GCP Zero-to-Hero
A five-tier mastery path — Foundation to Specialist — across every Google Cloud domain, every certification, and real job, troubleshooting and architecting skills.
Start the courseA complete, job-oriented path through Google Cloud: cloud fundamentals, the resource hierarchy, IAM, compute, storage, databases, networking, serverless, security, landing zones, the Architecture Framework, data, AI/ML, resilience and operations — built from production-grade lessons and capped with an enterprise landing-zone capstone.
What you’ll be able to do
- Navigate Google Cloud confidently — the resource hierarchy, projects, IAM, the console and gcloud
- Run compute, storage, database and networking services in production
- Build serverless and event-driven systems with Cloud Run, Pub/Sub and Eventarc
- Engineer security with IAM, Org Policy, KMS, VPC Service Controls and Workload Identity
- Stand up an enterprise landing zone with Shared VPC and the Architecture Framework
- Operate, troubleshoot and recover workloads, and be certification- and interview-ready
Prerequisites
- Basic IT literacy (files, networks, a terminal) — no prior cloud experience required
- A free Google Cloud account for the hands-on labs (Free Tier / $300 credit is enough)
Who it’s for
Career-changers and developers new to the cloud, engineers moving to Google Cloud, and people preparing for Google Cloud certifications or real GCP delivery work.
Curriculum
Tier 1 · Foundation — Google Cloud Basics (CDL/ACE)
Start at zero: what Google Cloud is, the global infrastructure, the resource hierarchy, IAM, and your first workloads.
- 1 Google Cloud Hands-On First Steps: Console, gcloud CLI, Cloud Shell & SDKs
- 2 Google Cloud Fundamentals: Global Infrastructure, Resource Hierarchy & Pricing
- 3 Google Cloud Billing & Cost Management, In Depth: Accounts, Budgets, Export & Discounts
- 4 Google Cloud IAM Fundamentals: Roles, Service Accounts, Policy & Inheritance
- 5 Google Cloud IAM, In Depth: Role Types, Policy Structure, Conditions, Inheritance & Recommender
- 6 Three-Tier Web Application on GCP: The Foundational Pattern
- 7 Serverless Event-Driven Data Pipeline on GCP for Beginners
- 8 GCP Cloud Adoption Framework: Overview & Maturity Model — The Four Themes (Learn, Lead, Scale, Secure), the Tactical–Strategic–Transformational Phases, Epics, and How to Assess Your Maturity
Tier 2 · Intermediate — Compute & Serverless (ACE)
Run compute: managed instance groups, Cloud Run, and event-driven Cloud Functions.
- 9 Google Compute Engine, In Depth: Machine Types, Disks, Images, Metadata & Every Option
- 10 Google Cloud Run, In Depth: Services, Jobs, Concurrency, Scaling & Traffic
- 11 Google Cloud Functions, In Depth: 1st vs 2nd Gen, Triggers, Runtimes, Concurrency & Scaling
- 12 Regional Managed Instance Groups: Autohealing, Canary Rollouts, and Stateful MIGs
- 13 Cloud Run in Production: Services, Jobs, VPC Egress, and Concurrency Tuning
- 14 Event-Driven Architecture with Cloud Functions 2nd Gen and Eventarc
Tier 2 · Intermediate — Storage & Databases (ACE)
Store data: Cloud Storage protection, Cloud SQL HA, and Spanner schema design.
- 15 Google Cloud Storage, In Depth: Buckets, Storage Classes, Lifecycle, Versioning & Encryption
- 16 Google Cloud SQL, In Depth: Engines, HA, Read Replicas, Backups & Connectivity
- 17 Google Cloud Firestore, In Depth: Native vs Datastore Mode, Documents, Indexes & Queries
- 18 Google Cloud Memorystore, In Depth: Redis, Redis Cluster, Memcached, HA & Eviction
- 19 Cloud Storage Data Protection: Retention Lock, Soft Delete, Versioning, and Replication
- 20 Cloud SQL in Production: HA, Read Replicas, PSC Connectivity, and Maintenance
- 21 Cloud Spanner Schema Design: Interleaving, Hotspot Avoidance, and Secondary Indexes
Tier 2 · Intermediate — Networking (VPC)
Design VPCs: Shared VPC, hierarchical firewall + Cloud NAT, Cloud DNS, and the global load balancer.
