Google Cloud is Every Retailer's Most Trusted Cloud - Build What's Next
Blog

Google Cloud is Every Retailer’s Most Trusted Cloud

6617

Of your peers have already read this article.

3:00 Minutes

The most insightful time you'll spend today!

If you missed the July Google Cloud Retail Summit, here's a post on insights on Google Cloud as the most trusted cloud for retailers. From allowing data control to protecting apps with its in-built technology, Google Cloud is best for retailers!

Whether they were ready for it or not, the COVID-19 pandemic transformed many retailers into digital businesses. Retailers made huge investments into commerce technologies, customer experience tools, sales and fulfillment technology, and improving digital experiences to continue providing their goods and services to their customers. Now, more than a year into the COVID-19 pandemic, digital retail is the new normal. In fact, many retailers are planning on expanding their digital investments. However, as their digital footprint expands, so do their threats and security concerns. 

As a digital-focused retailer, your website is the most visible part of your attack surface. Your website is where your customers search for goods or services, make payments, or learn more about your brand. However, your website does not operate in isolation. There is an underlying infrastructure as well as the services that run on top of it that need protection from a wide array of attacks that may seek to compromise your data, internal employees, business, and customers. During this week’s Google Cloud Retail Summit, we’ve shared why Google Cloud is built to be the most trusted cloud for retailers. From providing you with control over your data as you move from your own data centers to the public cloud to giving you built-in technology to protect your applications all the way to your end users, Google Cloud helps you safely migrate to and operate in our Trusted Cloud.

Trusted Cloud Gives You Control, Transparency, and Sovereignty

  • Access Transparency: We offer the ability to monitor and approve access to your data or configurations by Google Cloud support and engineering based on specific justifications and context, so you have visibility and control over insider access. 
  • Certificate Authority Service (CAS): CAS is a highly scalable and available service that simplifies and automates the management and deployment of private CAs while meeting the needs of modern developers and applications. With CAS, you can offload to the cloud time-consuming tasks associated with operating a private CA, like hardware provisioning, infrastructure security, software deployment, high-availability configuration, disaster recovery, backups, and more, allowing you to stand up a private CA in minutes, rather than the months it might normally take to deploy.
https://youtube.com/watch?v=m8LiWfdL5AE%3Fenablejsapi%3D1%26
  • Confidential Computing: We already encrypt data at-rest and in-transit, but customer data needs to be decrypted for processing. Confidential Computing is a breakthrough technology which encrypts data in-use—while it’s being processed. Confidential VMs take this technology to the next level by offering memory encryption so that you can further isolate your workloads in the cloud. With the beta launch of Confidential VMs, we’re the first major cloud provider to offer this level of security and isolation while giving you a simple, easy-to-use option for your newly built and “lift and shift” applications.
https://youtube.com/watch?v=o3NXEgbvdmQ%3Fenablejsapi%3D1%26
  • Cloud Key Management: We allow you to configure the locations where your data is stored, where your encryption keys are stored, and where your data can be accessed from. We give you the ability to manage your own encryption keys, even storing them outside Google’s infrastructure. Using our External Key Management service, you have the ability to deny any request by Google to access encryption keys necessary to decrypt customer data at rest for any reason.

