---
tags:
- cloud
- l1
- flashcard-deck
- gcp-kubernetes
---
<!-- wiki:breadcrumb:start -->
[Portal](../../../../library/portal/index.md) | **Level:** [L1: Foundations](../../../../library/portal/levels.md) | **Topics:** [GCP Troubleshooting](../../../../library/portal/topics.md) | **Domain:** Cloud
<!-- wiki:breadcrumb:end -->

id	category	difficulty	tags	question	answer	source_path
gcp-kubernetes/0ee1a410f413	gcp-kubernetes	easy	gcp,networking,kubernetes,security	List and explain the enterprise security capabilities provided by Anthos	* Control plane security - GCP manages and maintains the K8s control plane out of the box. The user can secure the api-server by using master authorized networks and private clusters. These allow the user to disable access on the public IP address by assigning a private IP address to the master.	projects/knowledge/interview/gcp/034-list-and-explain-the-enterprise-security-capabilit.txt
gcp-kubernetes/0fdd0a88238b	gcp-kubernetes	medium	gcp,iam	What is workload identity federation ?	Workload Identity Federation extends the capabilities of Workload Identity, enabling workloads to use external identity providers for authentication and authorization. It allows users to integrate their own identity systems with Google Cloud, enabling seamless and secure access to GCP resources based on their existing identity infrastructure.	projects/knowledge/interview/gcp/058-what-is-workload-identity-federation.txt
gcp-kubernetes/3181bb00ae00	gcp-kubernetes	hard	gcp,networking,kubernetes	Describe the two main components of Anthos Service Mesh	1. Data plane - it consists of a set of distributed proxies that mediate all inbound and outbound network traffic between individual services which are configured using a centralised control plane and an open API\n2. Control plane - is a fully managed offering outside of Anthos GKE clusters to simplify management overhead and ensure highest possible availability.	projects/knowledge/interview/gcp/040-describe-the-two-main-components-of-anthos-service.txt
gcp-kubernetes/3f4564fa99e1	gcp-kubernetes	hard	gcp,compute,storage,kubernetes	How do you enables logging for GCP resources ?	GCP provides Stackdriver Logging, which enables you to store, search, analyze, monitor, and alert on log data and events from GCP resources. It's the central logging solution for GCP, allowing you to collect logs from various services, such as Compute Engine, Kubernetes Engine, Cloud Storage, and more. You can enable logging at the project, folder, or organization level, and then configure which logs to collect and analyze using advanced filters and queries.	projects/knowledge/interview/gcp/060-how-do-you-enables-logging-for-gcp-resources.txt
gcp-kubernetes/4cbbab4af039	gcp-kubernetes	medium	gcp,networking,kubernetes,monitoring	What are flow logs? Where are they enabled?	VPC Flow Logs records a sample of network flows sent from and received by VM instances, including instances used as Google Kubernetes Engine nodes. These logs can be used for network monitoring, forensics, real-time security analysis, and expense optimization.\n\nEnable Flow Logs\n\n1. Open VPC Network in GCP Console\n\n2. Click the name of the subnet \n\n3. Click EDIT button\n\n4. Set Flow Logs to On\n\n5. Click Save	projects/knowledge/interview/gcp/022-what-are-flow-logs-where-are-they-enabled.txt
gcp-kubernetes/52bb71dcb53b	gcp-kubernetes	medium	gcp,compute,kubernetes,devops	How does Cloud Run for Anthos simplify operations?	Platform teams in organisations that wish to offer developers additional tools to test, deploy and run applications can use Knative to enhance this experience on Anthos as Cloud Run. Below are some of the benefits;	projects/knowledge/interview/gcp/045-how-does-cloud-run-for-anthos-simplify-operations.txt
gcp-kubernetes/56d5f36b974b	gcp-kubernetes	hard	gcp,iam,security	Describe GCP Workload Identity.	Workload Identity allows users to access GCP services from within workloads without requiring service account keys. It allows a higher level of security by associating service accounts with Google-managed service accounts, eliminating the need to manage service account keys explicitly. This feature streamlines the management of service account keys and enhances security by reducing the surface area for potential key exposure.	projects/knowledge/interview/gcp/136-describe-gcp-workload-identity.txt
