Skip to content

GoogleDistributedCloud/GDCBareMetal

Folders and files

NameName
Last commit message
Last commit date

Latest commit

 

History

213 Commits
 
 
 
 
 
 
 
 
 
 

Repository files navigation

Main blog - https://github.com/ObrienlabsDev/blog

Secure Private Data Center

Consolidated sovereign private data center artifacts. This repo details various approaches to standing up an air gapped data center that optionally uses or replicates functionality in GDC (Google Distributed Cloud) - software only, connected, air-gapped and air gapped appliance (formerly edge) solutions.

Hardware

See https://cloud.google.com/sovereign-cloud?hl=en which includes Google Cloud Dedicated and Google Distributed Cloud Only Intel processors are supported by GDC as of mid 2026 - x86-64 CPUs at microarchitecture level v3 (x86-64-v3) or higher. This excludes all ARM based machines including M series and the GB10 from NVidia in the DGX Spark. https://docs.cloud.google.com/kubernetes-engine/distributed-cloud/bare-metal/docs/installing/minimal-infrastructure

Google Cloud Distributed Air Gapped - 3 Rack - Hardware 3.0 (Feb 2024)

see GCP partner L300 GDC AG course 3:42 - https://partner.skills.google/paths/1681/course_templates/1034/video/519973 or https://www.youtube.com/watch?v=uE7kC3IXqF0 Screenshot 2026-07-06 at 11 40 14

Google Distributed Cloud - Air-gapped Appliance

This is the in-field version of GDC Air-gapped

GDC Air Gapped Appliance - Hardware Component Mapping

https://docs.cloud.google.com/distributed-cloud/hosted/docs/latest/appliance/resources/architecture

5U HPE-EL8000 - In the field GDC AG ruggedized.

See https://docs.cloud.google.com/distributed-cloud/hosted/docs/latest/appliance/overview#hardware_components

https://docs.cloud.google.com/distributed-cloud/hosted/docs/latest/appliance/admin/connect-the-device

gdc_air_gapped_appliance_front_profile
Component Vendor Model Alternate
TOR Switches 10G . .
TOR Switches 100-400G . .
HSM
Identity . . .
Storage NetApp NetApp ONTAP Select (OTS) .
Servers . . .
GPUs . . .
Power Supply . .
. . . .

see - https://buy.hpe.com/ca/en/compute/edgeline-systems/edgeline-systems/hpe-edgeline-el8000t-converged-edge-system/p/1012828509 specifically the HPE - Edglone E8000 https://wiseit.com.ua/en/hpe-server-dlya-iot/ with rugged case https://ecommerce.ultralifecorporation.com/ECommerce/product/el8000-ca/hpe-el8000-server-travel-case

6U HPE-EL8000 - GDC Air Gapped Appliance - Next 2023

_edge-cloud-google_next_2023

Networking

400Gb/s switches

GDC - Google Distributed Cloud

GDC is Google's version of private or hybrid cloud within your own data center. There are 3 main versions of GDC - where GDC Connected and GDC air-gapped are Google provided hardware and software. We will concentrate on GDC software only - for bare metal formerly branded as "Anthos clusters on-prem or bare metal" - see the older 2022 GCP services list referencing Anthos - https://cloud.google.com/terms/services/index-20220713 In late 2025 GKE took over the functions of GKE Enterprise which was itself a rebrand of Anthos in late 2023. When we did the L300 CEPF 10 hour lab for L300 certification in DevOps at Google (max 3 tries only) we needed to use Anthos to bring in functionality such as config sync and Anthos service mesh. The current GDC L300 trsining is nearly 2 years old from H1 2024. Therefore use the latesr 1.16.1 documentation as the final reference and not the partner traininf until it is updated for 2026. https://cloud.google.com/blog/products/containers-kubernetes/gke-enterprise-is-now-ga

GDCC - Google Distributed Cloud connected (edge)

GDCAG - Google Distributed Cloud air-gapped - https://docs.cloud.google.com/distributed-cloud/hosted/docs/latest/appliance/resources/architecture