- 22 Google Cloud VPC, In Depth: Subnets, Routes, Firewall Rules, Cloud NAT & Private Access
- 23 Google Cloud Load Balancing, In Depth: Global vs Regional, the LB Types & Backends
- 24 Building a Shared VPC: Centralized Networking Across Many GCP Projects
- 25 Controlling Egress on GCP: Hierarchical Firewall Policies and Cloud NAT, End to End
- 26 Cloud DNS at Scale: Private Zones, Peering, Forwarding, and Response Policies
- 27 Engineering the Global External Application Load Balancer on GCP
Tier 2 · Intermediate — Production Readiness (Architecture Framework)
What makes a workload production-ready: the reliability, operational-excellence and performance pillars.
- 28 Google Cloud Operations Suite, In Depth: Cloud Monitoring, Logging, Trace & Error Reporting
- 29 GCP Well-Architected: Reliability — User-Experience SLOs, Error Budgets, Redundancy Across Failure Domains, Graceful Degradation, Failure Recovery, Chaos Testing & Capacity Planning
- 30 GCP Well-Architected: Operational Excellence — Operational Readiness, the Cloud Operations Suite, Incident & Problem Management, Release Engineering, Toil Reduction & Capacity Planning
- 31 GCP Well-Architected: Performance Optimization — Performance Principles, Resource Selection, Scaling, Load Balancing, Caching, and Continuous Tuning
Tier 3 · Advanced — Networking Engineering (PCNE)
Connect at scale: Private Service Connect, HA VPN/Cloud Router, VPC Service Controls and hybrid/multi-cloud.
Tier 3 · Advanced — Security Engineering (PCSE)
Engineer security: deny policies & conditions, KMS/CMEK, Secret Manager, Workload Identity, Org Policy and compliance.
- 36 Google Cloud KMS & Secret Manager, In Depth: Keys, CMEK, Envelope Encryption & Secrets
- 37 Google Cloud Identity-Aware Proxy (IAP), In Depth: Zero-Trust Access to Apps, VMs & APIs
- 38 Advanced GCP IAM: Deny Policies, Conditional Bindings, and Impersonation Chains
- 39 Cloud KMS in Depth: CMEK, Envelope Encryption, Cloud HSM, and External Key Manager
- 40 Secret Manager Rotation Pipelines with Cloud Functions, IAM, and CMEK
- 41 Keyless Authentication to GCP: Workload Identity Federation for GitHub Actions and CI/CD
- 42 Designing a GCP Resource Hierarchy: Org, Folders, Projects, and Org Policy Guardrails
- 43 GCP Well-Architected: Security, Privacy & Compliance — IAM, Data & Network Security, Compliance, Secret Manager, Security Command Center, and Shielded/Confidential VMs
- 44 SOC 2 Continuous Compliance Automation on GCP with Drata
Tier 3 · Advanced — Serverless, Messaging & Integration
Build decoupled systems: Pub/Sub at depth, event-driven and serverless API architectures.
Tier 3 · Advanced — Containers / GKE
Run GKE in production: Autopilot hardening, Dataplane V2, the multi-cluster Gateway API, and Workload Identity.
- 49 Google Kubernetes Engine, In Depth: Autopilot vs Standard, Node Pools, Networking & Security
- 50 Google Artifact Registry, In Depth: Repositories, Formats, Scanning & Cleanup Policies
- 51 Google Cloud Build & Cloud Deploy, In Depth: Pipelines, Triggers, Substitutions & Releases
- 52 GKE Autopilot in Production: A Hardening and Cost-Control Playbook
- 53 GKE Dataplane V2: Cilium-Based Network Policy and Observability
- 54 GKE Gateway API: Single and Multi-Cluster Traffic Management
- 55 GKE Workload Identity Deep Dive: Secure Pod-to-Google-API Access Without Keys
- 56 GCP Enterprise Architecture: Production Microservices on GKE
Tier 3 · Advanced — Data Engineering (PDE)
Engineer data: BigQuery performance & fine-grained access, and real-time analytics pipelines.
- 57 Google BigQuery, In Depth: Datasets, Tables, Partitioning, Slots & Pricing
- 58 Google Cloud Bigtable, In Depth: Schema, Row-Key Design, Performance & Replication
- 59 Google Cloud Dataflow, In Depth: Apache Beam, Streaming vs Batch, Windowing & Autoscaling
- 60 Taming BigQuery Cost and Performance: Partitioning, Clustering, and Reservations
- 61 BigQuery Fine-Grained Security: Column-Level, Row-Level, and Data Masking
- 62 GCP Enterprise Architecture: Real-Time Analytics
- 63 Real-Time Payments Fraud Scoring Pipeline on GCP
Tier 4 · Expert — Architecture Framework, Cost & System Design (PCA)
Architect to the framework: cost optimisation and end-to-end system design.
