-cloud/</guid><description>&lt;p&gt;&lt;img loading="lazy" src="https://bravenewgeek.com/wp-content/uploads/2024/04/konfig.png"&gt;&lt;/p&gt;
&lt;p&gt;In a &lt;a href="https://blog.realkinetic.com/security-maintainability-velocity-choose-one-cf9eb9533d71"&gt;previous post&lt;/a&gt;, I explained the fundamental competing priorities that companies have when building software: security and governance, maintainability, and speed to production. These three concerns are all in constant tension with each other. For companies either migrating to the cloud or beginning a modernization effort, addressing them can be a major challenge. When you’re unfamiliar with the cloud, building systems that are both secure and maintainable is difficult because you’re not in a position to make decisions that have long-lasting and significant impact—you just don’t know what you don’t know. One small misstep can result in a major security incident. A bad decision can take years to manifest a problem. As a result, these migration and modernization efforts often stall out as analysis paralysis takes hold.&lt;/p&gt;</description></item><item><title>Introducing Konfig: GitLab and Google Cloud preconfigured for startups and enterprises</title><link>https://bravenewgeek.com/introducing-konfig-gitlab-and-google-cloud-preconfigured-for-startups-and-enterprises/</link><pubDate>Thu, 04 Apr 2024 14:51:23 -0600</pubDate><guid>https://bravenewgeek.com/introducing-konfig-gitlab-and-google-cloud-preconfigured-for-startups-and-enterprises/</guid><description>&lt;p&gt;&lt;a href="https://realkinetic.com/"&gt;Real Kinetic&lt;/a&gt; helps businesses transform how they build and deliver software in the cloud. This encompasses legacy migrations, app modernization, and greenfield development. We work with companies ranging from startups to Fortune 500s and everything in between. Most recently, we finished helping Panera Bread migrate their e-commerce platform to Google Cloud from on-prem and led their transition to GitLab. In doing this type of work over the years, we’ve noticed a problem organizations consistently hit that causes them to stumble with these cloud transformations. Products like GCP, GitLab, and Terraform are quite flexible and capable, but they are sort of like the piles of Legos below.&lt;/p&gt;</description></item><item><title>Cloud without Kubernetes</title><link>https://bravenewgeek.com/cloud-without-kubernetes/</link><pubDate>Mon, 12 Feb 2024 11:58:13 -0700</pubDate><guid>https://bravenewgeek.com/cloud-without-kubernetes/</guid><description>&lt;p&gt;&lt;img loading="lazy" src="https://bravenewgeek.com/wp-content/uploads/2024/02/Kubernetes-or-Cloud-Run-1024x683.jpeg"&gt;&lt;/p&gt;
&lt;p&gt;I think it’s safe to say Kubernetes has “won” the cloud mindshare game. If you look at the CNCF &lt;a href="https://landscape.cncf.io/"&gt;Cloud Native landscape&lt;/a&gt; (and manage to not go cross eyed), it seems like most of the projects are somehow related to Kubernetes. KubeCon is one of the fastest-growing industry events. Companies we talk to at Real Kinetic who are either preparing for or currently executing migrations to the cloud are centering their strategies around Kubernetes. Those already in the cloud are investing heavily in platform-izing their Kubernetes environment. Kubernetes competitors like Nomad, Pivotal Cloud Foundry, OpenShift, and Rancher have sort of just faded to the background (or simply pivoted to Kubernetes). In many ways, “cloud native” seems to be equated with “Kubernetes”.&lt;/p&gt;</description></item><item><title>Implementing ETL on GCP</title><link>https://bravenewgeek.com/implementing-etl-on-gcp/</link><pubDate>Wed, 15 Jul 2020 15:53:17 -0500</pubDate><guid>https://bravenewgeek.com/implementing-etl-on-gcp/</guid><description>&lt;p&gt;ETL (Extract-Transform-Load) processes are an essential component of any data analytics program. This typically involves loading data from disparate sources, transforming or enriching it, and storing the curated data in a data warehouse for consumption by different users or systems. An example of this would be taking customer data from operational databases, joining it with data from Salesforce and Google Analytics, and writing it to an OLAP database or BI engine.