GDGAGA - Google Distributed Cloud air-gapped Appliance

GDCSO - Google Distributed Cloud software only - Bare Metal

GDCS - Google Distributed Cloud Sandbox

There was a historical variant of GDC Hosted (renamed GDC connected (edge) where a POC can be setup to install GDC software only on your own VMs to prep for eventual delivery and integration of the 4 minimum racks in a 300k/month GDC Hosted - https://docs.cloud.google.com/distributed-cloud/hosted/docs/latest/gdch/resources/faq

GDC Requirements

GDC Air Gapped Requirements

Operational responsibities include instance installation, operation, infrastructure management, L1/L2 support, SLDC. All personnel involved with the GDC Air gapped instance must be local - and not remotely accessible by an external client, partner or google team. The differentiation between Google Distributed Cloud air-gapped and GDC connected - is the operational and SRE aspect - GDC-AG is locally operated and under local SRE.

Therefore, all the operational responsibilities, including facilitating, operating the instances, managing the infrastructure, L1/L2 support cycle, and software lifecycle, need to be done by the Operator.

Cgroupsv2

In ubuntu 22.04+

HSM

PKI

GDC Data Issues

Low to High side data transfer

This includes all of periodic connections to exchange metrics or upload image data or for air gapped - unclass to classified data transfer. Using a unidirectional data diode is one solution - like the BAE https://www.baesystems.com/en-us/product/data-diode-solution

see the CCCS CDS (Cross Domain Solution) dscussing with Luie - https://www.cyber.gc.ca/en/guidance/cross-domain-solutions-itse80030

GDC Connected - Hardware Component Mapping

Google Distributed Cloud at Next 26 - Sessions

BRK1-075: Whats new with Google Distributed Cloud

BRK2-195: AI at the edge: Transform operations with Google Distributed Cloud

BRK2-194: Build Agentic AI with Gemini and developer platforms on GDC

Sovereign-ready infrastructure: Architecting workloads for the public sector

Google Distributed Cloud at Next 26

Screenshot 2026-06-23 at 16 12 50

At the GCP conference in Las Vegas in April 2026 there were 4 GDC related presentations - however the hardware on the showcase floor was where we could talk directly to GDC personnel and the hardware vendor partners like Dell, Intel, NetApp, Palo Alto and Thales. _next_26_gdcc_Screenshot 2026-04-26 at 18 20 10

Component Vendor Model Alternate
TOR Switches 10G . .
TOR Switches 100-400G . .
Firewall Palo Alto _next_26_pa_Screenshot 2026-04-26 at 18 23 45 .
Identity Thales _next_26_thales_Screenshot 2026-04-26 at 18 23 59 .
Storage NetApp _next_26_netapp_Screenshot 2026-04-26 at 18 23 06 .
Servers HP _next_26_gdcc_servers_Screenshot 2026-04-26 at 18 24 36 .
Servers HPE This looks to be HPE related - like the HPE ProLiant DL100 series - https://buy.hpe.com/us/en/compute/rack-servers/proliant-dl100-servers/hpe-proliant-dl145-gen11/p/1014845266 _next_26_gdcc_question_Screenshot 2026-04-26 at 18 25 02 .
Servers Dell At the Intel booth at Next 26 - https://www.dell.com/en-ca/lp/dt/industry-telecom-xr8000 _next_26_intel_Screenshot 2026-04-26 at 18 27 27
GPUs . . .
Power Supply . _next_26_gdcc_power_Screenshot 2026-04-26 at 18 24 23
. . . .

unknown - possible HP Edgeline - https://www.hpe.com/ca/en/solutions/edge-computing.html -

GDC Bare Metal - Hardware Component Mapping

Component Vendor Model Alternate
TOR Switches 10G . .
TOR Switches 100-400G . .
Identity . . .
Storage . . .
Servers . . .
GPUs . . .
Power Supply . .
. . . .

GDC-AG connectivity

5 pathways for updates.