- 64 GCP Well-Architected: Cost Optimization — Cost Principles, Billing & Budgets, CUDs & Spot VMs, Right-Sizing, FinOps, and Cost Monitoring
- 65 GCP Well-Architected: System Design — Core Principles, Geography & Regions, the Resource Hierarchy, Networking Foundations, and Choosing Compute, Storage & Databases
Tier 4 · Expert — Landing Zones & Governance
Build the enterprise platform: the landing zone across resource hierarchy, identity, network, security and operations.
- 66 GCP Enterprise Architecture: Secure Foundation / Landing Zone
- 67 GCP Landing Zone: Resource Hierarchy — The Organization Node, Environment & Team Folders, Projects, and Design Trade-offs
- 68 GCP Landing Zone: Identity & Access — Cloud Identity, Groups, IAM, Service Accounts & Workload Identity Federation
- 69 GCP Landing Zone: Networking — Shared VPC, Hybrid Connectivity, Firewall Policies & Cloud DNS
- 70 GCP Landing Zone: Security & Guardrails — Org Policy Constraints, VPC Service Controls, Security Command Center, CMEK & Assured Workloads
- 71 GCP Landing Zone: Operations & Billing — Cloud Logging Sinks & Buckets, Cloud Monitoring, Billing Export & Budgets, and Org-Wide Observability
Tier 4 · Expert — Cloud Adoption Framework (CAF)
Lead the organisational journey: the CAF themes — learn, lead, scale, secure and the operating model.
- 72 GCP Cloud Adoption Framework: Learn Theme — Learning Programs at Scale, Partners, Certification & the Cloud CoE
- 73 GCP Cloud Adoption Framework: Lead Theme — Leadership & Governance, Mobilizing Teams, Cross-Functional Collaboration, and a Cloud Operating Model
- 74 GCP Cloud Adoption Framework: Scale Theme — Cloud-Native Adoption, Automation, CI/CD & Self-Service Operations
- 75 GCP Cloud Adoption Framework: Secure Theme — Advanced Security Posture, Identity/Network/Data Security, Compliance & Proactive Defense-in-Depth
- 76 GCP Cloud Adoption Framework: Operating Model & Epics — Designing the Cloud Operating Model, the Epic Backlog as Your Execution Engine, and Wiring It Into the Landing Zone & Enterprise Foundations Blueprint
Tier 4 · Expert — Resilience, DR & Migration
Design for failure and change: DR/resilience patterns and migration to Google Cloud.
Tier 4 · Expert — Enterprise Reference Architectures
Study complete designs: global web, peak-scale education, multi-tenant SaaS, and a centralised logging lake.
Tier 5 · Specialist — Data & Analytics (PDE)
Build the data platform: lakehouse, big data, and data mesh on Google Cloud.
Tier 5 · Specialist — AI/ML & Generative AI (PMLE)
Serve AI in production: Vertex AI MLOps, ML platforms, GenAI RAG, and recommendation engines.
- 86 Production MLOps on Vertex AI: Building Reproducible Training and Deployment Pipelines
- 87 GCP Enterprise Architecture: ML Platform / MLOps
- 88 GCP Enterprise Architecture: Generative-AI / RAG on Vertex AI
- 89 Product Recommendation Engine for Retail on GCP Vertex AI
- 90 GCP Enterprise Architecture: Retail Recommendation Engine
Tier 5 · Specialist — Integration & Industry Solutions
Domain solutions: API monetisation with Apigee and IoT analytics.
Track · Troubleshooting (Easy → Complex)
Diagnose anything: a method and per-area playbooks, then complex multi-service incident RCA.
Track · Architecting (Easy → Complex)
Turn requirements into designs: a six-rung ladder from a static site to multi-region global.
Track · Certification Center
Pass the exams: the CDL/ACE/PCA/PDE/Security prep kit with checklists, case studies and practice questions.
Track · Job-Ready — Projects & Capstone
Get hired: a six-project portfolio ladder and an enterprise landing-zone capstone.