पाठ 3 / 25
Console, gcloud, Cloud Shell and Infrastructure as Code
Pick the right tool for exploring, scripting and repeatable infrastructure.
Every tool calls the same APIs
The Google Cloud console, the gcloud CLI, client libraries and infrastructure-as-code tools all call the same per-service REST and gRPC APIs. Cloud Shell is a browser terminal with gcloud, kubectl, terraform and a small persistent home directory, already authenticated as you. Use the console to explore and learn, gcloud for scripts and one-off tasks, and Terraform (with the google provider) or Google's managed Infrastructure Manager, which runs Terraform for you, for repeatable environments. gcloud keeps named configurations (project, account, region), which helps when you switch between dev and prod. Application code uses Application Default Credentials (ADC), which on a laptop come from gcloud auth application-default login and in Google Cloud come from the attached service account.
The same bucket three ways
Bucket names are global across all of Google Cloud.
# gcloud
gcloud storage buckets create gs://shop-dev-assets-123 --location=asia-south1 \
--uniform-bucket-level-access
# Terraform (main.tf)
resource "google_storage_bucket" "assets" {
name = "shop-dev-assets-123"
location = "asia-south1"
uniform_bucket_level_access = true
}
# switching between environments
gcloud config configurations create prod
gcloud config set project shop-prod-654321Two different logins
gcloud auth login authenticates the CLI; gcloud auth application-default login creates the credentials your code uses locally. Forgetting the second one is a classic cause of "could not find default credentials".
त्वरित जाँच: What do client libraries running on Cloud Run use to authenticate by default?
- A JSON key file checked into the repository
- The developer's personal password
- Application Default Credentials from the attached service account
- The billing account ID
Answer
Application Default Credentials from the attached service account — ADC picks up the service account attached to the Cloud Run service, so no key file is needed.