Vulnerability signatures

EDR - Incoming Detection and Response updates

Firewall IOC and signature updates

Threat intelligence

Code updates (including image updates)

Operations Suite Infrastucture

OSI includes servicenow

Multitenant Organizations

Hardware level isolation with appliance pulg/play into the base 4 to 30 rack GDC organizations, projects (no folders), tags, kubernetes taints.

GDC software only for Bare Metal

This GDC software-only for BM is a rebrand of Anthos (Anthos clusters on-prem or bare metal) where on prem CPUs are billed back to the GCP Project. see 2022 post in https://cloud.google.com/blog/topics/anthos/anthos-on-prem-and-bare-metal-are-now-gdc-virtual

Architecture
flowchart LR
  reg[("helm charts")] -->|"deploy"| wh["GDC GKE Management Cluster<br/>/based-on Anthos"]
  wh -->|"Intent reconcile loop"| wh
  wh -->|"Policy validated?"| sync["kubectl apply<br/>+ signatures"]
Loading

Anthos BMCTL install

gcloud services enable anthos.googleapis.com
gcloud services enable gkeonprem.googleapis.com
gcloud container bare-metal admin-clusters query-version-config --location=$ON_PREM_API_REGION 
export BMCTL_VERSION=1.35.0-gke.525

GDC Air Gapped Architecture

GDC-AG Projects

Project network connectivity is via ProjectNetworkPolicy CRDs - similar to peering (unidirectional)

GDC-AG Networking

VPC Flow logs are Kubernetes network policies audit logging

Load Balancers

ILB - Internal LB ELB - External LB (check l7) and ingres CRD capability

DNS

External Authortive server, Internal authorative server, forwarder (check DNS peering?)

GDC-AG IAM

GDC DevOps

GDC API Access

Cortex APIs

/cortex, /prometheus /(alert manager) subsets

HTTP2/gRPC protocol APIs

Vertex AI - use grpcurl via golang.

GCD Console

GDC gdcloud CLI

GDC Kubectl CLI

GDC Terraform

Terraform can be used to deploy VMs on GDC via the underlying KubeVirt CRD running on the kubernetes cluster

TBD: GDC Ansible

GDC Software

Comparison GDC vs GCP Services

Service Sub Service GDC GCP
Vertex AI Vision AI/ML OCR BatchAnnotateFiles, BatchAnnotateImages OCR, Image, facial, and crop hint recognition

. | . | . | .

gdcloud commands

GDC GCP analogs OSS sim / L300 source
admin . .
alpha . .
appliance . .
artifacts . .
auth . .
clusters . .
completion . .
components . .
config . .
database . .
help . .
iam . .
init . .
kms . .
maintenance (db) . . 1552/1198/522208
organizations . .
plugin . .
storage . .
system . .
version . .
. . .

GDC Software Component Mapping - Airgapped

A large portion of GDC specific functionality is implemented as kubernetes operators against custom resource definitions in KRM - such as the Network Function Operator - for GDC Connected. For example Operators can be implemented to extend the base kubernetes API using the Java Operator SDK - https://github.com/operator-framework/java-operator-sdk - see ObrienlabsDev/blog#189