gcp-kubernetes/5936ac713d6e	gcp-kubernetes	medium	gcp,kubernetes,devops	Explain Google Kubernetes Engine (GKE).	GKE is a managed Kubernetes service for deploying, managing, and scaling containerized applications using Kubernetes.\nFeatures that sets it apart:\n* Automated Operations: Manages the Kubernetes infrastructure, including upgrades and node provisioning.	projects/knowledge/interview/gcp/097-explain-google-kubernetes-engine-gke.txt
gcp-kubernetes/5b86928c5d7c	gcp-kubernetes	medium	gcp,kubernetes,security,devops	What is Binary Authorization ?	Binary Authorization is a GCP security feature that enforces deployment policies by validating container images before they're deployed to a Kubernetes engine. It ensures that only trusted and authorized container images are allowed to run in the Kubernetes environment. Binary Authorization uses attestations and signatures to verify that images meet specific criteria, such as being signed by a trusted authority or adhering to certain security and compliance standards, enhancing the security of t	projects/knowledge/interview/gcp/072-what-is-binary-authorization.txt
gcp-kubernetes/6149611df3d4	gcp-kubernetes	easy	gcp,kubernetes,monitoring,devops	What is Anthos Service Mesh?	* It is a suite of tools that assist in monitoring and managing deployed services on Anthos of all shapes and sizes whether running in cloud, hybrid or multi-cloud environments. It leverages the APIs and core components from Istio, a highly configurable and open-source service mesh platform.	projects/knowledge/interview/gcp/039-what-is-anthos-service-mesh.txt
gcp-kubernetes/6d4cc5bfb6ce	gcp-kubernetes	hard	gcp,kubernetes,security	Explain Anthos Config Management	It is a core component of the Anthos stack which provides platform, service and security operators with a single, unified approach to multi-cluster management that spans both on-premises and cloud environments. It closely follows K8s best practices, favoring declarative approaches over imperative operations, and actively monitors cluster state and applies the desired state as defined in Git. It includes three key components as follows:	projects/knowledge/interview/gcp/037-explain-anthos-config-management.txt
gcp-kubernetes/7eed57823ecd	gcp-kubernetes	medium	gcp,kubernetes,devops	Can you deploy Anthos on AWS?	* Yes, Anthos on AWS is now GA. For more read [here](https://cloud.google.com/anthos/gke/docs/aws)\n\nRemember: Anthos runs on GCP, AWS, Azure, and bare metal. True multi-cloud K8s management.\n\nGotcha: Anthos on AWS/Azure requires separate billing and additional setup. Pricing is per-vCPU of managed clusters.	projects/knowledge/interview/gcp/033-can-you-deploy-anthos-on-aws.txt
gcp-kubernetes/821a315f2426	gcp-kubernetes	hard	gcp,kubernetes,devops	What's the difference between Container Registry and Artifact Registry ?	Container Registry: Google Container Registry is a private container image registry. It's specifically designed to store, manage, and secure Docker container images, making them available for use in GCP. These images are commonly used with services like Google Kubernetes Engine (GKE) and other container-based solutions.	projects/knowledge/interview/gcp/085-whats-the-difference-between-container-registry-an.txt
gcp-kubernetes/82dbf349f3d1	gcp-kubernetes	medium	gcp,networking,kubernetes,devops	Which load balancing options are available?	* Networking load balancing for L4 and HTTP(S) Load Balancing for L7 which are both managed services that do not require\n  additional configuration.\n* Ingress for Anthos which allows the ability to deploy a load balancer that serves an application across multiple clusters\n  on GKE	projects/knowledge/interview/gcp/032-which-load-balancing-options-are-available.txt
gcp-kubernetes/8a0486cdb941	gcp-kubernetes	easy	gcp,kubernetes	What is Google Cloud Code and how does it help Kubernetes development?	It is a set of tools to help developers write, run and debug GCP kubernetes based applications. It provides built-in support for rapid iteration, debugging and running applications in development and production K8s environments.	projects/knowledge/interview/gcp/026-what-is-cloud-code.txt
