Learning state
Track this guide
Saved in this browser only. No account required.
Google Cloud Platform Infrastructure Master Class
Engineering-grade reference manual for GCP infrastructure operations across projects, IAM, VPC networks, firewall rules, routes, load balancing, Cloud NAT, Cloud DNS, logging, packet mirroring, and Network Intelligence Center.
Overview
Google Cloud Platform (GCP) infrastructure work starts with clear project context, least-privilege IAM, and repeatable gcloud evidence. Use Terraform for desired state, but use gcloud for inventory, troubleshooting, break-glass verification, and CI/CD validation.
This guide focuses on infrastructure commands that help operators prove how GCP resources are connected, secured, routed, and observed.
CLI Context and Authentication
Show the installed Cloud SDK version:
gcloud version
Authenticate interactively:
gcloud auth login
Show the active account:
gcloud auth list
Set the active project:
gcloud config set project PROJECT_ID
Show the current configuration:
gcloud config list
Describe the active project:
gcloud projects describe PROJECT_ID
Project and Asset Inventory
List projects visible to the current identity:
gcloud projects list
List enabled services in a project:
gcloud services list --enabled --project PROJECT_ID
List Compute Engine resources by zone:
gcloud compute instances list --project PROJECT_ID
List all forwarding rules:
gcloud compute forwarding-rules list --project PROJECT_ID
Export Cloud Asset Inventory for review:
gcloud asset search-all-resources --scope=projects/PROJECT_ID --format=table
IAM and Service Accounts
List project IAM bindings:
gcloud projects get-iam-policy PROJECT_ID --format=json
List service accounts:
gcloud iam service-accounts list --project PROJECT_ID
Describe one service account:
gcloud iam service-accounts describe SERVICE_ACCOUNT_EMAIL --project PROJECT_ID
List service account keys:
gcloud iam service-accounts keys list --iam-account SERVICE_ACCOUNT_EMAIL --project PROJECT_ID
VPC Networks and Subnets
List VPC networks:
gcloud compute networks list --project PROJECT_ID
Describe a VPC network:
gcloud compute networks describe VPC_NAME --project PROJECT_ID
List subnets across regions:
gcloud compute networks subnets list --project PROJECT_ID
Describe a subnet:
gcloud compute networks subnets describe SUBNET_NAME --region REGION --project PROJECT_ID
Create a custom-mode VPC after design approval:
gcloud compute networks create VPC_NAME --subnet-mode=custom --project PROJECT_ID
Create a subnet after CIDR approval:
gcloud compute networks subnets create SUBNET_NAME \
--network VPC_NAME \
--range 10.40.10.0/24 \
--region REGION \
--project PROJECT_ID
Firewall Rules
List firewall rules:
gcloud compute firewall-rules list --project PROJECT_ID
Describe a firewall rule:
gcloud compute firewall-rules describe RULE_NAME --project PROJECT_ID
Create a scoped ingress rule after approval:
gcloud compute firewall-rules create allow-https-from-office \
--network VPC_NAME \
--direction INGRESS \
--action ALLOW \
--rules tcp:443 \
--source-ranges OFFICE_CIDR \
--target-tags web \
--project PROJECT_ID
Find rules that allow broad ingress:
gcloud compute firewall-rules list \
--filter='direction=INGRESS AND allowed:* AND sourceRanges:(0.0.0.0/0)' \
--format='table(name,network,direction,allowed[].map().firewall_rule().list(),sourceRanges.list())' \
--project PROJECT_ID
Routes and Connectivity
List routes:
gcloud compute routes list --project PROJECT_ID
Describe a route:
gcloud compute routes describe ROUTE_NAME --project PROJECT_ID
List Cloud Routers:
gcloud compute routers list --project PROJECT_ID
Describe a Cloud Router:
gcloud compute routers describe ROUTER_NAME --region REGION --project PROJECT_ID
List VPN tunnels:
gcloud compute vpn-tunnels list --project PROJECT_ID
List interconnect attachments:
gcloud compute interconnects attachments list --project PROJECT_ID
Load Balancing and Edge
List backend services:
gcloud compute backend-services list --project PROJECT_ID
Describe a backend service:
gcloud compute backend-services describe BACKEND_SERVICE --global --project PROJECT_ID
List target proxies:
gcloud compute target-http-proxies list --project PROJECT_ID
List URL maps:
gcloud compute url-maps list --project PROJECT_ID
List health checks:
gcloud compute health-checks list --project PROJECT_ID
Cloud NAT and DNS
List Cloud NAT configurations:
gcloud compute routers nats list --router ROUTER_NAME --region REGION --project PROJECT_ID
Describe a Cloud NAT configuration:
gcloud compute routers nats describe NAT_NAME --router ROUTER_NAME --region REGION --project PROJECT_ID
List Cloud DNS managed zones:
gcloud dns managed-zones list --project PROJECT_ID
List DNS records in a managed zone:
gcloud dns record-sets list --zone ZONE_NAME --project PROJECT_ID
Logging, Packet Mirroring, and Network Intelligence
Read recent VPC flow logs:
gcloud logging read 'resource.type="gce_subnetwork"' --limit 20 --project PROJECT_ID
List packet mirroring policies:
gcloud compute packet-mirrorings list --project PROJECT_ID
Describe a packet mirroring policy:
gcloud compute packet-mirrorings describe POLICY_NAME --region REGION --project PROJECT_ID
List Network Management connectivity tests:
gcloud network-management connectivity-tests list --project PROJECT_ID
Run a connectivity test:
gcloud network-management connectivity-tests run TEST_NAME --project PROJECT_ID
Describe a connectivity test result:
gcloud network-management connectivity-tests describe TEST_NAME --project PROJECT_ID
Safe Operating Pattern
Use this sequence before changing GCP infrastructure:
- Confirm project and account context.
- Capture read-only inventory with
gcloud ... listandgcloud ... describe. - Confirm IAM scope for the operator or service account.
- Review routing, firewall, DNS, load balancer, and logging evidence.
- Make changes through Terraform or reviewed
gcloudcommands. - Re-run the read-only commands to prove the final state.
Production Checklist
- Project ID and billing impact are approved.
- VPC CIDR and subnet plan are documented.
- Firewall rules are scoped by source range, tag, or service account.
- Routes do not override required private, VPN, or interconnect paths.
- Load balancer health checks match application behavior.
- Cloud NAT and DNS records have owner and rollback notes.
- VPC flow logs or equivalent telemetry are enabled for critical paths.
- Connectivity tests document source, destination, port, and expected result.