← Professional Cloud Architect: architecture and operations
03 / 8 · 45 MIN

Networking, provisioning, and capacity

Explain network paths, delegation, and scaling limits before cutover.

Concept and mechanism

A network connection needs compatible addressing, routes, rules, name resolution, and identity. A–B and A–C peering does not create B–C transit. Peering also does not make a private DNS zone visible in every network. In Shared VPC, the host project holds networking and service projects host workloads; Network User can be limited to required subnets while resource-creation permissions remain separate. Private Service Connect endpoints let consumers initiate access to a published service without general peering. Do not confuse endpoints with PSC interfaces, which support another initiation direction. For hybrid connections, check overlapping prefixes and encryption scope. Interconnect does not encrypt by default; MACsec and HA VPN over Interconnect have scopes that must match the requirement.

Guided application

In a fictional daily close, the application scales but the shared database has limited capacity. Calculate potential connections per instance and reserve headroom for other consumers. In Cloud Run, low average CPU can hide one saturated core on a multi-vCPU instance; review concurrency and configuration using evidence. Spot fits interruption-tolerant work, but checkpoints do not guarantee capacity before 06:00. Define alternative capacity and when to switch. For ML, orchestrate identifiable steps with data, code, parameters, artifacts, and promotion criteria. Additional GPUs do not replace provenance or model evaluation. In each case, provisioning the resource is only part of delivery: demonstrate connectivity, load behavior, and operational capability before acceptance.

IN PRACTICE

40 instances with pools of 20 can request 800 connections; a database with 400 free cannot sustain that configuration.

Common pitfalls

Peering as transit; private network as encryption; application scaling as scaling every dependency.

Related topics: Requirements, costs, and platform selection · Data, resilience, and events · Identity, perimeters, and keys

Take this idea with you

Validate the complete path and coordinate capacity across components.

Create account

Reference: Shared VPC · Current linked standard guide; edition date unconfirmed (2026-09-30 inspection)