Trusted cloud Helps You Prevent, Detect, and Respond to Threats

  • BeyondCorp Enterprise is Google’s comprehensive zero trust product offering. Google has over a decade of experience managing and securing cloud applications at a global scale, and this offering was developed based on learnings from our experience managing our own enterprise, feedback from customers and partners, as well as informed by leading engineering and security research. We understand that most customers host resources across different cloud providers. With this in mind, BeyondCorp Enterprise was purpose-built as a multicloud solution, enabling customers to securely access resources hosted not only on Google Cloud or on-premises, but also across other clouds such as Azure and Amazon Web Services (AWS).
https://youtube.com/watch?v=TtmsV-xq0r0%3Fenablejsapi%3D1%26
  • Cloud Armor: We’re simplifying how you can use Cloud Armor to help protect your websites and applications from exploit attempts, as well as Distributed Denial of Service (DDoS) attacks. With Cloud Armor Managed Protection Plus, you will get access to DDoS and WAF services, curated rule sets, and other services for a predictable monthly price.
https://youtube.com/watch?v=oXJ68Sa8jfU%3Fenablejsapi%3D1%26
  • Chronicle: Chronicle is a threat detection solution that identifies threats, including ransomware, at unparalleled speed and scale. Google Cloud Threat Intelligence for Chronicle surfaces highly actionable threats based on Google’s collective insight and research into Internet-based threats. Threat Intel for Chronicle allows you to focus on real threats in the environment and accelerate your response time.
  • Google Workspace Security: Used by more than five million organizations worldwide, from large banks and retailers with hundreds of thousands of people to fast-growing startups, Google Workspace and Google Workspace for Education include the collaboration and productivity tools found here. Google Workspace and Google Workspace for Education are designed to help teams work together securely in new, more efficient ways, no matter where members are located or what device they use. For instance, Gmail scans over 300 billion attachments for malware every week and prevents more than 99.9% of spam, phishing, and malware from reaching users. We’re committed to protecting against security 1 threats of all kinds, innovating new security tools for users and admins, and providing our customers with a secure cloud service.
  • Identity & Access Management IAM: Identity and Access Management (IAM) lets administrators authorize who can take action on specific resources, giving you full control and visibility to manage Google Cloud resources centrally. For enterprises with complex organizational structures, hundreds of workgroups, and many projects, IAM provides a unified view into security policy across your entire organization, with built-in auditing to ease compliance processes.
  • reCAPTCHA Enterprise: reCAPTCHA has over a decade of experience defending the internet and data for its network of more than 5 million sites. reCAPTCHA Enterprise builds on this technology with capabilities, such as two-factor authentication and mobile application support, designed specifically for enterprise security concerns. With reCAPTCHA Enterprise, you can defend your website against common web-based attacks like credential stuffing, account takeovers, and scraping and help prevent costly exploits from malicious human and automated actors. And, just like reCAPTCHA v3, reCAPTCHA Enterprise will never interrupt your users with a challenge, so you can run it on all webpages where your customers interact with your services.
https://youtube.com/watch?v=VDNsBRQ3yFk%3Fenablejsapi%3D1%26
  • Security Command Center: With Security Command Center (SCC), our native posture management platform, you can prevent and detect abuse of your cloud resources, centralize security findings from Google Cloud services and partner products, and detect common misconfigurations, all in one easy-to-use platform. We have Premium tier for Security Command Center to provide even more tools to protect your cloud resources. It adds new capabilities that let you spot threats using Google intelligence for events in Google Cloud Platform (GCP) logs and containers, surface large sets of misconfigurations, perform automated compliance scanning and reporting. These features help you understand your risks on Google Cloud, verify that you’ve configured your resources properly and safely, and document it for anyone who asks.
https://youtube.com/watch?v=4nelxX_1erk%3Fenablejsapi%3D1%26
  • VirusTotal: VirusTotal inspects items with over 70 antivirus scanners and URL/domain blocklisting services, in addition to a myriad of tools to extract signals from the studied content. Any user can select a file from their computer using their browser and send it to VirusTotal.
  • Web Risk API: With Web Risk, you can quickly identify known bad sites, warn users before they click infected links, and prevent users from posting links to known infected pages from your site. Web Risk includes data on more than a million unsafe URLs and stays up to date by examining billions of URLs each day.

Trusted cloud Plays an Active Role in Our Shared Fate 

Our trusted cloud provides a shared-fate model for risk management. We stand with retailers from day one, helping them implement best practices for safely migrating to and operating in our trusted cloud.

We hope you enjoy the sessions we’ve created for you with Google Cloud Retail Summit and that they help you understand the ways our trusted cloud can help secure retailers all over the world.

3487

Of your peers have already watched this video.

1:30 Minutes

The most insightful time you'll spend today!