gcp-kubernetes/8d8d1e12636a	gcp-kubernetes	hard	gcp,iam,kubernetes,devops	What role does Dataproc has in analytics ?	Google Cloud Dataproc is a managed Hadoop and Spark service. It's primarily used for big data processing and analytics. Dataproc simplifies the process of deploying and managing clusters, making it easier to run Spark and Hadoop jobs. It's beneficial for tasks like ETL (Extract, Transform, Load), machine learning, data exploration, and batch processing. Dataproc provides a scalable, cost-effective way to process large datasets.	projects/knowledge/interview/gcp/087-what-role-does-dataproc-has-in-analytics.txt
gcp-kubernetes/8dcabde40f0c	gcp-kubernetes	medium	gcp,compute,kubernetes	How does Anthos handle the control plane and node components for GKE?	On GCP the kubernetes api-server is the only control plane component exposed to customers whilst compute engine manages\ninstances in the project.\n\nRemember: GKE manages the control plane entirely — you never SSH into master nodes. Worker nodes run as Compute Engine VMs in your project.\n\nGotcha: In GKE Autopilot, even worker nodes are fully managed — you only define workloads.	projects/knowledge/interview/gcp/031-how-does-anthos-handle-the-control-plane-and-node-.txt
gcp-kubernetes/8f2c26607d96	gcp-kubernetes	hard	gcp,kubernetes,compute	Describe Traffic Director in GCP.	Traffic Director is a managed control plane for service mesh. It allows for global traffic management in a multi-cluster, multi-region, and multi-platform scenario. Traffic Director enables traffic routing, traffic shaping, and resiliency across services within a service mesh by using global load balancing and advanced traffic management policies. It's a critical component for high-performance, scalable, and reliable service-to-service communication in distributed architectures.	projects/knowledge/interview/gcp/132-describe-traffic-director-in-gcp.txt
gcp-kubernetes/8f74781e0d51	gcp-kubernetes	easy	gcp,kubernetes	What is Google Anthos and what multi-cloud capabilities does it provide?	It is a managed application platform for organisations like enterprises that require quick modernisation and certain levels\nof consistency for their legacy applications in a hybrid or multicloud world. From this explanation the core ideas can be drawn from these statements;	projects/knowledge/interview/gcp/028-what-is-anthos.txt
gcp-kubernetes/8f89dacbac6b	gcp-kubernetes	medium	gcp,kubernetes	How does Anthos Config Management help?	It follows common modern software development practices which makes cluster configuration, management and policy changes auditable, revertable, and versionable easily enforcing IT governance and unifying resource management in an organisation.	projects/knowledge/interview/gcp/038-how-does-anthos-config-management-help.txt
gcp-kubernetes/92c87a9de1e9	gcp-kubernetes	medium	gcp,networking,kubernetes,security	How can workloads deployed on Anthos GKE on-prem clusters securely connect to Google Cloud services?	* Google Cloud Virtual Private Network (Cloud VPN) - this is for secure networking\n* Google Cloud Key Management Service (Cloud KMS) - for key management\n\nRemember: Cloud VPN for encrypted tunnels, Cloud KMS for key management, Cloud Interconnect for dedicated high-bandwidth links.\n\nGotcha: Anthos on-prem still needs connectivity to GCP for management plane operations — it is not fully air-gapped.	projects/knowledge/interview/gcp/035-how-can-workloads-deployed-on-anthos-gke-on-prem-c.txt
gcp-kubernetes/aedd729922a8	gcp-kubernetes	medium	gcp,kubernetes,security	What is Google Anthos?	Anthos is a platform for managing applications across hybrid and multi-cloud environments. Anthos allows organizations to build and manage modern, cloud-native applications and workloads that run on GCP, on-premises, or other cloud platforms. It provides a consistent platform for application development, enabling operations across different environments with centralized management, security, and scalability.	projects/knowledge/interview/gcp/131-what-is-google-anthos.txt