&lt;/p&gt;</description></item><item><title>Using Google-Managed Certificates and Identity-Aware Proxy With GKE</title><link>https://bravenewgeek.com/using-google-managed-certificates-and-identity-aware-proxy-with-gke/</link><pubDate>Wed, 24 Jun 2020 11:31:44 -0500</pubDate><guid>https://bravenewgeek.com/using-google-managed-certificates-and-identity-aware-proxy-with-gke/</guid><description>&lt;p&gt;Ingress on Google Kubernetes Engine (GKE) uses a Google Cloud Load Balancer (GCLB). GCLB provides a single anycast IP that fronts all of your backend compute instances along with a lot of other &lt;a href="https://cloud.google.com/load-balancing"&gt;rich features&lt;/a&gt;. In order to create a GCLB that uses HTTPS, an SSL certificate needs to be associated with the ingress resource. This certificate can either be &lt;a href="https://cloud.google.com/load-balancing/docs/ssl-certificates/self-managed-certs"&gt;self-managed&lt;/a&gt; or &lt;a href="https://cloud.google.com/load-balancing/docs/ssl-certificates/google-managed-certs"&gt;Google-managed&lt;/a&gt;. The benefit of using a Google-managed certificate is that they are provisioned, renewed, and managed for your domain names by Google. These managed certificates can also be configured directly with GKE, meaning we can configure our certificates the same way we declaratively configure our other Kubernetes resources such as deployments, services, and ingresses.&lt;/p&gt;</description></item><item><title>Zero-Trust Security on GCP With Context-Aware Access</title><link>https://bravenewgeek.com/zero-trust-security-on-gcp-with-context-aware-access/</link><pubDate>Mon, 22 Jun 2020 14:54:15 -0500</pubDate><guid>https://bravenewgeek.com/zero-trust-security-on-gcp-with-context-aware-access/</guid><description>&lt;p&gt;A lot of our clients at Real Kinetic leverage &lt;a href="https://blog.realkinetic.com/serverless-on-gcp-183fd811a706"&gt;serverless on GCP&lt;/a&gt; to quickly build applications with minimal operations overhead. Serverless is one of the things that truly &lt;a href="https://blog.realkinetic.com/gcp-and-aws-whats-the-difference-3b1329f0ffb3"&gt;differentiates GCP&lt;/a&gt; from other cloud providers, and &lt;a href="https://blog.realkinetic.com/why-google-app-engine-9c3d2f75dd02"&gt;App Engine&lt;/a&gt; is a big component of this. Many of these companies come from an on-prem world and, as a result, tend to favor perimeter-based security models. They rely heavily on things like IP and network restrictions, VPNs, corporate intranets, and so forth. Unfortunately, this type of security model doesn’t always fit nicely with serverless due to the elastic and dynamic nature of serverless systems.&lt;/p&gt;</description></item><item><title>What’s Going on with GKE and Anthos?</title><link>https://bravenewgeek.com/whats-going-on-with-gke-and-anthos/</link><pubDate>Tue, 17 Sep 2019 10:12:52 -0500</pubDate><guid>https://bravenewgeek.com/whats-going-on-with-gke-and-anthos/</guid><description>&lt;h4 id="gcps-slippery-slide-into-enterprise"&gt;GCP’s Slippery Slide into Enterprise&lt;/h4&gt;
&lt;p&gt;When former Oracle exec Thomas Kurian took over for Diane Greene as Google Cloud’s CEO, a lot of people expressed concern about what this meant for the future of GCP. Vendor lock-in is already at the forefront of the minds of many cloud adopters, and Oracle is notorious for &lt;a href="https://www.cnbc.com/2017/04/19/amazon-aws-chief-andy-jassy-on-oracle-customers-are-sick-of-it.html"&gt;locking customers into expensive and prolonged contracts&lt;/a&gt;. However, I thought the move was smart on Google’s part.&lt;/p&gt;</description></item><item><title>Serverless on GCP</title><link>https://bravenewgeek.com/serverless-on-gcp/</link><pubDate>Tue, 20 Aug 2019 10:04:48 -0500</pubDate><guid>https://bravenewgeek.com/serverless-on-gcp/</guid><description>&lt;p&gt;Like many other marketing buzzwords, the concept of “serverless” has taken on a life of its own, which can make it difficult to understand what serverless actually &lt;em&gt;means&lt;/em&gt;. What it really means is that the cloud provider fully manages server infrastructure all the way up to the application layer. For example, GCE isn’t serverless because, while Google manages the &lt;em&gt;physical&lt;/em&gt; server infrastructure, we still have to deal with patching operating systems, managing load balancers, configuring firewall rules, and so on. Serverless means we merely worry about our application code and business logic and nothing else. This concept extends beyond pure compute though, including things like databases, message queues, stream processing, machine learning, and other types of systems.&lt;/p&gt;</description></item><item><title>Security by Happenstance</title><link>https://bravenewgeek.com/security-by-happenstance/</link><pubDate>Tue, 26 Mar 2019 11:25:14 -0500</pubDate><guid>https://bravenewgeek.com/security-by-happenstance/</guid><description>&lt;h4 id="key-rotation-auditing-and-securecicd"&gt;Key rotation, auditing, and secure CI/CD&lt;/h4&gt;