Case Study

How Carrefour is Building the Future of Retail on Google Cloud

Multinational retailer Carrefour was facing the challenge of meeting increasing customer expectations and realized that it needed to innovate faster. That’s when the company decided to move its SAP workloads to Gooogle Cloud.

As a result, Carrefour transformed over 1,000 stores and redesigned its back office management with SAP on Google Cloud. Not just that, it also realized the added benefits of flexibility, agility, and disaster recovery.

Watch this video as Carrefour executives explain why they decided to move SAP to Google Cloud and the benefits the company derived.

Case Study

Tencent Africa Cuts Cost and Improves Stability with Google Cloud

3428

Of your peers have already read this article.

3:00 Minutes

The most insightful time you'll spend today!

When Tencent Africa began to grow beyond the limits of its infrastructure, it turned to Google Cloud Platform to provide a stable, highly scalable solution, which cuts costs and latency.

About Tencent Africa

Tencent Africa is dedicated to making every day easier for customers and brands. Opening its doors in 2013 as WeChat Africa, the company is responsible for WeChat operations on the continent.

Industries: Technology
Location: South Africa

About Siatik Systems

Founded in 2008, South Africa-based Siatik Systems is a leading Google Cloud Platform solutions provider with a focus on cloud integration services, information technology consulting services, and bespoke software engineering solutions.

Industries:
Location:

Google Cloud Results

  • Reduced latency in its service from 180 to 35 milliseconds with powerful hardware and a fast, global network from Google Cloud Platform
  • Cut costs with per-minute billing and sustained use discounts
  • Increased the speed of provisioning new servers with easy-to-use interface of Google Compute Engine
Slashed service latency from 180 to 35 milliseconds

As one of Africa’s leading technology companies, Tencent Africa is responsible for WeChat operations on the continent. WeChat Africa has successfully launched a number of features including the WeChat Wallet, a mobile payment service for smartphones, which enables seamless and secure transactions for friends to send money to one another, cash money out at Standard Bank ATMs, use at accredited retailers, and make purchases from any SnapScan merchant in South Africa. Under the new name, Tencent Africa recently launched two new mobile products, JOOX, a mobile music streaming application, and VOOV, a social live streaming application.

When China’s Tencent brought its hugely popular instant messaging service WeChat to South Africa, it faced a near saturated market. To gain traction, Tencent Africa had to showcase WeChat’s versatility as a platform that goes far beyond just instant messaging. Engaging with local financial partners helped WeChat launch a WeChat Wallet to facilitate electronic payments, while providing exclusive content from South African cultural figures helped bring the platform extra publicity.

As WeChat started to grow its customer base, its on-premises infrastructure was stretched beyond its limits and the company looked for a cloud-based solution. After evaluating all its options, Tencent Africa found Google Cloud Platform best suited its needs.

“We’re a growing business and constantly upgrading our infrastructure. Getting new servers was becoming quite expensive so we wanted a cloud-based solution to reduce costs,” says Christoff Albertyn, Head of Technology at Tencent Africa. “When we did some latency testing, Google came out on top, so it made sense to go with them. Everybody loves Google, it’s a great brand. Just knowing a company like Google is behind it gives you peace of mind.”

“Siatik was a great partner to work with. Any questions I had, I could just pick up the phone and whatever it was they’d help me out. They were also able to get some of the team from Google to come to our offices and see how we worked, which was really good.”
-Christoff Albertyn, Head of Technology, Tencent Africa

Building a platform to scale

Instant messaging services need a stable infrastructure, the ability to scale at speed, and lightning fast performance. When Tencent Africa built an Official Accounts API to run a number of services on WeChat, to help companies engage with users on the platform, latency was its main concern. The Official Accounts services had to deliver replies over WeChat in under five seconds or the connection would drop.

Between the API on-premises servers in South Africa and WeChat’s main servers in China, Tencent Africa’s services regularly hit the limits of the permissible response time. In addition, by 2015, WeChat was starting to garner more customers across South Africa and Tencent Africa had to provision more servers. The on-premises servers were simply being asked to do too much, and expansion was proving expensive, so the company looked for a cloud-based solution.