gcp-kubernetes/bb88a2a901d2	gcp-kubernetes	hard	gcp,kubernetes,security	Describe Google Kubernetes Engine (GKE) Autopilot.	Autopilot is a managed environment for GKE that automates operational tasks for managing and scaling the Kubernetes cluster. It includes:\n* Automated Cluster Management: Manages resources, scaling, and optimization of clusters.\n* Improved Security: Adheres to best practices and provides automatic updates for security patches.\n* Simplified Experience: Reduces the complexities of managing and maintaining Kubernetes clusters.	projects/knowledge/interview/gcp/127-describe-google-kubernetes-engine-gke-autopilot.txt
gcp-kubernetes/bd1bca81fe7f	gcp-kubernetes	easy	gcp,kubernetes	What are the components of the managed control plane of Anthos Service Mesh?	1. Traffic Director - it is GCP's fully managed service mesh traffic control plane, responsible for translating Istio API objects into configuration information for the distributed proxies, as well as directing service mesh ingress and egress traffic	projects/knowledge/interview/gcp/041-what-are-the-components-of-the-managed-control-pla.txt
gcp-kubernetes/bdddfad08d1d	gcp-kubernetes	hard	gcp,kubernetes,compute,compute	Explain Google Cloud Dataproc.	Dataproc is a fast, easy-to-use, fully managed cloud service for running Apache Spark and Hadoop clusters.\n* Managed Clusters: Dataproc allows users to create, manage, and scale clusters quickly and easily.\n* Cost Efficiency: It provides a flexible and cost-effective solution by charging users only for the resources used.	projects/knowledge/interview/gcp/117-explain-google-cloud-dataproc.txt
gcp-kubernetes/c441e112b610	gcp-kubernetes	easy	gcp,compute,kubernetes	List some Cloud Run for Anthos use cases	As it does not support stateful applications or sticky sessions, it is suitable for running stateless applications such as:\n\n* Machine learning model predictions e.g Tensorflow serving containers\n* API gateways, API middleware, web front ends and Microservices\n* Event handlers, ETL	projects/knowledge/interview/gcp/047-list-some-cloud-run-for-anthos-use-cases.txt
gcp-kubernetes/c847c0ce4fd0	gcp-kubernetes	medium	gcp,kubernetes	How does Anthos Service Mesh help?	Tool and technology integration that makes up Anthos service mesh delivers significant operational benefits to Anthos environments, with minimal additional overhead such as follows:\n\nRemember: Anthos Service Mesh = managed Istio. Benefits: mTLS between services, traffic management, observability without application code changes.\n\nGotcha: ASM requires a minimum cluster size and adds resource overhead per sidecar proxy.	projects/knowledge/interview/gcp/042-how-does-anthos-service-mesh-help.txt
gcp-kubernetes/c998e2814012	gcp-kubernetes	easy	gcp,networking,kubernetes,devops	What is Island Mode configuration with regards to networking in Anthos GKE deployed on-prem?	"* This is when pods can directly talk to each other within a cluster, but cannot be reached from outside the cluster thus forming an ""island"" within the network that is not connected to the external network."	projects/knowledge/interview/gcp/036-what-is-island-mode-configuration-with-regards-to-.txt
gcp-kubernetes/cc98ac1e4940	gcp-kubernetes	easy	gcp,kubernetes,devops	What is Google Kubernetes Engine (GKE) and what does it provide?	* It is the managed kubernetes service on GCP for deploying, managing and scaling containerised applications using Google infrastructure.\n\nRemember: GKE = managed K8s. Google manages the control plane (API server, etcd, scheduler). You manage worker nodes (or use Autopilot for fully managed).\n\nGotcha: GKE Standard vs Autopilot: Standard = you manage nodes, Autopilot = Google manages nodes and charges per-pod.	projects/knowledge/interview/gcp/027-what-is-gke.txt
gcp-kubernetes/d17490b1fe06	gcp-kubernetes	easy	gcp,compute,kubernetes,cloud-functions	What is Cloud Run for Anthos?	It is part of the Anthos stack that brings a serverless container experience to Anthos, offering a high-level platform experience on top of K8s clusters. It is built with Knative, an open-source operator for K8s that brings serverless application serving and eventing capabilities.	projects/knowledge/interview/gcp/044-what-is-cloud-run-for-anthos.txt
gcp-kubernetes/d1adfa134500	gcp-kubernetes	medium	gcp,kubernetes,devops	List the technical components that make up Anthos	* Infrastructure management - Google Kubernetes Engine (GKE)\n* Cluster management - GKE, Ingress for Anthos\n* Service management - Anthos Service Mesh\n* Policy enforcement - Anthos Config Management, Anthos Enterprise Data Protection, Policy Controller\n* Application deployment - CI/CD tools like Cloud Build, GitLab\n* Application development - Cloud Code	projects/knowledge/interview/gcp/029-list-the-technical-components-that-make-up-anthos.txt
