Skip to content
Cloud architecture templates

Google Cloud — GKE Microservices with Managed Data

A Kubernetes cluster on GKE with its namespaces drawn as real containers, an ingress terminating outside traffic, and the stateful half deliberately outside the cluster in managed services. Reports clean. The pattern worth copying is that last part: the databases are managed, not StatefulSets, and the diagram makes that visible.

Template previewCloud architecture
Storefront on GKEA Google Cloud architecture diagram: 12 resources in 8 scopes (1 network, 0 availability zones), joined by 12 connections. Categories drawn: Containers, Storage, Databases, Networking, Security, Integration, Clients. No error or warning across 12 resources and 12 edges, every line read; 2 of the 10 checks could not run at all and 1 ran only in part — so this is a clean result on the part that could be checked, not a clean bill of health.Storefront on GKEGoogle Cloud · 12 resources · 8 scopes · 1 network · 0 zones · 12 connectionsNo error or warning across 12 resources and 12 edges, every line read; 2 of the 10 checks could not run at all and 1 ran only in part — so this is a cleanresult on the part that could be checked, not a clean bill of health.Internetintern…8Accountacme-storefront8Regioneurope-wes…8NetworkStorefront VPC10.20.0.0/168+ClusterGKE cluster8Namespaceedge8Namespaceshop8Namespaceo…8Shoppers—4+Global loadbalancer—3+WAF policygcp3+Ingresscontrollerk8s4+Storefrontk8s×44+Cart servicek8s×34+Searchservicek8s×24+Metricscollectork8s5+Orders databasegcp1+Session cachegcp1+Product mediagcp1+Domain eventsgcp1+https 443https 443https 443http 8080grpc 9000grpc 9000postgres 5432redis 6379object readcart eventsLegendContainersStorageDatabasesNetworkingSecurityIntegrationClientsRequest trafficData movementAsynchronousDepends onChecks — what ran, and what could notWhether the internet reaches something that ho…ran over 10 subjects, found nothingWhether anything holding data at rest sits in …could not run here — 1 reason givenWhether anything claiming redundancy is spread…could not run here — 1 reason givenEdges that leave one network for another, or c…ran over 5 subjects, 1 gap — a partial passResources that appear in no edge at all. A leg…ran over 12 subjects, found nothingEvery id an edge or a scope names is one that …ran over 12 subjects, found nothingEach id is declared once. Two declarations mak…ran over 20 subjects, found nothingType words that did not resolve. A hole in thi…ran over 12 subjects, found nothingDeclared ranges: that each parses, sits inside…ran over 1 subject, found nothingWhether every line was read and no shape cap b…ran over 20 subjects, found nothingFindings1`orders`, `cache`, `media` and `events` hold data at rest and sit inside no subnet at all, so nothing in this document says whether they are publicly routable and thischeck had nothing to read.in the figure: orders, cache, media, events2This document declares no availability zone, so the redundancy check DID NOT RUN AT ALL: nothing here claims redundancy either, so nothing was missed. Declare thezones (`zone az-a`, `zone az-b`) and put the resources inside them, and the claim becomes checkable.3`armor`, `glb`, `orders`, `cache`, `media` and 1 more are joined to something inside a network but sit in no network, internet or on-premises scope of their own, sowhether those edges cross a boundary COULD NOT BE DECIDED.in the figure: armor, glb, orders (badge 1), cache (badge 1), media (badge 1) +1 more4The walk reached 10 resources from the internet; every one of the 3 that hold data at rest — `media`, `orders` and `cache` — sits behind an ingress.in the figure: shoppers, armor (badge 3), glb (badge 3), ing, web +5 more5Every edge this check could read stays inside one network, stays outside all of them, or names a gateway to cross at; 5 endpoints were read across 1 declared network.in the figure: ing (badge 4), web (badge 4), cart (badge 4), search (badge 4), metrics6All 12 declared resources appear in at least one edge.in the figure: shoppers (badge 4), glb (badge 3), armor (badge 3), ing (badge 4), web (badge 4) +7 more7All 12 ids named by edges and scopes were declared somewhere in this document.in the figure: shoppers (badge 4), armor (badge 3), glb (badge 3), ing (badge 4), web (badge 4) +7 more8All 20 declared ids are distinct.in the figure: internet, proj, europe-west1, vpc, gke-main +15 more9All 12 resources resolved to a type this engine knows, so every check above had the full vocabulary to read.in the figure: shoppers (badge 4), glb (badge 3), armor (badge 3), ing (badge 4), web (badge 4) +7 more10The one declared range parses, it is not drawn inside another addressed network, so there was no containment to test, and no two ranges under one parent share anaddress. Ranges under different parents were not compared — two networks numbered alike is ordinary and correct.in the figure: vpc (badge 8)11Every line was read and no shape cap bit: the 20 declarations above are the whole document, so the counts are totals rather than floors.

Make it your own.

title "Storefront on GKE"
provider gcp

internet {
  user shoppers "Shoppers"
}

cloud proj "acme-storefront" {
  region europe-west1 {
    load-balancing glb "Global load balancer"
    cloud-armor armor "WAF policy"

    network vpc "Storefront VPC" cidr 10.20.0.0/16 {
      cluster gke-main "GKE cluster" {
      namespace edge "edge" {
        ingress ing "Ingress controller"
      }
      namespace shop "shop" {
        k8s:deployment web "Storefront" count 4 tier web
        k8s:deployment cart "Cart service" count 3 tier api
        k8s:deployment search "Search service" count 2 tier api
      }
        namespace ops "ops" {
          k8s:deployment metrics "Metrics collector"
        }
      }
    }

    cloud-sql orders "Orders database"
    memorystore cache "Session cache"
    cloud-storage media "Product media"
    pubsub events "Domain events"
  }
}

shoppers -> armor : https 443
armor -> glb : https 443
glb -> ing : https 443
ing -> web : http 8080
web -> cart : grpc 9000
web -> search : grpc 9000
cart -> orders : postgres 5432
cart -> cache : redis 6379
web => media : object read
cart ~> events : cart events
metrics ..> web
metrics ..> cart