Before committing to anything, Tencent Services did a thorough latency test of several cloud-based solutions. Google Cloud Platform came top. Tencent also engaged the help of Siatik, a Google Partner, to gauge what solutions best fit the company’s needs and help implement them. Siatik customers span both the public and private sectors and its consultants are regularly engaged in the health care, education, financial and technology industries. In order to provide leading technology solutions, it partners with industry leaders, such as Google, to provide best-of-breed infrastructure and cloud platform solutions to its customers.

“Siatik was a great partner to work with,” says Christoff. “Any questions I had, I could just pick up the phone and whatever it was they’d help me out. They were also able to get some of the team from Google to come to our offices and see how we worked, which was really good.”

“From day one, it was very smooth. The interface was amazing—Google must have spent a long time perfecting it because it was so easy to use. I set up the first virtual machine in no time without any struggles.”
-Christoff Albertyn, Head of Technology, Tencent Africa

With a simple, clean interface in Google Compute Engine, the company was able to spin up virtual instances very quickly and begin migrating its stack to Google. When it became more comfortable with Google Cloud Platform features, Tencent used Google Cloud SQL and Google BigQuery to manage its data streams, and Google Cloud Storage to store them safely.

From day one, it was very smooth. The interface was amazing—Google must have spent a long time perfecting it because it was so easy to use says Christoff. “I set up the first virtual machine in no time without any struggles.”

In addition to powerful hardware from Google Compute Engine, the fast, global network from Google helped to speed up performance. With the infrastructure ported over to Google, Tencent also brought in G Suite as an office productivity solution, which eased the pressure on its servers even more. Throughout the process, Siatik were on hand to advise and provide technical guidance whenever any issues came up.

What I really like is how quickly you can spin servers up. There’s no messing about and the interface is really easy to use, says Christoff. “You can have a virtual machine running in just a few minutes. It’s very impressive.”

Cutting costs, raising expectations

Google Cloud Platform helped Tencent Africa to slash its latency. Before the migration, pings to the Chinese servers and back would regularly take 180 milliseconds. Afterwards, this fell to around 35 milliseconds, helping to ensure smooth service to Tencent’s South African customers. Google offers innovative pricing, such as per-minute billing and sustained use discounts, which helped significantly cut server costs compared to an equivalent on-premises solution.

As its customer base grew, and Tencent Africa began to release new products, the ease of use of Google Compute Engine meant that spinning up new servers took minutes instead of hours and allowed the company to scale up and down at speed. Exploring products such as Kubernetes for rapid deployment or TensorFlow for machine learning, Tencent Africa continues to evolve and experiment with new products to keep WeChat a growing success in South Africa.

“Initially, we just used per-minute billing, but when I saw how much work we were doing with Google BigQuery and Google Cloud SQL, we started to generate sustained-use discounts, which helped save us a lot of money,” says Christoff. “The other great thing is, Google Cloud Platform monitors how you’re using it and tells you what else you can do to reduce costs.”

Case Study

EyecareLive Sees a Brighter Future in the Cloud with Enhanced Support

2947

Of your peers have already read this article.

3:30 Minutes

The most insightful time you'll spend today!

Enhanced Support gave EyecareLive unlimited, fast access to expert support from a team of experienced Google Cloud engineers during the intricate, multifaceted migration. Read more...

EyecareLive transforms the healthcare ecosystem with Enhanced Support, a support service from the Google Cloud Customer Care portfolio.

Telemedicine is now mainstream. It exploded during the COVID-19 pandemic. A 2022 survey by Jones Lang Lasalle (registration required) found that 38% of U.S. patients were using some form of telemedicine. This number is expected to grow as consumers are demanding more convenient and immediate access to care, and doctors are seeking efficiencies, cost savings, and to forge closer relationships with patients.

But because the eye-care field is so heavily regulated, optometrists and ophthalmologists face more technical hurdles to perform telemedicine than their peers in other medical practices.