gcp-kubernetes/d276ddbba4a1	gcp-kubernetes	easy	gcp,compute,kubernetes	List and explain three high-level out of the box autoscaling primitives offered by Cloud Run for Anthos that do not exist in K8s natively	* Rapid, request-based autoscaling - default autoscalers monitor request metrics which allows Cloud Run for Anthos to handle spiky traffic patterns smoothly\n\nRemember: Cloud Run for Anthos adds serverless abstractions (scale-to-zero, request-based autoscaling, rapid cold start) on top of K8s.\n\nGotcha: Scale-to-zero means cold starts. For latency-sensitive workloads, set minScale >= 1.	projects/knowledge/interview/gcp/046-list-and-explain-three-high-level-out-of-the-box-a.txt
gcp-kubernetes/d3407ea78a2e	gcp-kubernetes	easy	gcp, control-flow	What are labels in Kubernetes and how are they used for organization?	"You can think about labels in GCP as sticky notes that you attach to different GCP resources. That makes it easier for example, to search for specific resources (like applying the label called ""web-app"" and search for all the resources that are related somehow to ""web-app"")"	projects/knowledge/interview/gcp/011-what-are-labels.txt
gcp-kubernetes/d7b96c527100	gcp-kubernetes	hard	gcp,kubernetes,security	Explain Anthos on GCP.	Anthos is a hybrid and multi-cloud platform enabling workload management across various environments. Key features include:\n* Modernization: It allows modernization of existing applications and development of new cloud-native apps.\n* Uniform Management: Anthos offers a consistent way to manage different types of infrastructure, whether on-premises or across multiple clouds.\n* Security and Compliance: Provides security and compliance across hybrid and multi-cloud environments.	projects/knowledge/interview/gcp/105-explain-anthos-on-gcp.txt
gcp-kubernetes/e4d8a7610864	gcp-kubernetes	easy	gcp,kubernetes,devops	What is the primary computing environment for Anthos to easily manage workload deployment?	* Google Kubernetes Engine (GKE)\n\nRemember: Anthos = multi-cloud K8s management. GKE = Google's managed Kubernetes. Anthos uses GKE under the hood.\n\nGotcha: Anthos can also manage on-prem clusters (Anthos on bare metal) and clusters on other clouds (Anthos on AWS).	projects/knowledge/interview/gcp/030-what-is-the-primary-computing-environment-for-anth.txt
gcp-kubernetes/ee26aece7de2	gcp-kubernetes	easy	gcp,kubernetes,devops	List possible use cases of traffic controls that can be implemented within Anthos Service Mesh	* Traffic splitting across differing service versions for canary or A/B testing\n* Circuit breaking to prevent cascading failures\n* Fault injection to help build resilient and fault-tolerant deployments\n* HTTP header-based traffic steering between individual services or versions	projects/knowledge/interview/gcp/043-list-possible-use-cases-of-traffic-controls-that-c.txt
gcp-kubernetes/fea4d9b111b2	gcp-kubernetes	medium	gcp,iam	What is workload identity ?	Workload Identity in GCP is a feature that allows Google Cloud workloads, such as applications or services running on Google Cloud, to assume identities in a secure and granular manner. It allows these workloads to access other Google Cloud resources based on defined permissions, without the need for service account keys, ensuring a more secure and manageable environment.	projects/knowledge/interview/gcp/057-what-is-workload-identity.txt

<!-- wiki:related:start -->
---

## Wiki Navigation

### Related Content

- GCP Compute Flashcards *(CLI)* (flashcard_deck, L1) — GCP Troubleshooting
- GCP General Flashcards *(CLI)* (flashcard_deck, L1) — GCP Troubleshooting
- GCP Networking Flashcards *(CLI)* (flashcard_deck, L1) — GCP Troubleshooting
- GCP Security Flashcards *(CLI)* (flashcard_deck, L1) — GCP Troubleshooting
- [GCP Troubleshooting](../../../../library/topics/gcp-troubleshooting/index.md) (Topic Pack, L1) — GCP Troubleshooting
- GCP Troubleshooting Flashcards *(CLI)* (flashcard_deck, L1) — GCP Troubleshooting

<!-- wiki:related:end -->