Component Use Case GCP GDC Spec OSS Commercial
Alerts . . . . . .
API Gateway L7 LB Apigee . GKE dataplane 2 Gateway API Ingress
Billing . . . . . .
Configure (maintenance..) . . Configure . . .
Connect Agent (GKE) anthos fleet registration . Connect Agent . . .
Database . Cloud SQL DBaaS Database Service (PostgreSQL, oracle byol, AlloyDB Omni . . .
Distributed Database . Spanner Spanner Omni (see NEXT 26 Screenshot 2026-06-23 at 16 04 13 . . .
DNS private/public DNS, DNS peering/forwarding DNS DNS . . .
GKE Cluster Management . . Anthos . CAPI .
Git repos . Secure Source Repositories $1k/m or legacy CSR Cloud Source Repositories GDC? Gerrit, Gitlab (anything either containerized or via CRD) . Gerrit ADO, Bitbucket, Github, Gitlab
Identity/SSO RBAC / Identity Federation / WIF . SAML 2.0 and Fake OIDC Screenshot 2026-06-21 at 18 36 06 Screenshot 2026-06-21 at 18 32 17 and Anthos Identity Service (WIF) . KeyCloak AD (Active Directory), IBM Verify
IDS/IPS TLS Inspection Palo Alto NGFW Palo Alto . Falco .
Ingress public/private LB LB, ingress, gateway API GDC Ingress gateway (is this K8S Gateway API?) L4/L7 MetalB .
IPAM . . . . . .
KMS Symmetric/Asymmetric encryption KMS KMS . OpenSSL .
Logging . . . . ELK .
Machine Learning . Gemini Enterprise Agent Platform - audio file transcription Vertex AI audio file transcription, Vertex pretrained APIs, Speech-to-text, OCR Vertex AI Workbench . . .
Networking/eBPF/CNI . . GKE Dataplane 2 . Cilium .
Network Logging . IPS/IDS logs, VPC Flow Logs Kubernetes Network Policies Audit Logging . . .
Observability / Metrics / Time Series . . Prometheus / Grafana (per project) Screenshot 2026-06-21 at 22 36 25 . Prometheus / OpenTelemetry, PromQL, Open Metrics format, Cortex storage (AlertManager), Loki (Ops and Audit logs instances), Fluentbit .
Open Policy Agent . . OPA Gatekeeper . OPA .
Monitoring Loki spec . Grafana (per project) . Grafana .
Meta Monitoring type of HA for the monitoring stack . . . . .
Org Policies . . . . Open Policy Agent/Kyverno
Project . . . . K8s Namespaces or clusters .
Quota . . quota Billing Reports dashboard . .
Service Mesh . . . . Istio .
Storage PVC/Block . NetApp StorageGRID, Cortex storage . . GCNV Symcloud
Service . . ServiceNow (check PagerDuty integration) . . .
Terraform IaC . . yes but KRM is the primary IaC . . .
VM virtualization VMs on Kubernetes GCE GDC VM Manager Screenshot 2026-06-21 at 22 32 35 Screenshot 2026-06-21 at 22 16 50 N2, N3, A4, M2, M3 . KubeVirt .
VM APT and RPM package management . . yes . . .
. . . . . . .

Gemini Enterprise (formerly VertexAI) - translate, speech-to-text, workbench postgreSQL (check alloyDB Omni), Oracle byod

Gemini Enterprise

Gemini Enterprise models will run locally on GDC - see https://docs.cloud.google.com/distributed-cloud/gemini-on-gdcc/latest/docs/requirements#hardware

CAPI - Cluster API

Identity

GDC provides only predifined roles. The Fake OIDC provider has preloaded fake identities and associated JWT tokens. GDC Authorization uses Kubernetes Identities via RBAC

Kubernetes

GDC Namespaces

Namespace Use Cases notes
gpc-system . .
obs-system . .
infra-obs-obs-system . verify
platform-obs-obs-system . verify
. . .

GDC Special Projects

Namespace | Project | Use Cases | Headers | Storage | notes --- | --- | --- | --- . | Infra-obs | IO personna infra scopped logs/metrics | x-scope-orgIDinfraOBS. | PV then Cortex . . | Platform-obs | PA personna org scopped logs/metrics | | PV then Cortex | .

GDC Organization and Platform Deployments

Namespace Deployment Use Cases notes
gpc-system . . .
obs-system grafana (obs) . .