To join the telemedicine revolution, a generic technology solution wouldn’t do. Eye-care professionals need a more carefully architected and rigorously secure platform – one that ensures a very high degree of compliance and privacy.

EyecareLive provides exactly that. Their comprehensive cloud-based solution was built specifically for eye-care telemedicine practices. They not only facilitate telemedicine visits with patients via video, but help providers stay in compliance with complex industry regulations.

What’s more, EyecareLive is the only platform in the industry that conducts vision screening using Food and Drug Administration (FDA)-registered tests to check a patient’s vision before connecting them to a doctor through a video call. The doctor can thus triage any issues immediately and quickly determine the right next steps for proper care. In addition, their platform digitally connects optometrists and ophthalmologists to the entire eye-care ecosystem, including other doctors for referrals, insurance companies, hospitals, pharmaceutical firms, pharmacies, and, of course, patients.

On top of all of this, the automated back office for their eye-care practices processes electronic health records (EHRs), clinical workflow, billing, coding, and more into one platform. EyecareLive streamlines operations and frees up doctors to focus on delivering the highest possible eye healthcare and on building stronger relationships with patients.

“Considering the number of plug-and-play services that Google has built into the Google Cloud Healthcare solutions, Google is basically supporting the entire healthcare industry from an infrastructure provider point of view.” — Raj Ramchandani, CEO, EyecareLive

Seeking greater agility, EyecareLive migrated to Google Cloud

EyecareLive is truly cloud first. They had operated entirely in the AWS cloud since opening their doors in 2017. Several years in, they decided to look for an additional cloud provider with broader support for digital health platforms. They specifically wanted to migrate to one they could rely on to deliver plug-and-play services, which would accelerate innovation of their platform. Rather than re-architecting for a new cloud, EyecareLive wanted a cloud platform that would offer compatible services they could use to meet their needs for reliability and availability.

“If we want to deploy a new conversational bot or build AI models that assist doctors to diagnose based on a retina image, Google Cloud provides these services which are reliable and tested by Google Cloud Healthcare solutions in many cases.” — Raj Ramchandani, CEO, EyecareLive

Versatility was another requirement. The EyecareLive platform must fulfill the demands of a variety of organizations — doctors, pharmaceutical companies, clinics, and others. EyecareLive also has an international deployment strategy that goes far beyond offering a domestic telehealth solution. Therefore EyecareLive needed a cloud functionality that extended into the broader global eye-care ecosystem.

EyecareLive chose Google Cloud. The most compelling reason was the deep industry expertise found in Google Cloud for healthcare and life sciences. This distinguished Google Cloud from all other possible cloud providers considered by EyecareLive. “We like Google Cloud because of the differentiations such as Google Cloud Healthcare solutions, computer vision, and AI models that can be used out of the box,” says Raj Ramchandani, CEO of EyecareLive. “We found these features more robust for our use cases on Google Cloud than any other.”

“Google is heavily into its Healthcare Cloud. That’s what differentiates it. We love that part because we can tap into innovative healthcare cloud functionality quickly.” — Raj Ramchandani, CEO, EyecareLive

Key to production deployment (and beyond): Google Cloud Enhanced Support

As a cloud-born company, EyecareLive had an exceedingly tech-savvy team. But the migration was a complex one that involved migrating third-party software and networking products that were tightly integrated into EyecareLive’s own code. The team knew it needed expert help with the migration. What’s more, doctors, patients, and other users required 24/7 access to the platform, and any interruptions to availability or infrastructure hiccups during the migration would disrupt their online experiences. However, the EyecareLive team was already stretched by continuing to grow and innovate the business, so they asked Google Cloud for help.

EyecareLive purchased Enhanced Support, a support service offered by the Google Cloud Customer Care portfolio. Specifically designed for small and midsized businesses (SMBs). Enhanced Support gave EyecareLive unlimited, fast access to expert support from a team of experienced Google Cloud engineers during the intricate, multifaceted migration.

