# Console, gcloud, Cloud Shell and Infrastructure as Code — Google Cloud Platform

Source: https://www.skillbyai.com/en/gcp/f-tools

> Pick the right tool for exploring, scripting and repeatable infrastructure.

## Every tool calls the same APIs

The **Google Cloud console**, the **gcloud CLI**, client libraries and infrastructure-as-code tools all call the same per-service REST and gRPC **APIs**. **Cloud Shell** is a browser terminal with `gcloud`, `kubectl`, `terraform` and a small persistent home directory, already authenticated as you. Use the console to explore and learn, `gcloud` for scripts and one-off tasks, and **Terraform** (with the `google` provider) or Google's managed **Infrastructure Manager**, which runs Terraform for you, for repeatable environments. `gcloud` keeps named **configurations** (project, account, region), which helps when you switch between dev and prod. Application code uses **Application Default Credentials (ADC)**, which on a laptop come from `gcloud auth application-default login` and in Google Cloud come from the attached service account.

## The same bucket three ways

Bucket names are global across all of Google Cloud.

```bash
# gcloud
gcloud storage buckets create gs://shop-dev-assets-123 --location=asia-south1 \
  --uniform-bucket-level-access

# Terraform (main.tf)
resource "google_storage_bucket" "assets" {
  name                        = "shop-dev-assets-123"
  location                    = "asia-south1"
  uniform_bucket_level_access = true
}

# switching between environments
gcloud config configurations create prod
gcloud config set project shop-prod-654321
```

## Two different logins

`gcloud auth login` authenticates the CLI; `gcloud auth application-default login` creates the credentials your *code* uses locally. Forgetting the second one is a classic cause of "could not find default credentials".

**Quiz:** What do client libraries running on Cloud Run use to authenticate by default?

- [ ] A JSON key file checked into the repository
- [ ] The developer's personal password
- [x] Application Default Credentials from the attached service account
- [ ] The billing account ID

*Answer:* Application Default Credentials from the attached service account. ADC picks up the service account attached to the Cloud Run service, so no key file is needed.
