पाठ 22 / 25

Delivery and Observability

Build and deploy with Cloud Build and observe workloads with Cloud Logging and Monitoring.

From commit to dashboards

Cloud Build runs build steps in containers from a cloudbuild.yaml, pushing images to Artifact Registry; triggers start builds on pushes or pull requests. Cloud Deploy adds managed delivery pipelines with promotion between targets (dev → staging → prod), approvals and rollbacks for GKE and Cloud Run. Google Cloud Observability collects telemetry: Cloud Logging gathers logs from services automatically (write structured JSON logs so fields become searchable), Cloud Monitoring stores metrics, dashboards, uptime checks and alerting policies with notification channels, while Cloud Trace, Cloud Profiler and Error Reporting cover latency, CPU/memory hot spots and grouped exceptions. Instrument applications with OpenTelemetry to send traces and metrics. Cloud Audit Logs record administrative actions and, when enabled, data access, answering who did what, where and when.

Build, deploy, observe

A commit triggers a build, the release is promoted through environments, and telemetry flows back to dashboards and alerts.

A loop of three stages: a gear block, a rocket-like arrow through three stepping stones, and a chart panel returning an arrow to the start.
Figure 8.1 — The delivery and observability loop.

A build config and a log query

The build pushes a tagged image and deploys it; the query finds recent errors for that service.

# cloudbuild.yaml
steps:
  - name: gcr.io/cloud-builders/docker
    args: [build, -t, asia-south1-docker.pkg.dev/$PROJECT_ID/apps/orders:$SHORT_SHA, .]
  - name: gcr.io/cloud-builders/docker
    args: [push, asia-south1-docker.pkg.dev/$PROJECT_ID/apps/orders:$SHORT_SHA]
  - name: gcr.io/google.com/cloudsdktool/cloud-sdk
    entrypoint: gcloud
    args: [run, deploy, orders-api, --image, asia-south1-docker.pkg.dev/$PROJECT_ID/apps/orders:$SHORT_SHA, --region, asia-south1]

# Logs Explorer query:
# resource.type="cloud_run_revision"
# resource.labels.service_name="orders-api"
# severity>=ERROR
# timestamp>="2026-10-01T00:00:00Z"

Log JSON, not prose

A line like {"severity":"ERROR","message":"payment failed","orderId":"o-1001"} written to stdout becomes a structured entry you can filter by jsonPayload.orderId. Free-text logs can only be searched as strings.

त्वरित जाँच: Which service records who changed an IAM policy and when?

  • Cloud Profiler
  • Cloud CDN
  • Cloud Audit Logs
  • Memorystore
Answer

Cloud Audit Logs — Admin Activity audit logs record configuration changes such as IAM policy updates.