“It was my top priority to engage Google Cloud Customer Care to help us keep the platform always available for our doctors and users,” says Ramchandani. “The level of detail to the answers, the clarifications of having the Enhanced Support experts tell us to do it a certain way has been enormously helpful.”

For example, one of the valuable features delivered by Enhanced Support is Third-Party Technology Support, which gives EyecareLive access to experts with specialized knowledge of third-party technologies, such as networking, MongoDB, and infrastructure. This meant all components in EyecareLive’s infrastructure could be seamlessly migrated to Google Cloud, and afterward EyecareLive could lean on Enhanced Support experts to continue to troubleshoot and mitigate issues as necessary.

“The response times to the questions and issues we had when going live was fantastic. It was the best experience with a tech vendor we’ve had in a long time.” — Raj Ramchandani, CEO, EyecareLive

With Enhanced Support at their side, EyecareLive was able to get up and running quickly in preparation for their international expansion by using Google Cloud’s prebuilt AI models, load balancers, and networking technologies that were designed to be easily deployed across multiple regions throughout the globe. “We know exactly how to implement data locality to scale our deployment into different regions and into different countries, because we’ve learned that from the Google Cloud support team.” — Raj Ramchandani, CEO, EyecareLive

EyecareLive then proceeded to rapidly scale their business, knowing that Google Cloud would ensure they could meet compliance standards in whatever country or region they expanded into.

“Since we’ve moved to Google Cloud and chose Enhanced Support, we’ve had 100% availability. That’s zero downtime, which is incredible.” — Raj Ramchandani, CEO, EyecareLive

Enhanced Support also provided the capabilities for EyecareLive to:

  • Resolve issues and minimize any unplanned downtime to maintain a high-quality, secure experience for doctors and patients during and after migration
  • Acquire fast responses to questions from technical support experts
  • Learn from guidance from the Enhanced Support team beyond immediate technical issues

EyecareLive builds momentum toward their vision for eye-care telemedicine

By working closely with the Google Cloud Enhanced Support team, EyecareLive was able to successfully migrate their platform.

“If you ask any of my engineers which cloud provider they prefer, they’d all respond ‘Google Cloud,’” says Ramchandani. “The documentation is there, the sample code is there, everything that we need to get started is available.”

EyecareLive was then able to go on to grow and scale their business in the cloud in the following ways:

  • Successfully managed a complex migration with minimal disruption and maximum availability, ensuring a consistent, secure, and compliant-ready experience for doctors and patients
  • Gained the trust of both doctors and patients – they know that EyecareLive protects their sensitive medical data
  • Kept EyecareLive agile and focused on innovating forward rather than building new features from scratch by supporting the team as they took advantage of Google’s tailored, plug-and-play technologies
  • Analyzed performance over time to plan for future growth by partnering with Enhanced Support for the long term

“We know we can rely on Google Cloud from a security point of view. We love the fact that Google Cloud Healthcare solution is HIPAA compliant. Those are the things that make us trust Google to do the right thing.” — Raj Ramchandani, CEO, EyecareLive

With Enhanced Support, EyecareLive sees a bright future in the cloud

With the help of Enhanced Support, EyecareLive brings digital transformation to the eye-care in the healthcare industry by integrating the entire ecosystem of eye-care partners onto one platform making EyecareLive a leader in their industry.

Learn more about Google Cloud Customer Care services and sign up today.

Blog

What You Need to Know About Compute Engines

6540

Of your peers have already read this article.

1:30 Minutes

The most insightful time you'll spend today!

What are Compute Engines? How do they help you create and run virtual machines (VMs) that best fit your requirements? Find all your answers and insights from use cases and documentation on Compute Engine in this blog!

Compute Engine is a customizable compute service that lets you create and run virtual machines on Google’s infrastructure. You can create a Virtual Machine (VM) that fits your needs. Predefined machine types are pre-built and ready-to-go configurations of VMs with specific amounts of vCPU and memory to start running apps quickly. With Custom Machine Types, you can create virtual machines with the optimal amount of CPU and memory for your workloads. This allows you to tailor your infrastructure to your workload. If requirements change, using the stop/start feature you can move your workload to a smaller or larger Custom Machine Type instance, or to a predefined configuration.