&lt;p&gt;Companies often require employees to regularly change their passwords for security purposes. &lt;a href="https://www.pcisecuritystandards.org/document_library?category=pcidss&amp;amp;document=pci_dss"&gt;PCI compliance&lt;/a&gt;, for example, requires that passwords be changed every 90 days. However, NIST, whose guidelines commonly become the foundation for security best practices across countless organizations, &lt;a href="https://www.passwordping.com/surprising-new-password-guidelines-nist/"&gt;recently revised&lt;/a&gt; its recommendations around password security. Its Digital Identity Guidelines (&lt;a href="https://pages.nist.gov/800-63-3/sp800-63b.html"&gt;NIST 800-63-3&lt;/a&gt;) now recommends &lt;em&gt;removing&lt;/em&gt; periodic password-change requirements due to a growing body of research suggesting that frequent password changes actually &lt;a href="https://arstechnica.com/information-technology/2016/08/frequent-password-changes-are-the-enemy-of-security-ftc-technologist-says/"&gt;makes security &lt;em&gt;worse&lt;/em&gt;&lt;/a&gt;. This is because these requirements encourage the use of passwords which are more susceptible to cracking (e.g. incrementing a number or altering a single character) or result in people writing their passwords down.&lt;/p&gt;</description></item><item><title>Authenticating Stackdriver Uptime Checks for Identity-Aware Proxy</title><link>https://bravenewgeek.com/authenticating-stackdriver-uptime-checks-for-identity-aware-proxy/</link><pubDate>Tue, 29 Jan 2019 14:46:43 -0600</pubDate><guid>https://bravenewgeek.com/authenticating-stackdriver-uptime-checks-for-identity-aware-proxy/</guid><description>&lt;p&gt;&lt;a href="https://cloud.google.com/stackdriver/"&gt;Google Stackdriver&lt;/a&gt; provides a set of tools for monitoring and managing services running in GCP, AWS, or on-prem infrastructure. One feature Stackdriver has is “uptime checks,” which enable you to verify the availability of your service and track response latencies over time from up to six different geographic locations around the world. While Stackdriver uptime checks are not as feature-rich as other similar products such as &lt;a href="https://www.pingdom.com/"&gt;Pingdom&lt;/a&gt;, they are also completely &lt;em&gt;free&lt;/em&gt;. For GCP users, this provides a great starting point for quickly setting up health checks and alerting for your applications.&lt;/p&gt;</description></item><item><title>API Authentication with GCP Identity-Aware Proxy</title><link>https://bravenewgeek.com/api-authentication-with-gcp-identity-aware-proxy/</link><pubDate>Fri, 25 Jan 2019 11:21:53 -0600</pubDate><guid>https://bravenewgeek.com/api-authentication-with-gcp-identity-aware-proxy/</guid><description>&lt;p&gt;&lt;a href="https://cloud.google.com/iap/"&gt;Cloud Identity-Aware Proxy (Cloud IAP)&lt;/a&gt; is a free service which can be used to implement authentication and authorization for applications running in Google Cloud Platform (GCP). This includes &lt;a href="https://cloud.google.com/appengine/"&gt;Google App Engine&lt;/a&gt; applications as well as workloads running on &lt;a href="https://cloud.google.com/compute/"&gt;Compute Engine (GCE)&lt;/a&gt; VMs and &lt;a href="https://cloud.google.com/kubernetes-engine/"&gt;Google Kubernetes Engine (GKE)&lt;/a&gt; by way of &lt;a href="https://blog.realkinetic.com/http-to-https-using-google-cloud-load-balancer-dda57ac97c"&gt;Google Cloud Load Balancers&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;When enabled, IAP requires users accessing a web application to login using their Google account and ensure they have the appropriate role to access the resource. This can be used to provide secure access to web applications without the need for a VPN. This is part of what Google now calls &lt;a href="https://cloud.google.com/beyondcorp/"&gt;BeyondCorp&lt;/a&gt;, which is an enterprise security model designed to enable employees to work from untrusted networks without a VPN. At Real Kinetic, we frequently bump into companies practicing &lt;a href="https://www.onelogin.com/blog/the-death-star-a-lesson-in-cybersecurity"&gt;Death-Star security&lt;/a&gt;, which is basically relying on a hard outer shell to protect a soft, gooey interior. It’s simple and easy to administer, but it’s also vulnerable. That’s why we always approach security from a perspective of &lt;a href="https://en.wikipedia.org/wiki/Defense_in_depth_(computing)"&gt;&lt;em&gt;defense in depth&lt;/em&gt;&lt;/a&gt;.&lt;/p&gt;</description></item></channel></rss>