GDC Custom Resource Definitions

There are CRDs that implement analogs of traditional GCP operations specific to GDC via KRM. found/reading https://docs.cloud.google.com/distributed-cloud/hosted/docs/latest/gdcag/apis/service-api-overview

CRD group API notes
Alloy DB omni . .
Artifact Registry / Harbor . .
Backup . .
billing . .
cluster . .
hsm . .
iam . .
ipam . Screenshot 2026-07-07 at 00 29 56 https://partner.skills.google/paths/1681/course_templates/1034/video/519978
kms . .
maintenancewindow . Verify
marketplace . .
monitoring . .
networking . MonitoringRule
nodeUpgrade . .
logging . audit logs pulled node file system (DaemonSet), operational and audit logs - user project logs and user workload logs - stored on WORM bucket 1y+
Org policies . .
pki . .
Resource mAnager . .
Storage . .
upgrade . .
Vertex AI . .
VM Manager . .
. . .
. . .
MontoringTarget . .
NodeUpgrade . .
ProjectNetworkPolicy cross project peering is it transitive? no
? Node Maintenance type of node role for kubernetes upgrades which include unscheduling nodes.
OrganizationNetworkPolicy . .
VirtualMachineBackupPlanTemplate . .
VirtualMachineBackupRequest VMs .
VirtualMachineRestoreRequest . kubectl get virtualmachine.virtualmachine.gdc.goog -n PROJECT
. . VMNetworkPolicy (see k8s workloads as well)
. . .

GDC Kubernetes APIs

Storage Classes (ReadWriteMany and ReadWriteOnce)

GDC Kubernetes and Project relations

Kubernetes clusters in GDC can be 1:n (1 to many) n:m (many to many) or n:1 (many to 1) for project to cluster mappings. Limits are 16 user clusters per org with 42 nodes per user cluster - for a total of 640 + 32 = 672 nodes per org.

KubeVirt

Logging Sources

  • Kubernetes API
  • Istio
  • Harbor
  • Cluster VMs
  • deployments

Storage

Cortex

  • Prometheus for metrics and time series, and Loki for logs storage

NetApp

Rakuten

Harbor

Openstack

Open Nebula

Personas

From GDC L300 - Physical Networking - https://partner.skills.google/paths/1681/course_templates/1034/video/519975

Screenshot 2026-07-06 at 13 01 05

Infrastructure Operations

Platform Administrator

Application Operator

GDC - Helm Simulation

Helm Charts

Chart Site notes
Cortex . (AlertManager)
Fluentbit sidecar . .
Git GitLab .
Grafana . per project
KeyCloak . .
Loki . LogQL
Open Policy Agent . .
Prometheus . PromQL
. . .

GDC Simulation

GDC Base Hardware Simulation

GDC - Virtulized Hardware Simulation

GDC via Microsoft Hyper-V

ObrienlabsDev/blog#59

We are deferring to Hyperv on windows OS machines primarily because VMWare no longer does nested virtualization on 13 and 14 generation Intel chips. Hyperv is also a pseudo level 1 hypervisor over level 2 for workstation. The best scenario is to install ubuntu directly on intel hardware - like the Lenovo SR250 blade, however the p1gen6 provides for a portable cluster on 1 machine.

Spin up 3 generation 2 VMs on either a 128g 14900k desktop or a Lenovo P1gen6 96g laptop. Make sure to disable secure boot when initially installing ubuntu. Add an external network via one of the wired ethernet controllers by first creating a reference in virtual switch manager.

https://ubuntu.com/download/desktop or https://ubuntu.com/download/server

AFter creating the VMs, attach to the ext network and disable secure boot in order to allow boot from the ISO.

Add a new SCSI network adapter for "ext"

image

Now, there may be an issue running without secure boot once we get into bmctl - for now the bios settings disallow it.

image

Add net-tools and openssh-server

sudo apt install net-tools
sudo apt install openssh-server -y

GDC via VMWare Workstation

GDC via VMWare Fusion

Not really applicable except for generic kubernetes clusters as GDC binaries are only in Intel CPU format not ARMv64

GDC - Bare Metal - Simulated Local Rack

GDC Bare Metal - Official Google config samples

https://docs.cloud.google.com/kubernetes-engine/distributed-cloud/bare-metal/docs/reference/config-samples

_gdc_simulated_rackScreenshot 2026-04-30 at 12 30 20

Lenovo BMC Rack Servers as GDC Simulators

Lenovo SR250 V3 Rack Server

Lenovo Intel Xeon 6325P blades are cost effective for GDC simulation and include a secondary management CPU/Software stack for configuraiton - lead time is 30 days for shipping. The following SR250 V3 server can run either Redhat or Ubuntu.