Compute engine sketch
Click to enlarge

Machine types

In Compute Engine, machine types are grouped and curated by families for different workloads. You can choose from general-purpose, memory-optimized, compute-optimized and accelerator-optimized families. 

  • General-purpose machines are used for Day-to-day computing at a lower cost and for balanced price/performance across a wide range of VM shapes. The use cases that best fit here are web serving, app serving, back office applications, databases, cache, media-streaming, microservices, virtual desktops, development environments.
  • Memory-Optimized machine are recommended for ultra high-memory workloads such as in-memory analytics and large in-memory databases such as SAP HANA 
  • Compute-Optimized machines are recommended for ultra high performance workloads such as High Performance Computing (HPC), Electronic Design Automation (EDA), gaming, video transcoding, single-threaded applications.
  • Accelerator-Optimized machines are optimized for high performance computing workloads such as Machine learning (ML), Massive parallelized computations and High Performance Computing (HPC)

How does it work?

You can create a VM instance using a boot disk image, a boot disk snapshot, or a container image. The image can be a public operating system (OS) image or a custom one. Depending on where your users are you can define the zone you want the virtual machine to be created in. By default all traffic from the internet is blocked by the firewall and you can enable the HTTP(s) traffic if needed. 

Use snapshot schedules (hourly, daily, or weekly) as a best practice to back up your Compute Engine workloads. Compute Engine offers live migration by default to keep your virtual machine instances running even when software or hardware update occurs. Your running instances are migrated to another host in the same zone instead of requiring your VMs to be rebooted. 

Availability

For High Availability (HA) Compute Engine offers automatic failover to other regions or zones in event of a failure. Managed instance groups (MIGs) help keep the instances running by automatically replicating instances from a predefined image. They also provide application based autohealing health checks. If an application is not responding on a VM, the auto healer automatically recreates that VM for you. Regional MIGs let you spread app load across multiple zones. This replication protects against zonal failures. MIGs work with load balancing services to distribute traffic across all of the instances in the group. 

Compute Engine offers autoscaling to automatically add or remove VM instances from a managed instance group based on increases or decreases in load. Autoscaling lets your apps gracefully handle increases in traffic, and it reduces cost when the need for resources is lower. You define the autoscaling policy for automatic scaling based on the measured load, CPU utilization, requests per second or other metrics.

Active Assist’s new feature, predictive autoscaling, helps improve response times for your applications–When you enable predictive autoscaling, Compute Engine forecasts future load based on your Managed Instance Group’s (MIG) history and scales it out in advance of predicted load, so that new instances are ready to serve when the load arrives. Without predictive autoscaling, an autoscaler can only scale a group reactively, based on observed changes in load in real time. With predictive autoscaling enabled, the autoscaler works with real-time data as well as with historical data to cover both the current and forecasted load. That makes predictive autoscaling ideal for those apps with long initialization times and whose workloads vary predictably with daily or weekly cycles. For more information, see How predictive autoscaling works or check if predictive autoscaling is suitable for your workload, and to learn more about other intelligent features, check out Active Assist.

Pricing

You pay for what you use. But you can save cost by taking advantage of some discounts! Sustained use saving are automatic discounts applied for running instances for a significant portion of the month. If you know your usage upfront, you can take advantage of committed use discounts which can lead up to significant savings without any upfront cost. And by using short lived preemptive instances you can save up to 80%, they are great for batch jobs and fault tolerant workloads. You can also optimize resource utilization with automatic recommendations. For example if you are using a bigger instance for a workload that can run on a smaller instance you can save costs applying these recommendations.