After post shipping diagnostics and setup... Screenshot 2026-03-29 at 20 23 00

The blades can be installed to a standard 19 inch rack in 1U slots and connected to top of rack switches/routers along with separate redundant power sources. Screenshot 2026-03-29 at 20 00 20

For smaller rack depths such as 24 inches - the supplied lenovo specific extendable rails must be replaced with fixed 3rd party rails. Screenshot 2026-03-29 at 21 09 48

SR250 V3 noise levels - https://youtu.be/E6iNi3QMMcE

Dell Poweredge R260 Rack Servers as GDC Simulators

TOR Networking

Currently using TPLink 10gbps rack switches and routers.

Kubernetes Installation

docker desktoop

  • single node with storage provisioner - only for testing out images and helm charts locally

kubeadm

minikube

microk8s

GCP GKE

Rancher RKE2 / K3S

VM test install

It has been a while since Rancher 1.6 and RKE1. tracking via #6

https://docs.rke2.io/install/quickstart

root@ubuntuvm01:/var/lib/rancher/rke2/bin# history
    1  curl -sfL https://get.rke2.io | sh -
    2  systemctl enable rke2-server.service
    3  systemctl start rke2-server.service
root@ubuntuvm01:/var/lib/rancher/rke2/bin# journalctl -u rke2-server

Development

GDC Provided Developer tools

  • Istio Mesh routing? check on Istio service mesh for mTLS, ZTA,

  • Prometheus

  • Grafana

DevOps

Server Setup

GKE Enterprise (Anthos) for GDC Bare Metal

see https://docs.cloud.google.com/kubernetes-engine/distributed-cloud/bare-metal/docs/try/admin-user-gce-vms Creating a GKE cluster on Bare Metal https://docs.cloud.google.com/kubernetes-engine/distributed-cloud/bare-metal/docs/installing/install-prep or Distributed Cloud Edge https://docs.cloud.google.com/distributed-cloud/connected/latest/docs/clusters

Screenshot 2026-05-07 at 11 35 52

Make sure to increase default quotas before running the 5 vm script - and don't use northamerica-northeast1 (montreal - it is at capacity)

| NAME             | DIMENSIONS | REGION | REQUESTED LIMIT | APPROVED LIMIT |
+------------------+------------+--------+-----------------+----------------+
| CPUS_ALL_REGIONS |            | GLOBAL |              64 |             64 |
| SSD_TOTAL_GB | region=northamerica-northeast2 | northamerica-northeast2 |            1000 |           1000 |
Screenshot 2026-06-14 at 20 25 06 Screenshot 2026-06-14 at 20 22 04
|---------------------------------------------------------------------------------------------------------|
| VM Name               | L2 Network IP (VxLAN) | INFO                                                    |
|---------------------------------------------------------------------------------------------------------|
| abm-admin-cluster-cp  | 10.200.0.3            | 🌟 Ready for use as control plane for the admin cluster |
| abm-user-cluster-cp   | 10.200.0.4            | 🌟 Ready for use as control plane for the user cluster  |
| abm-user-cluster-w1   | 10.200.0.5            | 🌟 Ready for use as worker for the user cluster         |
| abm-user-cluster-w2   | 10.200.0.6            | 🌟 Ready for use as worker for the user cluster         |
|---------------------------------------------------------------------------------------------------------|

CICD

Git and build containers on GDC may differ from normal GCP public where Cloud Build, CSR, SSR or SaaS providers like ADO, Github Actions are used. Essentially anything that can be containerized or have a CRD developed around can be used for git storage and build systems

Design Issues

DI00: Differences between Hardware level 3.0 in 2024H1 and 2026H1

OIRv2

Optical Interconnect Rack V2 differences from V1

CIQ - Customer Intake Questionaire

OIQ -

DI01: Meta Monitoring Stack

The monitoring stack itself must me monitored

DI02: Use of Persistent Volumes on monitoring stack startup - manual IS override required