Security

Compute Engine provides you default hardware security. Using Identity and Access Management (IAM) you just have to ensure that proper permissions are given to control access to your VM resources. All the other basic security principles apply, if the resources are not related and don’t require network communication amongst themselves, consider hosting them on different VPC networks. By default, users in a project can create persistent disks or copy images using any of the public images or any images that project members can access through IAM roles. You may want to restrict your project members so that they can create boot disks only from images that contain approved software that meet your policy or security requirements. You can define an organization policy that only allows Compute Engine VMs to be created from approved images. This can be done by using the Trusted Images Policy to enforce images that can be used in your organization. 

By default all VM families are Shielded VMs. Shielded VMs are virtual machine instances that are hardened with a set of easily configurable security features to ensure that when your VM boots, it’s running a verified bootloader and kernel — is the default for everyone using Compute Engine, at no additional charge. For more details on Shielded VMs refer to the documentation here.

For additional security, you also have the option to use Confidential VM to encrypt your data in use, while it’s being processed in Compute Engine. For more details on Confidential VM refer to the documentation here.

Use cases

There are many use cases Compute Engine can serve in addition to running websites and databases. You can also migrate your existing systems onto Google Cloud, with Migrate for Compute Engine, enabling you to run stateful workloads in the cloud within minutes rather than days or weeks. Windows, Oracle or VMware applications have solution sets enabling a smooth transition to Google Cloud. To run windows applications either bring your own license leveraging Sole-tenant nodes or using the included licenced images. 

Conclusion

Whatever your application use case may be, from legacy enterprise applications to digital native applications, Compute Engine’s families will fit it. For a more in-depth look into Compute Engine check out the documentation

For more #GCPSketchnote, follow the GitHub repo. For similar cloud content follow me on Twitter @pvergadia and keep an eye out on thecloudgirl.dev

3939

Of your peers have already watched this video.

40:00 Minutes

The most insightful time you'll spend today!

Webinar

Attention CFOs: How to Save Money on the Cloud

Cutting down on wastage, saving cost, and having a better control are some of the key priorities of organizations when it comes to the cloud. According to the 2018 State of the Cloud report by Rightscale, 35% of customer cloud spend is wasted, 58% of users cite cost savings as their top focus, and 76% consider spend control to be a challenge.

No wonder, customers are constantly looking to control costs and get the most capability out of every cloud dollar spent by their organizations.

Google Cloud’s simple, flexible, and fair pricing principles ensure that customers end up saving a lot more when they use Google Cloud and pay only for what they use and nothing more. Automatic discounts, recommendations, and smart tools to monitor and control usage, ensure that customers are treated fairly.

Watch this webinar to find out how you can save even more money on the cloud.

More Relevant Stories for Your Company

Case Study

How Sri Lanka’s Largest Ride-hailing Company Fixed its App and Improved Business

PickMe is Sri Lanka's largest ride-hailing company. “(Almost) every Sri Lankan is our customer. We have passengers who use us on a daily basis. We have drivers who use the platform to make a living. So obviously, the ecosystem is pretty big,” says Jiffry Zulfe, Founder & CEO, PickMe. Before

Blog

Google Cloud Announces Improvements in Private Catalog to Drive Terraform Deployments

As an enterprise admin, when you choose to use Google Cloud Private Catalog to enable curated, self-serve Google Cloud infrastructure provisioning, you need the ability to manage your organization’s deployments. Today, we’re pleased to announce support for several improvements to Terraform driven deployments through Private Catalog.  With this new release, you can

Blog

Unlocking Economic Potential: Cloud FinOps

Built for a CapEx world, most organizations’ finance systems aren’t set up to take advantage of cloud’s dynamic, OpEx-driven consumption patterns. Practicing Cloud FinOps can unlock the business value latent in adopting public cloud. GETTY It may not be a household name yet, but chances are you’ve crossed paths with OpenX

Case Study

Beany’s Cloud-Based Accounting Solutions Transform Small Business Finance

Many people start a small business that aligns with their passions, but soon discover the day-to-day running of a business is very different than anticipated. Dealing with accounting, finance, and other daily activities can quickly overwhelm even the most promising of new businesses. Recognizing the unique challenges facing small businesses,

SHOW MORE STORIES