PV sizes are limited - to 20Gb (verify). Loki and Cortex use PVs on bootstrap - this must be modified to use Object Storage via NetApp StorageGRID. As of 202606 this is a manual process that must be automated on cluster startup (TODO: verify which cluster or every cluster down to user clusters)

https://partner.skills.google/paths/1552/course_templates/1193/video/522176

Use Cases

Issues

GCP Documentation

GDC Documentation

GDC Documentation - Air Gapped

GDC Documentation - Data Sheets

Training

GCD - Google Cloud Dedicated - EU only

GCD is of interest and alignment - but we are concentrating on GDC here in Canada

GDC - Google Distibuted Cloud Training

GDC Training - Example Sequence

Get yourself a skillsboost subscription via Google Developer Premium or use your partner training subscription.

GDC Connected

GDC Air-gapped

Note: as of July 2026 - the partner L300 GDC Air Gapped training is still at Hardware 3.0 released around Feb 2024. For GDC Connected - we are at GDC Hardware 4.0 The exams are a bit like certification exams - you need 80% and have a limited set of tries (5) - if you launch the test without any interaction - this counts as 1 attempt (attempt 2-5 is blocked by 48-72h gaps

Screenshot 2026-06-19 at 11 43 35

Partner Delivery Readiness Portal

Go over specific course and labs for CEPF L300 certifications specific to GDC and associated services (GKE, LLM training/RAG ...) - https://delivery-readiness-portal.cloud.google/app/gcp-projects/manage-dri-attribute For example the LLM evaluation on GKE using L4s (these are close to the google specific L300 labs except 2h instead of the normal 10h timeline, max 3 tries without VP reset and complexity (80% pass rate required) - https://partner.skills.google/course_templates/1720

CEPF labs

These are the CE labs that have a maxiumum of 3 tries, are timed at 2-10 hours and only available via specific account RBAC. I would recommend pre-automating the labs using at least gcloud IaC first before using up one attempt. 80% is required as usual. GPU Bencharking for Inference - GKE Node pools - https://partner.skills.google/course_templates/1720/labs/629704

Workarounds for GDC training specific to partner logins

I am a GCP partner so I have access to all the L200/L300 GDC training (paths 1681/1033), however if you are in the middle of attaining partner status or do not yet have a login from your org - some of the content is available without a partner login - for example the L300 air gapped training (paths 1681/1034) does not need a partner login. Some of the partner content (paths 1681/1035 is searchable in non partner skillsboost such as the air gapped introduction (paths 1552). Another option is to get the youtube URL (bottom right corner) for each course video (this will not solve the section and module tests and credit for the course - but are a workaround). You will need a correlation of course videos. For example the L200 GDC Air-Gapped course is only available to partners - however the following intro to start is available on generic youtube.

https://partner.skills.google/paths/1681/course_templates/1033/video/523528 = https://www.youtube.com/watch?v=sVsdfqV5-7g

Become a GCP Partner

Training Deprecation

Some of the GDC training is 1 to 2 years old. There are sections that are older than 2023 such as the reference to spinnaker CICD which is no longer used at Google. I would recommend prioritizing the documentation over the training - as GDC and GCP documentation are regularly updated.

Links

Errors

Private Cloud: PaaS Kubernetes stack with IaaS provisioning - HA and DR

Finances / FinOps

GDC Costs

GDC virtual

25k/m

GDC connected

35/m per vCPU - min 96 vCPU

Anthos credit

Can we use this one time credit

Trial for google/anthos.googleapis.com Expired	$1,025.01 f3c....bafc7 Following SKUs. Anthos (Google Cloud) (services/9186-F79E-3871/skus/03CC-5250-7F51) Anthos (Azure) (services/9186-F79E-3871/skus/688E-3D16-399E) January 24, 2022

GKE Costs

GKE control planes are per cluster (regardless of size) - at $0.1/hr - with free credits of 74.4 allocated for a single cluster (autopilot or zonal) - https://cloud.google.com/kubernetes-engine/pricing

Anthos Costs

Anthos has a one time credit of 1000US - getting details for new accounts. Screenshot 2026-03-31 at 16 17 50

Compatabiiity

Ubuntu Certified

Details around various hardware configurations that support Ubuntu. https://ubuntu.com/certified

QSFP56 NVIDIA DGX Spark

Dell PowerEdge R260

Lenovo SR250 V3

SFP28

Operational Testing

DR: Disaster Recovery

SLA/SLO/SLIs

HA Testing

Failure Testing

  • data corruption
  • exponential backoff, circuit breaker
  • power failures
  • pod OOM killed (memory limit)

SRE Run Books

Frameworks

Open Source Frameworks / Specifications

Private and Mirrored Repositories

PSPF

ISM

Esential Eight

Partner Companies

Cirrascale for Gemini GDC deployment

Thales

NetApp

Partner CSPs

Amazon Outposts

Azure Stack

Oracle

Keywords

ACM (GitOps)

Anthos

eBPF

Extended Berkeley Packet Filter - part of cilium ehich is part of GKE Enterprise - https://docs.cloud.google.com/kubernetes-engine/docs/concepts/dataplane-v2

GENEVE

GKE

SIT/UAT

VRF

Virtual Routing and Forwarding (GDC provides separate VRFs for each organization) - https://www.cisco.com/c/en/us/td/docs/voice_ip_comm/cucme/vrf/design/guide/vrfDesignGuide.html

Universe

A GDC universe has 1 to 6 zones (10 to 100 km apart - with 50 km max separation between p2 primary zones) - (representing 2 regions each with an operations center). Note: 2 zones in a universe can only do manual as opposed to automated recovery. Therefore the addition of a separate GDC installation at least 10 km apart can be considered a 2nd zone for that particular region. Normally 1 or more additional zones at a distance of at least 10 km apart can be considered a separate region if they are greater than 100 km apart. Connecting multiple GDC universes is a TBD topic.

See GDC-AG L300 https://partner.skills.google/paths/1681/course_templates/1034/video/519991 or the latest documentation on Zones, Regions and types of Universes in GDC at https://docs.cloud.google.com/distributed-cloud/hosted/docs/latest/gdcag/resources/multi-zone/mz-overview and https://docs.cloud.google.com/distributed-cloud/hosted/docs/latest/gdcag/platform/pa-user/subnets-overview#subnet-labeling

References

Government References

GDC Release Notes

Links

GDC Training Content of Interest

The following slides are from the GDC Practitioner, L200 and L300 air-gapped training above - from my previous employeer - Google

GDC Partner and Vendor Roles

Screenshot 2026-06-27 at 22 24 47 https://partner.skills.google/paths/1681/course_templates/1033/video/523528 = https://www.youtube.com/watch?v=sVsdfqV5-7g

GDC Types/Solutions

Screenshot 2026-06-27 at 22 21 35 https://partner.skills.google/paths/1681/course_templates/1033/video/523528 = https://www.youtube.com/watch?v=sVsdfqV5-7g

GDC Use Cases

Screenshot 2026-06-27 at 22 13 21 https://partner.skills.google/paths/1681/course_templates/1035/video/500364

GDC Monitoring, Alerting and Metrics

Metrics Data flow

Screenshot 2026-07-04 at 16 28 54

Monitoring deployment

Screenshot 2026-07-04 at 17 57 03

Monitoring data flow

Screenshot 2026-07-04 at 17 57 21

https://partner.skills.google/paths/1552/course_templates/1193/video/522175

TODO

  • lock down Google Cloud Dedicated and it's relationship or rename to Google Cloud Distributed (Air Gapped or Connected). A: EU focused

About

No description, website, or topics provided.

Resources

License

Stars

1 star

Watchers

0 watching

Forks

Releases

No releases published

Packages

 
 
 

Contributors

Languages